VAPT · Cloud Security · DevSecOps

Find it before
they do. Then fix it.

Independent penetration testing and cloud security engineering for teams running on AWS, Azure and GCP. The engineer who finds the vulnerability is the engineer who helps you close it.

OWASP ASVS OWASP LLM Top 10 CIS Benchmarks CVSS v3.1 CERT-In aligned
external assessment — sample output
$ subfinder -d example.com | httpx -silent | nuclei -severity high,critical
[INF] Templates loaded: 1,842
[INF] 47 hosts resolved · 112 services fingerprinted
 
[high] exposed-git-config dev.example.com
[high] tls-version-detect api.example.com TLS 1.0
[critical] s3-bucket-public assets.example.com
 
3 findings queued for manual validation
Critical disclosed to client within 24h
 
$

Sample output. Automated discovery only — every finding is then validated by hand.

Platforms & tooling worked with daily

AWSAzureGoogle Cloud KubernetesTerraformDocker GitHub ActionsGitLab CIJenkins Burp Suite ProNucleiProwler TrivyHashiCorp VaultOPA BloodHoundSemgrepPower BI

Service catalogue

Six services. One practitioner. No handoffs.

Security findings are only useful if someone can fix them. Every engagement pairs the offensive work with the cloud and pipeline engineering needed to close what it finds.

ZS-01

Penetration Testing & VAPT

Manual, evidence-led testing across web, mobile, API, internal and external network, and thick-client targets. Every finding carries reproduction steps, business impact and a CVSS v3.1 vector — not a scanner dump.

OWASP ASVSBurp Suite ProRetest includedCVSS v3.1
ZS-02

Cloud Security

Posture review and hardening across AWS, Azure and GCP. IAM least-privilege redesign, network segmentation, key management, logging coverage and drift detection measured against CIS Benchmarks.

AWSAzureGCPCSPMCIS
ZS-03

AI & LLM Security

Adversarial assessment of LLM applications and agents: prompt injection, RAG corpus poisoning, tool-call abuse, model extraction, output handling and guardrail bypass — mapped to the OWASP Top 10 for LLM Applications.

Prompt injectionRAG poisoningAgent toolingRed teaming
ZS-04

DevSecOps

Security built into the pipeline rather than bolted on after it. SAST, DAST and SCA gating, IaC scanning, secrets management, signed artefacts, and policy-as-code that fails builds on the rules that actually matter.

GitHub ActionsGitLab CITrivyOPAVault
ZS-05

Cloud Migration

Assessment, landing-zone design and execution. Workloads classified against the 6R model, infrastructure expressed in Terraform, and cutovers rehearsed so the production move is uneventful.

TerraformLanding zone6R strategyZero-downtime
ZS-06

Cloud FinOps & Optimisation

Billing forensics that find the spend nobody owns: idle capacity, oversized instances, forgotten snapshots, cross-AZ egress and untagged resources. Then commitment strategy and anomaly alerting to keep it down.

RightsizingSavings PlansTaggingAnomaly alerts

Cloud practice

Secure the cloud, then make it cheaper.

Cost work and security work look at the same thing — resources nobody owns. An orphaned volume, a permissive role and a forgotten environment are a finding on both reports.

Posture & hardening

Know exactly where the estate stands.

A full configuration review against CIS Benchmarks, scored and prioritised by real exploitability rather than raw finding counts. You get the remediation plan and, if you want it, the hands to apply it.

  • Identity first. Role trust policies, privilege escalation paths, stale keys and cross-account access.
  • Data exposure. Public buckets, unencrypted volumes, over-shared snapshots and secrets in plaintext.
  • Detection coverage. Whether your logging would actually capture an intrusion, and what it would miss.
  • Drift control. Guardrails so a hardened account stays hardened after the engagement ends.
cloud posture review — sample output
$ prowler aws --compliance cis_2.0_aws
 
FAIL iam_root_mfa_enabled
Root account has no MFA device
FAIL s3_bucket_public_access_block
4 buckets permit public ACLs
FAIL cloudtrail_multi_region_enabled
Logging active in 1 of 6 regions
PASS ebs_default_encryption
 
38 FAIL / 174 PASS — CIS 2.0 score 82%
landing zone plan — sample output
$ terraform plan -out=landing-zone.tfplan
 
+ module.network.aws_vpc.main
+ module.network.aws_flow_log.vpc
+ module.security.aws_guardduty_detector
+ module.logging.aws_cloudtrail.org_trail
+ module.identity.aws_iam_role.break_glass
 
Plan: 47 to add, 0 to change, 0 to destroy.
No drift from approved baseline

Migration & modernisation

Move without the outage story.

Every workload assessed against the 6R model before anything moves, so you rehost what should be rehosted and retire what nobody needed. Infrastructure lands as reviewable Terraform, not console clicks.

  • Discovery. Dependency mapping and a workload inventory that survives contact with reality.
  • Landing zone. Account structure, network topology, guardrails and logging built before the first migration.
  • Rehearsed cutover. A dry run and a documented rollback, so the production move is uneventful.
  • Handover. Runbooks and a team that can operate the thing after you stop paying me.

FinOps

Most cloud bills are an architecture problem.

Billing forensics first, commitments last — buying Reserved Instances on top of waste just locks the waste in for three years. The quick wins usually pay for the engagement.

  • Idle reclamation. Instances provisioned for a launch that never scaled; volumes detached years ago, still billing.
  • Storage lifecycle. Tiering for objects nobody has read since upload, and snapshot policies with a real expiry.
  • Network egress. Cross-AZ and cross-region chatter between services never meant to be split apart.
  • Tagging & showback. An ownership model so each team sees its own spend — the thing that actually keeps a bill down.
cost review, 30-day window — sample output
$ aws ce get-cost-and-usage --granularity MONTHLY
 
idle EC2 >14d, <2% CPU $1,240/mo
unattached 63 EBS volumes $418/mo
cross-AZ data transfer $2,106/mo
untagged 291 resources (11%) unowned
 
addressable waste $3,764/mo
commitment strategy deferred to month 4

Depth on each provider

AWS

Amazon Web Services

  • IAM roles, SCPs and permission boundaries
  • S3 exposure, KMS key policy and encryption posture
  • EKS cluster hardening and pod security standards
  • GuardDuty, Security Hub and CloudTrail coverage
  • Organizations, Control Tower and landing zones
  • Cost Explorer, CUR analysis and Savings Plans
AZURE

Microsoft Azure

  • Entra ID, conditional access and PIM review
  • Storage account exposure and private endpoints
  • AKS hardening and network policy
  • Defender for Cloud and Sentinel coverage
  • Management groups, policy and landing zones
  • Cost Management, reservations and budgets
GCP

Google Cloud

  • IAM bindings, service accounts and workload identity
  • Cloud Storage exposure and CMEK posture
  • GKE hardening and binary authorisation
  • Security Command Centre and audit log coverage
  • Org policy, VPC Service Controls and perimeters
  • Billing export, BigQuery analysis and CUDs
$50k $25k $0 JAN FEB MAR APR MAY JUN 48.2k 31.6k MONTHLY CLOUD SPEND — ILLUSTRATIVE
Illustrative example only, not a client result. The shape of a typical six-month programme: quick wins first, commitments last.

Why the order matters

Most cost programmes start by buying commitments, because that is the lever with the fastest paperwork. It is also the lever that freezes your architecture for one to three years.

Reclaim the waste first and the baseline you commit against is smaller, honest, and cheaper. The same review produces a security finding list, because the resources nobody is paying attention to are the ones nobody is patching either.

AI & LLM security

Your AI feature is a new attack surface.

An LLM with tool access is an untrusted user with your credentials. Assessment covers the model, the retrieval layer, the tool boundary and the output path — mapped to the OWASP Top 10 for LLM Applications.

  • Direct & indirect prompt injection. Including payloads delivered through documents your RAG pipeline ingests.
  • Tool and function abuse. Whether a persuaded model can call something it should never reach.
  • Data leakage. System prompt extraction, training data recall and cross-tenant bleed.
  • Guardrail bypass. Measured coverage rather than a vendor claim, with the gaps written down.
llm red team — sample output
$ promptfoo eval -c llm-redteam.yaml
 
PASS direct-injection/override 14/14
PASS pii/system-prompt-extract 11/11
WARN indirect-injection/rag-doc 3/9
FAIL tool-abuse/unscoped-call 0/6
FAIL output/unsanitised-html 1/8
 
guardrail coverage 62%
agent can invoke billing API unscoped

Platforms & automation

Tooling built around how your team works.

Two platforms built and maintained in-house, plus systems built around your stack — trackers, evidence collection and AI agents, scoped to how your team works rather than bought off a shelf.

Automated testing In-house

Automated pentest platform

Continuous coverage between manual engagements. The platform orchestrates discovery, fingerprinting and safe validation on a schedule, so a service that appeared last Tuesday does not wait until next year's test to be looked at. Breadth is automated; depth still comes from manual work.

Scheduled runs · diffs against last scan · feeds the tracker

Active Directory In-house

AD pentesting platform

Purpose-built for the environment most internal compromises run through. Maps attack paths to tier-0 assets and surfaces the misconfigurations that actually get used — Kerberoasting and AS-REP roasting candidates, unconstrained and constrained delegation, ACL abuse chains, ADCS template flaws and GPO write paths.

Non-destructive checks · ADCS ESC1–ESC8 · path-to-DA output

AI agents

Security & operations agents

Purpose-built agents for the work that eats an engineer's week: triaging scanner output, enriching alerts with asset context, drafting remediation tickets, and watching your external surface for changes between tests.

Scoped build · human-in-the-loop by default

Tracking

Vulnerability tracker

One place for findings from every source — pentests, scanners, bug bounty and cloud posture tools. Deduplicated, assigned to a real owner, with SLA clocks by severity and a retest workflow that closes the loop.

Dashboards for engineering and for the board

Evidence

Audit evidence platform

Evidence collection that does not start three weeks before the audit. Automated collectors pull configuration and log proof on a schedule, mapped to PCI DSS, ISO 27001 and SOC 2 controls, timestamped and exportable for your assessor.

PCI DSS · ISO 27001 · SOC 2 · CERT-In

Monitoring

Continuous control monitoring

Scheduled checks that prove a control stayed switched on after the auditor left. Drift on encryption, logging, MFA or retention raises a ticket the day it happens, not at the next annual review.

Turns a point-in-time pass into a standing one

Reporting

Power BI security dashboards

The numbers leadership actually asks for, in the tool they already open. Vulnerability posture and SLA breaches, cloud spend by team, and control status — pulled from your scanners, billing exports and posture tools into one model that refreshes itself, instead of a screenshot pasted into a deck the night before the board meeting.

Scheduled refresh · row-level security · drill-through to findings

Discovery

Asset & attack surface inventory

Continuous discovery of what you actually expose: forgotten subdomains, shadow deployments, expiring certificates and services that appeared without a ticket. An inventory that stays true after the spreadsheet goes stale.

Alerts on new exposure, not monthly reports

What the AD platform actually traces

Illustrative path — not a real environment
1 Foothold workstation 2 Domain user LDAP enumeration 3 Exposed SPN kerberoastable 4 Service account GenericWrite ACL 5 Domain Admin tier-0 reached PATH LENGTH 5 · EVERY HOP IS A PLACE TO BREAK THE CHAIN

Who this is for

Built for the people who own the risk.

Founders & CTOs

You have an enterprise deal blocked on a security questionnaire and no security team to answer it.

Unblock the deal

Platform & SRE teams

The estate grew faster than the guardrails, and nobody is certain what is exposed or what it costs.

Regain control

Engineering leads

You want findings your developers can act on in a sprint, not a 200-page PDF nobody opens.

Fixable findings

Compliance owners

An audit needs evidence of independent testing, with a retest to prove the findings were closed.

Audit-ready evidence

Engagement method

How a test actually runs.

A fixed five-phase sequence, with the retest included in the original price. You hear about a critical finding the day it is found — never first in the report.

Scope

Targets, rules of engagement, testing windows and escalation contacts agreed in writing. Fixed price, no hourly drift.

Reconnaissance

Attack-surface mapping, technology fingerprinting and credentialed enumeration to build a real picture before any exploitation.

Exploitation

Manual exploitation and chaining, safely and within scope. Criticals are disclosed out-of-band within 24 hours of discovery.

Reporting

An executive summary a board can read, and a technical body with reproduction steps, evidence and prioritised remediation.

Retest

Once your fixes land, every finding is re-tested and the report reissued with a clean status. Included, not an upsell.

Zodiac Academy

Training that runs on real targets.

Hands-on cohorts for engineering teams, delivered remotely or on-site. Lab-first: participants spend most of each session in a live environment, not watching slides.

Offensive Security

40 HRS
  • Web and API exploitation against a deliberately vulnerable stack
  • Burp Suite workflow, from scoping to custom extensions
  • Active Directory attack paths and privilege escalation
  • Writing findings a developer can act on, with CVSS scoring
  • Capstone: a full assessment with a peer-reviewed report

For QA, developers and aspiring pentesters

Cloud Security

32 HRS
  • Identity as the new perimeter: IAM, roles and trust policies
  • Breaking and hardening S3, storage accounts and buckets
  • Kubernetes security on EKS, AKS and GKE
  • Detection engineering with CloudTrail and cloud-native logs
  • Capstone: harden a deliberately misconfigured landing zone

For cloud, platform and SRE teams

DevOps & DevSecOps

36 HRS
  • Pipeline design, artefact signing and supply-chain integrity
  • Terraform and IaC scanning with policy-as-code gates
  • Container hardening and image provenance
  • Secrets management and credential rotation in practice
  • Capstone: ship a service through a fully gated pipeline

For platform engineers and release teams

Working with Zodiac

What independence buys you.

01

One named practitioner

The person who scopes your engagement is the person who tests it and presents the findings. Nothing is handed to a junior after the sale.

24h

Criticals disclosed same day

Anything critical reaches you out-of-band within 24 hours of discovery, with mitigation advice — long before the report is written.

0

No product resale

No vendor margins and no tooling partnerships, so the remediation advice is the advice that fits your stack — including doing nothing.

Findings you can act on

Every issue ships with reproduction steps and a concrete fix. Where the fix is architectural, the engineering to close it is work Zodiac can do.

Start here

Tell me what you are protecting.

A scoping call takes about thirty minutes and costs nothing. Bring your architecture, your compliance deadline, or just the thing that has been worrying you.

Typical lead time
2–3 weeks to engagement start
Coverage
Remote worldwide · on-site across India