CERT-In empaneled · Offensive security & compliance

We test the controls before they're certified.

Intect is the offensive-security and compliance practice of Hion Security Pvt Ltd, based in New Delhi. We're empaneled by CERT-In — India's national cybersecurity authority — and we run both sides of one discipline: attack first, to prove what actually holds; assurance second, because by then we've already tested it.

Offensive security and compliance, from one team. The people who scope a red-team engagement are the same discipline that carries its evidence into an ISO, SOC 2 or regulatory audit.

01

Clients we work with.

Some of the organizations we've worked for — across finance and market infrastructure, manufacturing, aerospace, agrochemicals and government.

  • Sammaan Capital Limited
  • SMC Global Securities Limited
  • Ace Cranes Limited
  • CMR Green Technologies Limited
  • Globe Capital Market Limited
  • Jump Trading Financial India
  • Ministry of MSME
  • Vitrana
  • Raphe mPhibr
  • Indian Energy Exchange
  • Indian Gas Exchange
  • Willowood Chemicals Private Limited
  • Indiabulls
  • Canara Bank
  • State Bank of India
  • Punjab National Bank
  • Aurionpro
  • & many more
02

Built on the attacker's side of the keyboard.

Intect grew from one conviction: if you want to know whether a control works, attack it.

Our researchers spend their time finding the ways into systems that scanners and checklists miss. That habit shaped the firm: we're CERT-In empaneled — accredited under India's national cybersecurity authority — and our work now runs from penetration testing and red teaming to technically validated compliance across the standards and regulators that govern modern business.

We test the controls we audit, and we report exactly what we find. That line hasn't moved since the firm started, and it's the line every engagement is still measured against.

Our approach

To make security something you can prove, not assume. We turn the attacker's perspective into evidence a board, a regulator and a customer can all trust.

03

What we won't compromise on.

Three commitments that shape every engagement, from the first scoping call to the final retest.

01

Integrity

We say only what's true. We never claim a credential we don't hold, we report findings plainly — good news and bad — and we keep readiness and certification properly separate.

02

Depth over speed

Every engagement is run by hand by senior researchers who chain weaknesses and dig past the obvious — the finding that matters is rarely the one a scanner flags first.

03

Partnership

We work alongside your team, not over it — from scoping through remediation and retest. One point of contact from the first probe to a clean audit.

04

Two practices, one discipline.

We attack first and certify second — and the second is stronger for the first.

Offensive Security · 12 disciplines

Adversary-grade testing

Red teaming, penetration testing, and cloud and AI attack simulation — manual, adversary-grade testing that shows exactly how far someone could get, and how to stop them.

Red Team AssessmentWeb Application VAPTNetwork VAPTCloud Security AssessmentAI/ML Penetration Testing
Explore services →
Compliance & Assurance · 16 frameworks

Technically validated audits

Certification-readiness and regulatory audits across the standards modern business runs on — technically validated, because we test the controls before they're certified.

ISO 27001SOC 2PCI DSSIS Audit – RBIDPDP Act
Explore compliance →
05

How we're held to account.

One organisation-level empanelment, and the real facts behind the practice.

We're accredited as an information-security auditing organisation under CERT-In — India's national cybersecurity authority — the credential regulators and boards recognise, and the basis on which we run the statutory audits that require it. In-house, that offensive discipline sits alongside CISA-certified IS auditors who carry the evidence into the audit room. Behind the organisational credential stands a certified bench — offensive, audit, security-management and privacy disciplines in one house.

The accredited body issues the ISO certificate and a licensed CPA signs the SOC 2 report — we make you audit-ready, and we're clear about where our role ends and theirs begins.

Company at a glance
Legal entity
Hion Security Pvt Ltd
Headquarters
New Delhi, India
Corporate Office
B-18, Sector - 1, Noida, Uttar Pradesh 201301
Empanelment
CERT-In Empaneled
Practice areas
Offensive Security · Compliance & Assurance
Certifications held across the team
  • OSCP OffSec Offensive Security Certified Professional
  • OSWE OffSec Offensive Security Web Expert
  • CRTP Altered Security Certified Red Team Professional
  • CRTE Altered Security Certified Red Team Expert
  • eJPT INE Security Junior Penetration Tester
  • CEH EC-Council Certified Ethical Hacker
  • LPT EC-Council Licensed Penetration Tester
  • CISA ISACA Certified Information Systems Auditor
  • CIPP/E IAPP Certified Information Privacy Professional / Europe
  • CISSP ISC2 Certified Information Systems Security Professional
  • CISM ISACA Certified Information Security Manager
06

The two who built it.

Hion Security's directors — one builds the company, the other carries the attacker's craft.

Portrait of Shambhavi Srivastava, CEO and co-founder of Intect
CEO & Co-Founder · Director, Hion Security Pvt Ltd

Shambhavi Srivastava

Shambhavi runs the company. She pairs strategic HR expertise with a working command of the cybersecurity industry it serves — setting up businesses from scratch, mentoring startups on culture, and building the high-performing teams this work depends on. That discipline is what keeps Intect's bench sharp.

CEH · EC-Council IIM Bangalore
Shambhavi on LinkedIn →
Portrait of Sahil Pahwa, co-founder of Intect
Co-Founder · Director, Hion Security Pvt Ltd

Sahil Pahwa

Sahil's work spans the full spectrum of offensive security — vulnerability assessment and penetration testing through cloud security and DevSecOps — grounded in a builder's understanding of application development and cloud infrastructure. Twelve-plus years in, he still describes the job as living at the intersection of strategy and shell access. As a CIPP/E and CISM, he carries the same rigour into data privacy and compliance work.

CIPP/E CISM 12+ years
Sahil on LinkedIn →
We never claim a credential we don't hold. Readiness and certification stay properly separate — that's what makes our assurance mean something.
Scope an engagement

Talk to the people who'll run your engagement.

Whether it's a red-team engagement, a penetration test, or audit-readiness across ISO, SOC 2 or a regulatory framework — you'll scope it with the same team that does the work.