# DrishtiX Cyber Labs (DXCL): full site content Source: https://dxcl.tech # DrishtiX Cyber Labs (DXCL): VAPT and AI security testing Canonical page: https://dxcl.tech/ Security, seen clearly. See your attack surface before attackers do. We test web apps, APIs, AI systems and connected devices for teams that ship fast. You work directly with the testers doing the work, and you get a certificate your customers and investors can verify. Book a scoping call: https://dxcl.tech/contact/ or info@dxcl.tech ## At a glance - Fixed-price scope within 48 hours of a 30-minute call. - Technical and managerial reports by day 12 to 14. - Engagements from $3,000. The first check of your fixes is included. - Certificates valid for 3 to 6 months, set per engagement, verifiable at https://dxcl.tech/trust/ ## Why now Security used to be a big-company problem. Not any more. - 31% of breaches now start with an exploited vulnerability, the most common way in. Source: Verizon, Data Breach Investigations Report 2026. - The average cost of a data breach worldwide is USD 4.99 million, in IBM's latest study of breaches up to February 2026. Source: IBM, Cost of a Data Breach 2026. - One in four malicious breaches used AI, and those cost about USD 1 million more than average. Source: IBM, Cost of a Data Breach 2026. - Failing to take reasonable security safeguards under India's DPDP Act can draw a penalty of up to INR 250 crore. Source: Press Information Bureau, Government of India, 2025. ## Three surfaces, one team Most firms cover one of these well. Products shipping AI features on connected hardware need all three tested together, by people who talk to each other. - **Application and infrastructure** (from $3,000): web and mobile apps, APIs and integrations, network and cloud configuration. - **AI security** (from $8,000): prompt injection and jailbreaks, agent and tool misuse, data leakage through model outputs. - **IoT security** (from $8,000): firmware extraction and analysis, hardware debug interfaces, BLE, Zigbee and MQTT. Details: https://dxcl.tech/services/ ## Fourteen days from first call to report 1. **Day 0, talk.** You tell us what you are shipping. We confirm we are the right fit. 2. **Day 1, scope.** A 30-minute scoping call, then a fixed-price scope within 48 hours. 3. **Day 4 to 5, test.** Trial runs and confirmations, then automated attacks and manual testing of every page and endpoint in scope. 4. **Day 12 to 14, report and certificate.** A technical report for engineers and a managerial report for leadership, walked through live. The certificate is issued the same day. 5. **After, fix check.** We support your developers while they fix, check that each fix holds, and record the check on the certificate. ## The certificate Proof you can share, not a PDF in a drawer. Each certificate has a unique ID tied to one engagement and one scope, a QR code anyone can scan to confirm it is genuine and still valid, and a validity of 3 to 6 months set per engagement. A retest renews it. Verify one at https://dxcl.tech/trust/ ## Pricing Fixed prices agreed before testing starts. Half up front, half on delivery of the report. - Starter VAPT: $3,000 to $5,000. One web app or API. - Standard VAPT: $6,000 to $8,000. App, API and cloud together. - AI or IoT: $8,000 to $10,000. LLM features, agents, or a connected device and its firmware. - Enterprise: from $25,000. Multiple products and surfaces. Details: https://dxcl.tech/pricing/ ## Balance, security, success - **Balance: security that keeps up.** Certificates that expire and retests that renew them keep assurance current. - **Security: you talk to the testers.** No account managers in between. - **Success: written for builders.** Findings come with the request, the impact and the fix. --- # Services and certificate Canonical page: https://dxcl.tech/services/ ## Three surfaces, one team. Applications and infrastructure, AI systems, connected devices. Most firms cover one of these well. Products shipping AI features on connected hardware need all three tested together, by people who talk to each other. ## Application and infrastructure Vulnerability assessment and penetration testing across everything your users touch. From $3,000. Starter VAPT, $3-5K: one web app or API. Standard VAPT, $6-8K: app, API and cloud together. Full pricing: https://dxcl.tech/pricing/ What we test: * Web and mobile apps * APIs and integrations * Network and cloud configuration Where teams usually start: * A first test before a fundraise or launch. * An enterprise deal that asks for proof of testing. * A compliance or customer request. Standards we follow: * Web applications: OWASP Web Security Testing Guide (WSTG) and Application Security Verification Standard (ASVS). * APIs: OWASP API Security Top 10. * Mobile apps: OWASP Mobile Application Security Verification Standard (MASVS) and Testing Guide (MASTG). * Network and cloud: NIST SP 800-115 and the Penetration Testing Execution Standard (PTES). ## AI security Testing for the failure modes that arrive with LLMs and agents, before your users find them. From $8,000. AI or IoT tier, $8-10K: LLM features and agents. Full pricing: https://dxcl.tech/pricing/ What we test: * Prompt injection and jailbreaks * Agent and tool misuse * Data leakage through model outputs Where teams usually start: * An AI launch: a new assistant, agent or LLM feature. * An enterprise buyer asking how your AI features were tested. * A fundraise where the product is built around AI. Standards we follow: * AI and LLM systems: OWASP Top 10 for LLM Applications and MITRE ATLAS. ## IoT security Hardware, firmware and the radios in between, tested the way an attacker with the device in hand would. From $8,000. AI or IoT tier, $8-10K: a connected device and its firmware. Full pricing: https://dxcl.tech/pricing/ What we test: * Firmware extraction and analysis * Hardware debug interfaces * BLE, Zigbee and MQTT Where teams usually start: * A connected device getting ready to launch. * An enterprise customer asking for evidence of device testing. * A compliance or customer request. Standards we follow: * IoT devices: OWASP IoT Security Testing Guide (ISTG). ## How an engagement runs. Every engagement follows the same path, so you always know what happens next and who is doing it. Testing starts only after you approve the scope, the environment and the testing window. 1. Day 0, Talk: you tell us what you're shipping and what prompted the test: a fundraise, an enterprise deal, an AI launch. We confirm we're the right fit. 2. Day 1, Scope: a 30-minute scoping call with the testers. A fixed-price scope reaches your inbox within 48 hours, with the environment and window for you to approve. 3. Day 4 to 5, Test: trial runs and confirmations from our side, then testing starts in the agreed environment and window: automated attacks first, then manual testing of every page and endpoint in scope. 4. Day 12 to 14, Report and certificate: a technical findings and vulnerability report for your engineers, plus a managerial report for leadership. Every finding is rated Critical, High, Medium, Low or Informational. The certificate is issued the same day. 5. After, Fix check: a live walkthrough with the testers, support for your developers while they fix, then a fix check recorded on your certificate. ### What you receive. Two reports by email, a call with the people who did the work, and help until your fixes are checked. Each finding comes with the request, the impact and the fix, written for engineers. * **Technical report:** each finding with the affected endpoint, the request that proves it, the impact, a severity rating and the fix. * **Managerial report:** overall risk in plain words, findings by severity, and what to fix first, for founders and leadership. * **Live walkthrough:** the testers who found each issue explain it and answer your developers' questions. * **Remediation support:** open support and guidance for your developers while they fix. * **Fix check, included:** we re-test what you fixed, and the certificate record shows the date. * **Certificate:** a unique ID and QR code anyone can check, valid for 3 to 6 months. Read the sample report: https://dxcl.tech/trust/sample-report/ ## Tools for breadth. People for depth. Tools find the known patterns quickly. People find the logic flaws tools miss. Every engagement uses both, in that order. * **Automated attacks.** Best-of-market tools sweep everything in scope for known weaknesses first, so testers spend their time where judgement matters. * **Manual testing.** Testers then work through every page and endpoint in scope by hand, looking for broken logic, weak access rules and issues that only appear when chained. * **Testers you talk to.** Every engagement is run by certified security testers. No account managers in between: the people who find an issue explain it and check your fix. Standards we test against: https://dxcl.tech/trust/#method How findings are rated: https://dxcl.tech/trust/#severity ## Proof you can share, not a PDF in a drawer. Investors and enterprise buyers ask whether you've been tested. The certificate answers in seconds, and its expiry date keeps your security from going stale. * **Unique ID:** every certificate is issued against one engagement and one scope. * **QR check:** anyone can scan it to confirm it's genuine and still valid. * **3 to 6 months:** validity is set per engagement. When it expires, a retest renews it. The public record shows the holder, the scope, the testing window, the issue and expiry dates, and the fix check date once done. It records one engagement and its scope. It is not a CERT-In audit certificate, an ISO 27001 certification or a SOC 2 report, and it does not claim the system has no vulnerabilities. Verify a certificate: https://dxcl.tech/trust/#verify What a certificate means: https://dxcl.tech/trust/#meaning ## One test, or a steady rhythm. Start with a single engagement. When your product changes faster than a certificate lasts, retests and an annual contract keep your assurance current. * **One-time testing:** one scoped engagement, from the scoping call to the certificate, at a fixed price agreed in writing before testing starts. Half when you approve the scope, half on delivery of the report. * **Retesting:** the first fix check is included in every engagement. A later full retest, for example to renew a certificate, costs 70% of the original fee, or 50% on an annual contract. * **Annual contract:** three scheduled tests and one ad hoc test a year, with full retests at the lower rate. Several products or surfaces at once? Enterprise engagements start at $25K and are scoped around your roadmap. Prices, payment and retest terms: https://dxcl.tech/pricing/ ## Tell us what you're shipping. A fundraise, an enterprise deal, an AI launch. Send a line about your product and we come back with a fixed-price scope within 48 hours. Book a scoping call: https://dxcl.tech/contact/ or email info@dxcl.tech --- # Pricing: fixed-price VAPT and AI security testing from $3,000 Canonical page: https://dxcl.tech/pricing/ . Machine-readable: https://dxcl.tech/pricing.json Fixed prices, agreed in writing before testing starts. Half when you approve the scope, half when we deliver the report. The first check of your fixes is included. Prices are in US dollars. ## Tiers - **Starter VAPT, $3,000 to $5,000:** one web app or API. Good for a first test before a fundraise or launch. - **Standard VAPT, $6,000 to $8,000:** app, API and cloud together. The usual fit for Series A teams. - **AI or IoT, $8,000 to $10,000:** LLM features, agents, or a connected device and its firmware. - **Enterprise, from $25,000:** multiple products and surfaces, scoped around your roadmap. ## Every engagement includes - A 30-minute scoping call and a fixed price in writing within 48 hours - Automated attacks plus manual testing of every page and endpoint in scope - Certified testers you talk to directly - A technical report and a managerial report by day 12 to 14 - A live walkthrough of every finding - Support for your developers while they fix - A check that your fixes hold - A certificate valid for 3 to 6 months, verifiable at https://dxcl.tech/trust/ ## Retests and annual contracts - First check of your fixes: included. - A later full retest, for example to renew an expired certificate: 70% of the original fee. - Annual contract (three scheduled tests and one ad hoc test a year): 50% of the original fee per retest. ## What testing costs elsewhere Market figures from published 2026 pricing guides and industry timelines (indicative): - A typical penetration test: about $18,300 on average; $10,000 to $30,000 for most engagements (Synack, 2026 pricing guide). 4 to 6 weeks from planning to final report (Halock Security Labs, 2024). - A web app or API test: $5,000 to $30,000 or more depending on complexity (Synack, 2026). 4 to 5 weeks on average (Schellman, 2024). - A web app VAPT in India: INR 40,000 to 3.5 lakh depending on complexity; quotes under INR 20,000 to 40,000 are usually automated scans, not manual tests (Tranquility Cybersecurity, 2026; CyberSigma Consulting Services, 2026). 1 to 3 weeks of testing plus reporting (Tranquility Cybersecurity, 2026). - DXCL: $3,000 to $10,000 for most engagements, Enterprise from $25,000, fixed in writing; report by day 12 to 14; technical and managerial reports, walkthrough, support while fixing, fix check and a verifiable certificate. ## The cost of not testing - INR 25.5 crore: average cost of a data breach in India, a record high (IBM, Cost of a Data Breach 2026: India). - INR 250 crore: maximum DPDP Act penalty for failing to take reasonable security safeguards (Press Information Bureau, 2025). - 4% of worldwide annual turnover, or EUR 20 million if higher: the top GDPR fine (GDPR Article 83(5)). - 43 days: median time to fully fix a critical, actively exploited vulnerability in 2025 (Verizon DBIR 2026). ## Questions - **Are prices fixed?** Yes. You get a fixed price in writing after the scoping call, before any testing starts. It does not change unless you change the scope. - **How is payment structured?** Half when you approve the scope, half when we deliver the report. - **What does a retest cost?** The first check of your fixes is included. A later full retest, for example to renew an expired certificate, costs 70% of the original fee, or 50% on an annual contract. - **Who does the testing?** Certified security testers, the same people you meet on the scoping call. No account managers sit between you and the people who find and explain the issues. --- # About us, and how we operate Canonical page: https://dxcl.tech/about/ ## Drishti means seeing beyond It is Sanskrit for penetrating vision, and it is the work we do. DrishtiX Cyber Labs (DXCL) looks past the surface of what fast-moving teams ship and lays a firm foundation beneath it, so you can keep rising without having to look down. ## Why we exist Security and data safety now matter to every team that ships, not only to large firms. The help on offer had not caught up. DXCL was founded by an application security specialist from a global IT services firm. From the inside, two things were plain: the real technical value of cyber and AI security, and a gap in the market for teams that grow fast. Then the ground moved. AI and a new wave of startups put customer data, models and connected products in the hands of small teams. Funders now ask about data safety before they invest. And AI security is still early: the attacks are new, and so is the practice of testing for them. ### Where teams usually turn - **Large consultancies:** built to serve large clients, and good at it. For a fast-growing team that means a long turnaround, often around a month, at enterprise rates. - **Specialist firms:** mid-sized firms that do strong work, but there are few of them compared with demand, and they still charge enterprise rates. - **Freelancers and bug bounty:** some are excellent, but they are hard to depend on, and most cover either VAPT or AI security, not both. We built DXCL for the space in between: enterprise-level testing and reporting at founder-friendly prices, current with the threat landscape, from a team that is warm and direct in a market that often feels cold. ## What we stand for Three values, and what each one is for: joy in building, safety for the people who use what you build, and room to grow. ### Balance: joy in building Security that keeps pace with shipping. Building a company should feel like building, not like bracing for the next incident. Good testing takes weight off: you know what was tested, what was found and what is fixed, and you can get back to the work you enjoy. That is why the environment and testing window are agreed with you up front, and every engagement follows the same path. ### Security: safety for your users Testing that holds up when someone pushes on it. Your users trust you with their data, and that trust is only as good as the testing behind it. So we test the way an attacker would: automated attacks with best-of-market tools first, then people working by hand through every page and endpoint in scope, looking for the flaws in logic that scanners miss. ### Success: room to grow Proof that helps close the next deal or round. Growth brings harder questions from investors, enterprise buyers and compliance teams. We want your answer to be short: here is our certificate, check it yourself. Behind it sit a managerial report written for leadership and a technical report your engineers can work from straight away. ## How we operate Eight commitments that hold on every engagement, from a single API to a full product. 1. **You talk to the testers.** No account managers in between. The people testing your product are the people on your calls. 2. **Certified testers, every time.** Every engagement is run by certified security testers with the skills your scope calls for. 3. **Tools and people, together.** Automated attacks cover the known patterns at speed. Manual testing of every page and endpoint in scope finds what tools miss. 4. **Prices fixed in writing.** You get a fixed price after the scoping call, before any testing starts. It changes only if you change the scope. 5. **Written approval comes first.** Testing starts only after you approve the scope, the environment and the testing window in writing. 6. **Reports for builders and leaders.** Engineers get each finding with the request, the impact and the fix. Leadership gets a managerial report in plain words. 7. **Support while you fix.** Your developers can bring us questions while they work through the findings. The first check of your fixes is included. 8. **Certificates that expire.** Validity is set per engagement, from 3 to 6 months. A full retest renews it, so your assurance stays current. The 14-day path, step by step: https://dxcl.tech/services/#process Methods, standards and certificate verification: https://dxcl.tech/trust/ ## Where we work Hyderabad, India. We work with teams in India today and are expanding internationally. Prices are quoted in US dollars. ## Where we are going Two aims shape what we build next. - **Make verifiable proof the norm.** We want a certificate with an expiry date and a public check to become the normal way founders, funders and customers ask, and answer, one question: has this been tested, and how recently? It sits alongside formal audits and certifications, not in place of them. - **Cover the whole lifecycle.** Testing is one moment in the life of a product. We aim to grow with the teams we work with across the whole SDLC, from development through security and operations to AI, so security is part of every stage rather than a check at the end. ## Tell us what you're shipping A fundraise, an enterprise deal, an AI launch. Send a line about your product and we come back with a fixed-price scope within 48 hours. Book a scoping call: https://dxcl.tech/contact/#form Or email info@dxcl.tech --- # Infomedia: posts and channels from DXCL Canonical page: https://dxcl.tech/infomedia/ Notes from the work. A new post every week on VAPT, AI security and the rules your buyers and investors are starting to ask about. Short, practical, and sourced. Every post is listed in https://dxcl.tech/llms.txt with a link to its Markdown version, and in the RSS feed at https://dxcl.tech/infomedia/feed.xml ## Channels - YouTube: https://www.youtube.com/@dxcltech - Instagram: https://www.instagram.com/dxcl.tech - X: https://x.com/dxcltech - Facebook: https://www.facebook.com/dxcl.tech --- # Book a scoping call with DrishtiX Cyber Labs (DXCL) Canonical page: https://dxcl.tech/contact/ Tell us what you are shipping. A fundraise, an enterprise deal, an AI launch. Send a few lines and we come back with a fixed-price scope within 48 hours. ## Ways to reach us - Form: https://dxcl.tech/contact/ (name, work email, company, what needs testing, what is driving this (optional), about your product). - Email: info@dxcl.tech - API, for agents acting for a person who asked: POST JSON to https://dxcl.tech/api/contact as described in https://dxcl.tech/openapi.json. Fields: name, email, company, surface (web-mobile-api, ai-llm, iot-hardware, cloud, unsure), trigger (optional: fundraise, enterprise-deal, launch, compliance, other), message. ## What happens next 1. We read your note and reply to arrange a 30-minute call. 2. A fixed-price scope reaches your inbox within 48 hours of the call. 3. Testing starts only when you approve the scope, the environment and the window. ## Where we are Hyderabad, India. Working with teams worldwide. We use what you send only to reply to you. Privacy: https://dxcl.tech/privacy/ --- # Trust portal: verify a DXCL certificate, sample report, methods Canonical page: https://dxcl.tech/trust/ Check our work. Then check us. Verify a DXCL certificate, see what our reports look like, and read exactly how we test. ## Verify a certificate Open https://dxcl.tech/trust/?id=CERTIFICATE-ID in a browser, or type the ID printed on the certificate into the form. IDs look like DCL-XXXX-XXXX-XXXX. The result shows who the certificate was issued to, the scope, the testing window, the issue and expiry dates, the fix check date once done, and whether it is valid, expired or revoked today. The check runs in the browser. Each record is encrypted with its own certificate ID, so only someone holding the ID can read it, and DXCL never publishes a list of the companies it tests. If a check fails, email info@dxcl.tech with the ID and a person will confirm it. Sample certificate to try: DCL-DEM0-2026-0001 (issued to the fictional Sample Company Pvt Ltd). ## What a certificate means It confirms: - DXCL tested the systems listed in the scope, in the testing window shown. - Testing combined automated attacks with manual testing of every page and endpoint in scope. - Every finding was reported to the holder with its impact and a fix. - When the fix check is complete, the date it was done. - The date it stops counting as evidence: 3 to 6 months after the report, set per engagement. It does not claim: - That the system has no vulnerabilities. - Anything about systems outside the listed scope, or changes shipped after the testing window. - To be a CERT-In audit certificate, an ISO 27001 certification or a SOC 2 report. It complements those; it does not replace them. Lifecycle: issued on the day of the report; fix check recorded; valid for 3 to 6 months; expired or renewed by a full retest with a new ID; revoked if misused or if the scope was misrepresented. ## Sample report Every engagement ends with a managerial report for leadership, a technical report for engineers, a live walkthrough call with the testers, and an included fix check. Sample: https://dxcl.tech/trust/sample-report/ ## How we test Automated attacks with best-of-market tools, then manual testing of every page and endpoint in scope. Test plans follow public standards: - Web applications: OWASP Web Security Testing Guide (WSTG) and Application Security Verification Standard (ASVS). - APIs: OWASP API Security Top 10. - Mobile apps: OWASP MASVS and MASTG. - AI and LLM systems: OWASP Top 10 for LLM Applications and MITRE ATLAS. - Network and cloud: NIST SP 800-115 and PTES. - IoT devices: OWASP IoT Security Testing Guide (ISTG). On request, findings are mapped to controls such as ISO/IEC 27001 Annex A, SOC 2, PCI DSS and the reasonable security safeguards required by India's DPDP Act. ## How findings are rated Each finding gets a CVSS base score and a severity, adjusted for business context, with every adjustment explained in the report. - Critical: direct path to sensitive data or full control, with little effort or skill. - High: serious impact that needs some access or a specific condition. - Medium: real weakness with limited impact, or one that needs chaining with others. - Low: small risk on its own. - Informational: no direct risk; a hardening step or good practice. ## Rules of engagement - Written approval first: testing starts only after the client approves scope, environment and window in writing. - Certified people: every engagement is run by certified security testers the client meets and talks to directly. - Your data stays yours: what we see is used only to test and report; findings go to the people the client names. ## Report a vulnerability in DXCL Email info@dxcl.tech with the affected URL or system, steps to reproduce and how to reach you. Please do not access, change or keep data that is not yours, run denial-of-service, spam or social engineering tests, or share the issue publicly before it is fixed. Machine-readable contact: https://dxcl.tech/.well-known/security.txt --- # Sample report: what a DXCL report looks like Canonical page: https://dxcl.tech/trust/sample-report/ A sample DXCL penetration test report for a fictional company. All names, hosts and data are invented. The matching sample certificate is DCL-DEM0-2026-0001 (verify at https://dxcl.tech/trust/?id=DCL-DEM0-2026-0001). ## Cover - Client: Sample Company Pvt Ltd (fictional) - Report ID: DXCL-RPT-2026-SAMPLE, version 1.0, classification: sample, public - Testing window: 14 to 25 September 2026. Report date: 28 September 2026. - Prepared by: DrishtiX Cyber Labs testing team ## 1. Managerial summary Overall risk: moderate. One access control flaw let any logged-in customer read other customers' invoices. Two high-severity issues were fixed within a week, and both fixes held at the fix check on 3 October 2026. Findings by severity: Critical 0, High 2, Medium 3, Low 2, Informational 3. Fix first: 1. Check ownership on every object the API returns (H-01). 2. Limit login attempts and add a second factor for admin users (H-02). 3. Stop returning stack traces from the API in production (M-02). ## 2. Scope and method - In scope: web app at app.example.com and REST API at api.example.com, two customer roles and the admin role. - Out of scope: third-party payment provider, denial-of-service testing, social engineering. - Environment: staging with production-like data. - Approach: automated attacks with best-of-market tools, then manual testing of every page and endpoint in scope. - Standards: OWASP Web Security Testing Guide, OWASP ASVS, OWASP API Security Top 10. ## 3. Findings | ID | Finding | Severity | CVSS 3.1 | After fix check | |---|---|---|---|---| | H-01 | Broken object level authorisation on the invoices API | High | 6.5 | Fixed and verified | | H-02 | No limit on login attempts for admin accounts | High | 7.5 | Fixed and verified | | M-01 | Session tokens stay valid after password change | Medium | 5.4 | Open, scheduled | | M-02 | Stack traces returned by the API in production mode | Medium | 5.3 | Fixed and verified | | M-03 | File upload accepts SVG files with scripts | Medium | 5.4 | Open, scheduled | | L-01 | Software versions shown in response headers | Low | 3.7 | Accepted risk | | L-02 | Password reset links valid for 72 hours | Low | 3.1 | Open, scheduled | | I-01 | Content Security Policy could be stricter | Informational | None | Open | | I-02 | Cookies missing the SameSite attribute | Informational | None | Fixed and verified | | I-03 | Unused API version still reachable | Informational | None | Open | ## Finding H-01: Broken object level authorisation on the invoices API - Severity: High. CVSS 3.1 base score 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), raised to High because the data covers every customer, the IDs are guessable and exploitation needs only a free account. - Endpoint: GET https://api.example.com/v1/invoices/{id} - References: OWASP API Security Top 10, API1 Broken Object Level Authorization; CWE-639. - Evidence: logged in as customer A, a request for an invoice belonging to customer B returned 200 OK with that invoice. - Impact: any logged-in customer could read every other customer's invoices, including names, addresses and GST numbers; a reportable breach under India's DPDP Act. - Fix: check ownership on the server for every object lookup; take the account ID from the session, never from the request; add an automated test expecting a 404 for another account's invoice. - Fix check: fixed and verified on 3 October 2026. ## After the report Both reports arrive by email and the certificate is issued on the day of the report. The testers walk your developers through every finding, answer questions while they fix, then re-test the fixes and record the fix check on the certificate. --- # The DPDP clock is running. What Indian startups should test now Canonical page: https://dxcl.tech/infomedia/dpdp-rules-the-clock-is-running/ Published: 2026-10-05 by DrishtiX Cyber Labs (DXCL). Topic: Compliance. India's data protection rules give most companies until May 2027. The penalties reach INR 250 crore. Here is what the law asks for, and what to test before the deadline. For years, data protection in India was something big companies worried about. That changed with the Digital Personal Data Protection Act, 2023, and the rules that put it into practice. If you collect personal data from Indian users, and almost every startup does, this applies to you. The good news is that there is still time. The bad news is that it is less time than it feels like. ## The dates that matter The government notified the DPDP Rules on 13 November 2025. Most of the operational duties, including security safeguards and breach reporting, come into force 18 months after that: 13 May 2027.[^1] In January 2026 the ministry asked industry for views on cutting that window to 12 months, which would have pulled the date forward to November 2026.[^2] As we write, no such change has been notified and May 2027 still stands. Check the latest notification before you lock your roadmap. Eighteen months sounds like a lot. It is about six release cycles for a fast team, with a fundraise or two in between. ## What the law asks for Three duties matter most for a product team. 1. **Reasonable security safeguards.** You must take reasonable steps to protect the personal data you hold. Failing to do so, where it leads to a breach, can draw a penalty of up to INR 250 crore, the highest in the Act.[^3] 2. **Breach notification.** If personal data is breached, you must tell the Data Protection Board and the affected people. Under the Rules, a detailed report to the Board is due within 72 hours of becoming aware of the breach.[^1] Failing to notify can draw a penalty of up to INR 200 crore.[^3] 3. **Logs you can rely on.** The Rules ask for logs and monitoring that let you detect and investigate unauthorised access, kept for at least a year.[^1] This sits on top of CERT-In's 2022 directions, which already require listed cyber incidents to be reported to CERT-In within 6 hours of noticing them.[^4] ## Why this is not paperwork It is tempting to treat all of this as a policy document and a checkbox. The numbers say otherwise. CERT-In handled more than 29.44 lakh cyber incidents in 2025.[^5] IBM's 2026 study put the average cost of a data breach in India at a record INR 25.5 crore, before any penalty.[^6] "Reasonable security safeguards" will be judged after something goes wrong. The question will be simple: did you look for the holes, and did you fix them? ## What to test before May 2027 You do not need to do everything at once. Start where personal data actually lives. - **Map it.** Know which apps, APIs, databases and third parties hold personal data. You cannot protect what you have not listed. - **Test the paths to it.** Run a penetration test on the web and mobile apps and APIs that touch personal data. Look hardest at access control: can one user see another user's data? - **Test your AI features.** If an assistant or agent can read customer data, test whether it can be talked into revealing it. - **Check your logging.** Confirm that access to personal data is logged, that the logs are kept, and that someone would notice an unusual pattern. - **Rehearse the 72 hours.** Walk through who decides, who writes the report and who tells customers. Do it before you need it. - **Retest after big changes.** A test from last year says little about the product you ship this quarter. ## Where we fit We are not lawyers, and a security test is not a legal opinion. Talk to your counsel about what the Act means for your business. What we do is the testing that "reasonable security safeguards" depends on. Our VAPT and AI security engagements find the paths to your users' data, explain them in language your engineers can act on, check that the fixes hold, and leave you with a dated, verifiable record of the work. On request, we map findings to the safeguards your lawyers and auditors ask about. The deadline is fixed. How ready you are when it arrives is not. ## Sources 1. EY India, [DPDP Act 2023 and DPDP Rules 2025: point of view](https://www.ey.com/content/dam/ey-unified-site/ey-com/en-in/pdf/2025/11/ey-india-dpdp-act-2023-and-rules-2025-pov.pdf) (November 2025), summarising Rules 1, 6 and 7. 2. Storyboard18, [MeitY seeks industry views on fast-tracking DPDP Act rollout, proposes 12-month compliance timeline](https://www.storyboard18.com/digital/meity-seeks-industry-views-on-fast-tracking-dpdp-act-rollout-proposes-12-month-compliance-timeline-88332.htm) (January 2026). 3. Press Information Bureau, Government of India, [explainer on the DPDP Act and Rules](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf) (17 November 2025). 4. CERT-In, [Directions under section 70B(6) of the IT Act](https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf) (28 April 2022). 5. Press Information Bureau, Government of India, [CERT-In achievements in 2025](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2026/jan/doc2026123764501.pdf) (January 2026). 6. IBM, [Cost of a Data Breach 2026: India](https://in.newsroom.ibm.com/India-Records-its-Highest-Average-Cost-of-a-Data-Breach-2026). --- # Prompt injection is your AI feature's front door Canonical page: https://dxcl.tech/infomedia/prompt-injection-is-the-front-door/ Published: 2026-10-05 by DrishtiX Cyber Labs (DXCL). Topic: AI security. The number one risk in the OWASP Top 10 for LLM Applications, explained for founders. What it is, why it is really an access problem, and five things to test before your AI launch. Every AI feature has a front door, and it is the prompt. Anything that reaches your model's context can steer it: a user's message, a support ticket, a PDF a customer uploaded, a web page your agent reads. If your model treats that text as instructions, someone else is now giving orders inside your product. That is prompt injection. It sits at number one in the OWASP Top 10 for LLM Applications.[^1] ## This is no longer theoretical In a Gartner survey of 302 security leaders, 32% said they had faced an attack on AI applications that used the application prompt in the previous 12 months.[^2] IBM's 2026 Cost of a Data Breach study found that one in four malicious breaches were AI-enabled, and those cost an average of USD 6 million, about USD 1 million more than the average breach.[^3] Among organisations that reported an AI-related breach, 92% lacked proper AI access controls.[^4] The good news: teams are catching on. The World Economic Forum's 2026 outlook found that 64% of organisations now assess the security of AI tools before deploying them, up from 37% a year earlier. That still leaves about a third with no such process.[^5] ## It is really an access problem Here is the part founders miss. You cannot fully stop a model from being talked into something. Models are built to follow text. So the real question is not "can the model be tricked?" It is "what can the model do once it is?" If your assistant can only answer questions from public docs, a successful injection is embarrassing. If your agent can read every customer's records, send email, or call internal APIs with an admin token, the same injection is a breach. That is why we test AI features the way we test any system with privileges: by mapping what each tool and data source can reach, then trying to make the model reach further. ## Five things to test before your AI launch 1. **Indirect injection.** Put instructions inside content your model reads: a document, a web page, a ticket. See whether it obeys them. 2. **Tool permissions.** List every tool your agent can call and the identity it calls with. Each should work with the user's permissions, not the platform's. 3. **Data boundaries.** Ask the model, directly and indirectly, for another user's data, your system prompt and anything in retrieval it should not show. 4. **Output handling.** Check what happens to model output downstream. If it is rendered as HTML, run as code, or passed to another system, injection travels with it. 5. **Cost and abuse.** Try long, looping or expensive requests. An agent that can be made to run forever is a bill, and sometimes an outage. ## How we approach it Our AI security engagements follow the OWASP Top 10 for LLM Applications and MITRE ATLAS, combine automated attacks with manual testing, and end with the same thing every DXCL engagement does: a report your engineers can act on the same day, a walkthrough with the testers, a check of your fixes, and a certificate your buyers can verify. If you are about to ship an assistant, an agent, or retrieval over customer data, test it before your users do. ## Sources 1. OWASP Gen AI Security Project, [LLM01 Prompt Injection](https://genai.owasp.org/llmrisk/llm01-prompt-injection/). 2. Gartner, [survey of 302 cybersecurity leaders, March to May 2025](https://www.gartner.com/en/newsroom/press-releases/2025-09-22-gartner-survey-reveals-generative-artificial-intelligence-attacks-are-on-the-rise) (press release, 22 September 2025). 3. IBM, [Cost of a Data Breach Report 2026](https://newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled,-costing-companies-6-million-on-average) (press release, 29 July 2026). 4. IBM X-Force, [2026 Cost of a Data Breach: AI adversaries and enterprise risk](https://www.ibm.com/think/x-force/2026-cost-of-a-data-breach-ai-adversaries-enterprise-risk). 5. World Economic Forum, [Global Cybersecurity Outlook 2026](https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2026.pdf). --- # Why our certificates expire Canonical page: https://dxcl.tech/infomedia/why-our-certificates-expire/ Published: 2026-10-05 by DrishtiX Cyber Labs (DXCL). Topic: Certificates. A security certificate that never expires is a photo of a moving car. Here is why ours last 3 to 6 months, and why that helps you close deals. You ship every week. The product we test on day one is not the product your customers use three months later. New endpoints, new integrations, a new AI feature someone wired up on a Friday. So a certificate that says "tested" forever is not proof of anything. It is a photo of a moving car. That is why every DXCL certificate has an expiry date. Here is the thinking behind it. ## Fixing takes time, even for the worst bugs Finding a vulnerability is the fast part. Fixing it properly is where the time goes. Verizon's 2026 Data Breach Investigations Report found that exploiting vulnerabilities is now the most common way attackers get in, at 31% of breaches.[^1] The same report found that only 26% of the most dangerous known vulnerabilities, the ones on CISA's Known Exploited Vulnerabilities list, were fully fixed in 2025. The median time to fully fix one was 43 days.[^1] That is not because teams are careless. A client of any size might get a report with ten findings, three of them critical. Fixing even one critical issue can take days, depending on what else is on the roadmap and how the team works. We would rather say that out loud than pretend a report is the end of the story. ## Buyers and investors are checking The other reason is simple: people now ask. In G2's 2026 buyer research, IT security review was the single biggest source of delay after a software vendor had been chosen. 39% of buyers named it, and half of enterprise buyers did.[^2] On the investment side, 84% of M&A advisers surveyed by SRS Acquiom expect more scrutiny of cybersecurity in due diligence over the next one to two years.[^3] When that question lands in your inbox, an old PDF does not answer it. A current, checkable record does. ## How our certificate works We built it around three ideas. 1. **One scope, one window.** The certificate names exactly what we tested and when. Nothing more is implied. 2. **Validity set by what we found.** It lasts 3 to 6 months from the day of the report. A team with a few low-severity findings and a quiet roadmap gets longer. A team with critical issues and a big release coming gets shorter. One fixed number would be wrong for one of them. 3. **Anyone can check it in seconds.** Every certificate has a unique ID and a QR code. Your buyer or investor opens our [Trust portal](/trust/), and sees who it was issued to, the scope, the dates, and whether we have confirmed your fixes. When it expires, a full retest renews it. That is the point: your assurance moves with your product. ## What it is not A DXCL certificate is a dated record of one engagement. It is not a CERT-In audit certificate, an ISO 27001 certification or a SOC 2 report, and it does not claim your system has no vulnerabilities. No honest test can claim that. It sits alongside those, and it is often what a buyer can check fastest. ## Using it well Put the certificate ID in your security questionnaire answers, your data room and your sales deck. Tell buyers they can verify it themselves. Then book the retest before it lapses, ideally before your next big release. Expiry is not a weakness of the certificate. It is the feature that makes it worth trusting. ## Sources 1. Verizon, [2026 Data Breach Investigations Report, executive summary](https://www.verizon.com/business/resources/executivebriefs/2026-dbir-executive-summary.pdf). 2. G2, [2026 Buyer Behavior Report](https://learn.g2.com/why-b2b-deals-stall-after-the-ai-shortlist-in-2026) (1,038 B2B software decision-makers). 3. SRS Acquiom with Mergermarket, [M&A Due Diligence Study 2026](https://srsacquiom.com/our-insights/m-a-due-diligence-study-2026) (150 senior US investment bank executives).