Services Pricing Why Us Blog Contact contact@baselayersecurity.com

Free retest included on all engagements — we verify your fixes at no extra charge. NDA signed before every engagement.

NDA Before TestingSigned before any engagement begins. Your architecture stays confidential.
Rules of EngagementScope, methods, and boundaries agreed in writing before testing starts.
Executive + Technical ReportSeparate reports for founders/investors and your engineering team.
Free Retest IncludedWe verify your fixes at no extra charge after remediation.
Secure Evidence HandlingAll findings, screenshots, and PoCs are stored securely and deleted post-engagement.
Web Security
Basic Web App VAPT
Small to mid-size web applications
₹29,999 starting from
Typical delivery: 3–5 business days
Transparent pricing No hidden fees

  • OWASP Top 10 assessment
  • Authentication & session testing
  • Manual + automated scanning
  • Prioritised findings report
  • Free retest after fixes
    You receive
  • Executive summary (non-technical)
  • Technical findings with severity ratings
  • Proof-of-concept evidence per vulnerability
  • Prioritised remediation guide
Request Proposal
Web Security
Web Application VAPT
SaaS & web applications · Full manual testing
₹49,999 starting from
Typical delivery: 5–7 business days · Ideal for: SaaS startups & fintechs
Transparent pricing No hidden fees

  • Full manual penetration testing
  • Business logic flaw detection
  • Auth bypass & privilege escalation
  • API endpoint review
  • Detailed remediation guide
  • Free retest after fixes
    You receive
  • Executive summary (non-technical)
  • Full technical report with CVSS ratings
  • PoC evidence per finding
  • Developer remediation guide
  • Retest confirmation report
Request Proposal
API Security
API Security Assessment
REST / GraphQL APIs
₹39,999 starting from
Typical delivery: 5–7 business days · Ideal for: API-first SaaS & fintech platforms
Transparent pricing No hidden fees

  • OWASP API Top 10 coverage
  • Broken auth & access control
  • Rate limiting & injection testing
  • Excessive data exposure review
  • Postman collection provided
  • Free retest after fixes
    You receive
  • Executive summary (non-technical)
  • Technical report with endpoint findings
  • Postman collection with test cases
  • Developer remediation guide
  • Retest confirmation report
Request Proposal
Cloud Security
Cloud Security Review
AWS · Azure · GCP
₹49,999 starting from
Typical delivery: 3–5 business days · Ideal for: Cloud-native SaaS & growing businesses
Transparent pricing No hidden fees

  • IAM policy & role review
  • Misconfiguration detection
  • Exposed storage & endpoints
  • Network security analysis
  • CIS benchmark comparison
  • Free retest after fixes
    You receive
  • Executive summary (non-technical)
  • Technical findings with risk ratings
  • CIS benchmark gap analysis
  • Prioritised remediation guide
  • Retest confirmation report
Request Proposal
Retest Only
Already fixed your vulnerabilities from a previous assessment? We'll verify everything is properly remediated.
Included freeor ₹9,999 standalone
Common Questions

Frequently asked questions

What does "starting from" mean?

Prices listed are base rates for standard scope engagements. Final pricing depends on the size of your application, number of endpoints, complexity of the environment, and your timeline. We always agree on scope and price before starting — no surprises.

How long does an assessment take?

Basic Web App VAPT: 3–5 days. Web Application VAPT or API Assessment: 5–7 days. Cloud Security Review: 3–5 days. Startup Bundle: 10–14 days. Timelines are agreed upfront and we keep you updated throughout.

Do you sign an NDA before starting?

Yes — always. We sign a mutual NDA before any engagement begins. Your code, architecture, and findings are completely confidential.

What do I get in the report?

Every report includes an executive summary (for founders and investors), a technical findings section with severity ratings, proof-of-concept evidence for each vulnerability, and a prioritised remediation guide your developers can act on immediately.

What happens after the report?

We provide remediation guidance and clarification during the remediation process. Once you've fixed the issues, we retest at no extra charge and issue a Remediation Verification Report you can share with investors or customers.

Can I pay in instalments?

Yes. For engagements above ₹49,999 we offer a 50% upfront / 50% on delivery structure. For the Complete Security Assessment we can discuss a phased payment plan. Just ask during the scoping call.

Not sure where to start?

Book a 30-minute scoping call — we'll review your environment and recommend the right engagement for your business.

Book Free Scoping Call Email Us Directly