Skip to content
Mounteyes

Cybersecurity services, delivered by people who will tell you what is actually wrong

Assessment, managed protection, incident response and advisory work for businesses and individuals in India. Every engagement is scoped in writing before it starts, and quoted against that scope rather than read off a menu.

Every engagement includes

  • A named engineer who understands your setup, not a rotating queue.
  • Written scope and authorisation agreed before any testing begins.
  • Findings ranked by real exploitability, each with the fix stated.
  • Reporting your engineers and your board can both read.
  • A re-test after remediation, so the fix is proven rather than assumed.
  • An honest assessment — including when the answer is that you need less than you asked for.

How engagements are priced

We do not publish a price list, and no serious security firm can. The same two words — "website audit" — describe two days of work and two months of work. What decides the number is scope, estate size, urgency, and whether you need a project or ongoing cover.

Project-based
A fixed scope for a fixed fee: an audit, a VAPT cycle, a hardening exercise, a compliance readiness review. Agreed in writing before it starts.
Monthly retainer
Ongoing monitoring, managed protection and a named escalation path, billed monthly against agreed coverage and response windows.
Incident response
Scoped in the first call, because when something is live the priority is containment rather than paperwork. You will know the basis of the charge before we start work.
Individuals affected by fraud
Quoted according to the situation and what is realistically achievable. If the honest answer is that nothing you pay for will improve your outcome, we say so and point you to the free official routes.

Nothing is charged before scope is agreed, and we never ask for card or UPI details over chat, email or a phone call.

Managed security & monitoring

Continuous protection and monitoring, delivered on our platforms with a named escalation path.

Managed Detection & Response (24×7)

Continuous monitoring of your servers, applications, network and logs by our platform and our engineers, with agreed response windows. Detection, triage, containment and a written timeline for every incident.

Most requested

Delivered on AI Server, API & Website Monitoring and Security

AI CCTV Monitoring Setup & Management

Assessment of your existing cameras, per-zone detection rules, escalation chains and ongoing tuning — so alerts stay useful instead of becoming noise somebody eventually switches off.

Most requested

Delivered on AI CCTV Monitoring & Incident Alerting

Log Monitoring & Security Alerting

Collection and correlation of server, application, authentication and access logs, alerting on the sequences that indicate an attack chain rather than on single odd events.

Assessment & testing

Finding what is exploitable across your applications, servers, network, cloud and code — before someone else does.

Vulnerability Assessment & Penetration Testing (VAPT)

Authorised testing of your applications, APIs and infrastructure against the OWASP and CIS baselines, with proof of exploitability, business impact, a prioritised remediation plan and a re-test once you have fixed it.

Most requested

Website & Web Application Security Audit

HTTPS and certificate configuration, security headers, authentication and session handling, access control, exposed files and endpoints, and dependency risk — reviewed, ranked and returned with fixes.

Most requested

API Security Testing

Authorisation and object-level access checks — the IDOR class behind most real breaches — plus input validation, rate limiting, token handling and error leakage, tested across your documented and undocumented endpoints.

Network & Infrastructure Security Assessment

External attack surface, internal segmentation, exposed administrative services, firewall rules and remote-access configuration, assessed and returned as a work list rather than a wall of output.

Server Hardening & Secure Configuration

Baseline hardening against CIS benchmarks: services and ports, users and privileges, SSH and remote access, TLS configuration, logging, updates and backups — implemented, documented and verified.

Cloud Security Configuration Review

IAM policy and privilege review, public exposure of storage and databases, network and security-group rules, logging coverage, and key and secret handling across AWS, Azure or Google Cloud.

Mobile App Security Testing

Android and iOS builds reviewed for hardcoded secrets, insecure local storage, weak transport security, tampering and reverse-engineering exposure — together with the backend API the app depends on.

Secure Code Review

Manual review of authentication, authorisation, data handling and payment paths alongside automated analysis, reported with the design-level fix rather than only a line number.

Incident response & recovery

Help when it has already happened: containment, cleanup, evidence, and recovery through legitimate channels.

Incident Response & Breach Containment

Immediate containment, scope determination, removal of the attacker's foothold and a written timeline. Then the harder question answered: which gap was used, and what closes it.

Most requested

Malware Removal & Blacklist Recovery

Cleanup of infected files, injected redirects, spam pages and backdoors, restoration to a verified clean state, root-cause identification, and submission for removal from Google and browser blacklists.

Most requested

Ransomware Readiness & Recovery Advisory

Backup and recovery-point validation, segmentation and privilege review, and a recovery plan that has actually been tested. If an incident is live, honest advice on the options — and never negotiation or payment on your behalf.

Account Compromise & Recovery Assistance

Structured help regaining access through the platform's own official recovery and appeal processes: which route applies, what evidence to prepare and how to word it — then securing the account so it does not happen again.

Most requested

Cyber Fraud & Financial Loss Response

The immediate correct steps after a fraudulent transaction: the 1930 helpline and a cybercrime.gov.in complaint, what your bank needs and how quickly, evidence preservation, and realistic expectations about recovery.

Most requested

Digital Forensics & Evidence Preservation

Sound acquisition and analysis of logs, disks and devices with chain of custody maintained, producing findings that hold up in an insurance claim or a legal process.

Advisory & compliance

Consulting, compliance readiness and training — the work that stops the same incident happening twice.

Cybersecurity Consultation

A working session on a specific problem or decision — an architecture question, a vendor assessment, a suspicious incident, or simply where to start — ending in a prioritised list rather than a sales pitch.

Most requested

Compliance & Audit Readiness

Gap assessment, control implementation and evidence preparation for ISO 27001, SOC 2 and India's DPDP Act — including the security questionnaires your enterprise customers keep sending.

Most requested

Security Awareness Training & Phishing Simulation

Training built around the attacks your staff actually receive — invoice fraud, UPI and OTP scams, fake courier and KYC messages — with simulated phishing afterwards to measure whether it worked.

Security Architecture Review & Roadmap

A review of how your systems fit together — trust boundaries, authentication, data flows, third-party access — and a roadmap that sequences fixes by risk rather than by whichever is easiest.

What we do not do

We do not access systems that are not yours, bypass platform security, crack or recover passwords, intercept OTPs, or offer "guaranteed" recovery. A provider claiming otherwise is either lying or committing a crime on your behalf — and leaving you liable for it.

  • Testing or attacking any system without the owner's written authorisation.
  • Accessing an account, device or network without the owner's authorisation.
  • Bypassing, disabling or defeating platform security or two-factor authentication.
  • Password cracking, credential purchases or OTP interception.
  • Covert surveillance of individuals, or facial identification of members of the public.
  • Guaranteed recovery of any account, any data or any money.
  • Ransom negotiation or payment on your behalf.

Not sure which of these you need?

Describe the situation and we will tell you — including if the answer is that you need less than you think. A scoping conversation costs nothing and ends with a written scope you can compare against anyone else's.

Talk to Our Security Team