We test the controls before they're certified.
Intect is the offensive-security and compliance practice of Hion Security Pvt Ltd, based in New Delhi. We're empaneled by CERT-In — India's national cybersecurity authority — and we run both sides of one discipline: attack first, to prove what actually holds; assurance second, because by then we've already tested it.
Offensive security and compliance, from one team. The people who scope a red-team engagement are the same discipline that carries its evidence into an ISO, SOC 2 or regulatory audit.
Clients we work with.
Some of the organizations we've worked for — across finance and market infrastructure, manufacturing, aerospace, agrochemicals and government.
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- & many more
Built on the attacker's side of the keyboard.
Intect grew from one conviction: if you want to know whether a control works, attack it.
Our researchers spend their time finding the ways into systems that scanners and checklists miss. That habit shaped the firm: we're CERT-In empaneled — accredited under India's national cybersecurity authority — and our work now runs from penetration testing and red teaming to technically validated compliance across the standards and regulators that govern modern business.
We test the controls we audit, and we report exactly what we find. That line hasn't moved since the firm started, and it's the line every engagement is still measured against.
To make security something you can prove, not assume. We turn the attacker's perspective into evidence a board, a regulator and a customer can all trust.
What we won't compromise on.
Three commitments that shape every engagement, from the first scoping call to the final retest.
Integrity
We say only what's true. We never claim a credential we don't hold, we report findings plainly — good news and bad — and we keep readiness and certification properly separate.
Depth over speed
Every engagement is run by hand by senior researchers who chain weaknesses and dig past the obvious — the finding that matters is rarely the one a scanner flags first.
Partnership
We work alongside your team, not over it — from scoping through remediation and retest. One point of contact from the first probe to a clean audit.
Two practices, one discipline.
We attack first and certify second — and the second is stronger for the first.
Adversary-grade testing
Red teaming, penetration testing, and cloud and AI attack simulation — manual, adversary-grade testing that shows exactly how far someone could get, and how to stop them.
Technically validated audits
Certification-readiness and regulatory audits across the standards modern business runs on — technically validated, because we test the controls before they're certified.
How we're held to account.
One organisation-level empanelment, and the real facts behind the practice.
We're accredited as an information-security auditing organisation under CERT-In — India's national cybersecurity authority — the credential regulators and boards recognise, and the basis on which we run the statutory audits that require it. In-house, that offensive discipline sits alongside CISA-certified IS auditors who carry the evidence into the audit room. Behind the organisational credential stands a certified bench — offensive, audit, security-management and privacy disciplines in one house.
The accredited body issues the ISO certificate and a licensed CPA signs the SOC 2 report — we make you audit-ready, and we're clear about where our role ends and theirs begins.
- OSCP OffSec Offensive Security Certified Professional
- OSWE OffSec Offensive Security Web Expert
- CRTP Altered Security Certified Red Team Professional
- CRTE Altered Security Certified Red Team Expert
- eJPT INE Security Junior Penetration Tester
- CEH EC-Council Certified Ethical Hacker
- LPT EC-Council Licensed Penetration Tester
- CISA ISACA Certified Information Systems Auditor
- CIPP/E IAPP Certified Information Privacy Professional / Europe
- CISSP ISC2 Certified Information Systems Security Professional
- CISM ISACA Certified Information Security Manager
The two who built it.
Hion Security's directors — one builds the company, the other carries the attacker's craft.
Shambhavi Srivastava
Shambhavi runs the company. She pairs strategic HR expertise with a working command of the cybersecurity industry it serves — setting up businesses from scratch, mentoring startups on culture, and building the high-performing teams this work depends on. That discipline is what keeps Intect's bench sharp.
Sahil Pahwa
Sahil's work spans the full spectrum of offensive security — vulnerability assessment and penetration testing through cloud security and DevSecOps — grounded in a builder's understanding of application development and cloud infrastructure. Twelve-plus years in, he still describes the job as living at the intersection of strategy and shell access. As a CIPP/E and CISM, he carries the same rigour into data privacy and compliance work.
We never claim a credential we don't hold. Readiness and certification stay properly separate — that's what makes our assurance mean something.
Talk to the people who'll run your engagement.
Whether it's a red-team engagement, a penetration test, or audit-readiness across ISO, SOC 2 or a regulatory framework — you'll scope it with the same team that does the work.