# IntelligenceX > VAPT, MDR, incident response and compliance across the UK, USA, EU and India, backed by five SaaS platforms: CERTX, DARKX, CSPMX, CYWAREX and ConsentX. IntelligenceX is a cybersecurity, DevSecOps and compliance firm. We deliver VAPT, managed detection and response, incident response, security awareness and compliance (ISO 27001, SOC 2, PCI DSS, GDPR, plus India regulatory: RBI, SEBI, IRDAI, CERT - In, DPDP) across the UK, USA, EU and India. Markets served: United Kingdom, United States, European Union, India. Contact: contact@intelligencex.org (general), contact@intelligencex.org (sales), saas@intelligencex.org (24/7 incident response). ## Services - [Web Application Penetration Testing](https://www.intelligencex.org/services/web-application-penetration-testing): Web application security testing, manual and OWASP-aligned, proves exploitable web app and API flaws with developer-ready fixes. UK, US, EU, India. - [Mobile Application Security Testing](https://www.intelligencex.org/services/mobile-application-security-testing): Android penetration testing and mobile application penetration testing for iOS and Android, OWASP MASVS-aligned, with proof and fixes. UK, US, EU, India. - [Network Penetration Testing](https://www.intelligencex.org/services/network-penetration-testing): Network penetration testing, external and internal, aligned to PTES and NIST SP 800-115, mapped to MITRE ATT&CK. PCI, SOC 2, ISO ready. UK, US, EU, India. - [Cloud Penetration Testing](https://www.intelligencex.org/services/cloud-penetration-testing): Cloud penetration testing for AWS, Azure and GCP that exploits IAM and misconfiguration attack paths, not just flags them. CIS and ATT&CK-mapped. UK, EU, India. - [IoT Security Testing](https://www.intelligencex.org/services/iot-security-testing): IoT security testing across hardware, firmware, wireless, companion apps and cloud APIs. OWASP IoT and ETSI EN 303 645 aligned for EU CRA and UK PSTI evidence. - [Operational Technology (OT) Security](https://www.intelligencex.org/services/ot-security): OT security assessment for ICS, SCADA, PLCs and HMIs using safety-first, passive methods that protect uptime. ISA/IEC 62443 and NIST SP 800-82 aligned. - [Medical Device Security Testing](https://www.intelligencex.org/services/medical-device-security-testing): Medical device security testing, independent and FDA-aligned, across firmware, wireless and apps. Premarket-ready artefacts for 510(k), 524B and EU MDR. - [Secure Code Review](https://www.intelligencex.org/services/secure-code-review): Secure code review combining expert manual analysis and SAST to catch authentication, authorisation and logic flaws tools miss. OWASP-aligned, developer-ready fixes. - [Software Composition Analysis (SCA)](https://www.intelligencex.org/services/software-composition-analysis): Software composition analysis to inventory dependencies, flag CVEs and licence risk, and generate a CycloneDX or SPDX SBOM for EU CRA and DPDP-ready supply chains. - [Threat Modeling](https://www.intelligencex.org/services/threat-modeling): Threat modeling at design stage using STRIDE and PASTA to find architecture weaknesses before they are built. Secure-by-design assurance for the UK, EU and India. - [Red Teaming](https://www.intelligencex.org/services/red-teaming): Red teaming by IntelligenceX: intelligence-led adversary simulation across MITRE ATT&CK, TIBER-EU and CBEST to prove your detection and response. UK, EU, India. - [Root Cause Analysis (RCA)](https://www.intelligencex.org/services/root-cause-analysis): Structured investigation that finds the true cause of an incident or recurring vulnerability and how to prevent recurrence. - [AI / LLM Penetration Testing](https://www.intelligencex.org/services/ai-llm-penetration-testing): AI penetration testing for LLM apps, agents and RAG, OWASP LLM Top 10-aligned, finds prompt injection and data leakage with fixes. UK, US, EU, India. - [Managed Detection and Response (MDR)](https://www.intelligencex.org/services/managed-detection-and-response): 24/7 human-led monitoring, threat hunting and response that catches and stops attacks, not just forwards alerts. - [Endpoint and Network Protection](https://www.intelligencex.org/services/endpoint-and-network-protection): Layered, zero-trust defence across every device and the traffic between them, blocking malware and lateral movement. - [Incident Response and Digital Forensics](https://www.intelligencex.org/services/incident-response-and-forensics): Rapid breach containment, forensic investigation and recovery, with IR retainers and ransomware response. - [Security Awareness Training](https://www.intelligencex.org/services/security-awareness-training): Phishing simulation and an LMS that measurably reduce human risk, powered by CYWAREX. - [Annual Cybersecurity Plan](https://www.intelligencex.org/services/annual-cybersecurity-plan): A prioritised 12-month security roadmap aligned to NIST CSF 2.0, turning ad-hoc spending into a measurable programme. - [Virtual CISO (vCISO)](https://www.intelligencex.org/services/virtual-ciso): Executive-level security leadership on a flexible, fractional basis, without the cost of a full-time CISO. - [Managed Cloud (AWS, Azure & GCP)](https://www.intelligencex.org/services/managed-cloud): Fully managed AWS, Azure and GCP operations covering provisioning, patching, monitoring, cost control and 24/7 support, secured by default. - [Cloud Migration & Modernisation](https://www.intelligencex.org/services/cloud-migration): Plan and execute low-risk migrations to AWS, Azure or GCP, from lift-and-shift to re-architecting for cloud-native scale. - [Cloud Architecture & Well-Architected Review](https://www.intelligencex.org/services/cloud-architecture-well-architected): Design or review your cloud architecture against the Well-Architected Framework for security, reliability, performance and cost. - [FinOps & Cloud Cost Optimisation](https://www.intelligencex.org/services/finops-cloud-cost-optimisation): Cut cloud waste and bring financial accountability to AWS, Azure and GCP spend using the FinOps Foundation framework. - [Disaster Recovery & Backup](https://www.intelligencex.org/services/disaster-recovery-backup): Design and operate resilient backup and disaster recovery for cloud and hybrid workloads, with tested RPO and RTO targets. - [DevOps Consulting & Automation](https://www.intelligencex.org/services/devops-consulting): Assess and improve your delivery practices, then automate build, test and deploy so you ship faster and more safely. - [Managed DevOps](https://www.intelligencex.org/services/managed-devops): An on-demand DevOps team that builds and runs your pipelines, infrastructure and platform so your engineers focus on product. - [CI/CD Pipeline Engineering](https://www.intelligencex.org/services/ci-cd-pipeline-engineering): Design and build fast, secure CI/CD pipelines with automated testing, security gates and reliable deployments. - [Infrastructure as Code (Terraform)](https://www.intelligencex.org/services/infrastructure-as-code): Define your cloud infrastructure as version-controlled, repeatable Terraform or OpenTofu code with modules and guardrails. - [Kubernetes & Containers](https://www.intelligencex.org/services/kubernetes-and-containers): Design, deploy and operate production-grade Kubernetes and container platforms that are secure, scalable and cost-aware. - [Platform Engineering](https://www.intelligencex.org/services/platform-engineering): Build an internal developer platform with golden paths and self-service so teams ship safely without reinventing infrastructure. - [DevSecOps (Secure CI/CD)](https://www.intelligencex.org/services/devsecops): Shift security left by building automated scanning, supply-chain integrity and policy gates directly into your CI/CD pipelines. - [Cloud Security Posture Management (CSPM)](https://www.intelligencex.org/services/cloud-security-posture-cspm): Continuously detect and fix cloud misconfigurations and compliance drift across AWS, Azure and GCP against CIS Benchmarks. - [Site Reliability Engineering (SRE)](https://www.intelligencex.org/services/site-reliability-engineering): Engineer reliability with SLOs, error budgets and automation so your services stay available and on-call stays sane. - [Observability & Monitoring](https://www.intelligencex.org/services/observability-and-monitoring): Implement metrics, logs and traces with OpenTelemetry and Prometheus/Grafana so you can find and fix issues fast. - [AI / MLOps Enablement](https://www.intelligencex.org/services/ai-mlops-enablement): Operationalise machine learning with CI/CD for models, a model registry, monitoring and governance so AI runs reliably in production. ## Compliance & Audit - [ISO/IEC 27001](https://www.intelligencex.org/compliance/iso-27001): ISO 27001 certification readiness: ISMS gap assessment, design and Stage 1 & 2 audit support by lead auditors. UK, US, EU and India procurement. - [SOC 2](https://www.intelligencex.org/compliance/soc-2): SOC 2 Type I and Type II readiness against the Trust Services Criteria, with CPA-firm liaison. - [PCI DSS](https://www.intelligencex.org/compliance/pci-dss): PCI DSS compliance done right: v4.0.1 scoping, gap assessment and SAQ/QSA support by cardholder-data experts. UK, US, EU and India merchants. - [GDPR](https://www.intelligencex.org/compliance/gdpr): GDPR compliance advisory for EU, UK, US & India: gap assessment, data mapping, DPIAs, DSAR workflows and an ISO 27701 path to demonstrable accountability. - [HIPAA](https://www.intelligencex.org/compliance/hipaa): HIPAA Security Rule risk analysis, gap assessment and safeguard remediation for PHI. - [NIST Cybersecurity Framework 2.0](https://www.intelligencex.org/compliance/nist-csf-2): NIST CSF 2.0 maturity assessment across all six functions incl. Govern: current/target profile, tiers and a prioritised roadmap mapped to ISO 27001 & SOC 2. - [ISO/IEC 27017](https://www.intelligencex.org/compliance/iso-27017): ISO 27017 cloud security controls assessed as an extension to your ISO 27001 ISMS by cloud specialists. Prove shared-responsibility assurance globally. - [ISO/IEC 27018](https://www.intelligencex.org/compliance/iso-27018): ISO 27018 cloud PII protection controls assessed within your ISO 27001 audit, mapped to GDPR Article 28. For public cloud and SaaS processors. - [ISO/IEC 27701](https://www.intelligencex.org/compliance/iso-27701): ISO 27701 advisory for UK, EU & India: PIMS gap analysis, design and audit-readiness support, mapped to GDPR and DPDP. Certify in 3-5 months. - [Cyber Crisis Management Plan](https://www.intelligencex.org/compliance/cyber-crisis-management-plan): Board-endorsed cyber crisis plans with scenario playbooks and tabletop exercises. - [SDLC Gap Analysis](https://www.intelligencex.org/compliance/sdlc-gap-analysis): Secure SDLC maturity assessment against NIST SSDF and OWASP SAMM, with a roadmap to embed security in development. - [RBI IS Audit](https://www.intelligencex.org/compliance/rbi-is-audit): RBI IS audit for banks and NBFCs against the RBI Cyber Security Framework and IT Governance Master Direction, by a qualified, CERT-In-aligned team in India. - [CERT-In Security Audit](https://www.intelligencex.org/compliance/cert-in-audit): CERT-In audit empanelment readiness: comprehensive ICT audit and Section 70B compliance (6-hour reporting, 180-day in-India logs, NTP sync) for India. - [DPDP Act 2023](https://www.intelligencex.org/compliance/dpdp-act): DPDPA readiness for India's DPDP Act 2023 and 2025 Rules: consent architecture, DPIAs, breach response and SDF data audits, with full compliance due 13 May 2027. - [SEBI CSCRF](https://www.intelligencex.org/compliance/sebi-cscrf): SEBI Cybersecurity and Cyber Resilience Framework compliance: graded controls, VAPT, cyber audit and SBOM. - [IRDAI Compliance Audit](https://www.intelligencex.org/compliance/irdai-audit): IRDAI audit against the 2023 Information and Cyber Security Guidelines: CISO governance, VAPT and IS audit by a qualified, CERT-In-aligned team for India's insurers. - [RBI Payment Aggregator Audit](https://www.intelligencex.org/compliance/rbi-payment-aggregator-audit): CERT-In-aligned system and cybersecurity audit for payment aggregators, supporting the SAR for RBI. - [SAR Compliance Audit](https://www.intelligencex.org/compliance/sar-audit): Regulator-format System Audit Report readiness and support for RBI-regulated entities. - [CICRA Compliance](https://www.intelligencex.org/compliance/cicra): Credit Information Companies Regulation Act (CICRA) advisory for India: data-security gap assessment, credit-data VAPT and CISA-led specified-user certification under RBI. - [IT General Controls (ITGC)](https://www.intelligencex.org/compliance/itgc): ITGC design and operating-effectiveness testing for financial audits, IFC reporting and SOC readiness. - [Digital Lending Application Audit](https://www.intelligencex.org/compliance/digital-lending-audit): RBI Digital Lending Directions 2025 audit of DLAs and LSPs: borrower protection, data localisation, KFS/APR and DLG. ## Products - [CERTX](https://www.intelligencex.org/products/certx): All-in-one risk and compliance management: cyber asset discovery, continuous compliance for 20+ frameworks and multi-cloud monitoring. - [DARKX](https://www.intelligencex.org/products/darkx): Real-time dark web monitoring across TOR, I2P and paste sites, with AI-powered analysis and SOC-validated alerts. - [CSPMX](https://www.intelligencex.org/products/cspmx): Detect, monitor and auto-remediate cloud misconfigurations with real-time scanning and AI-driven detection. - [CYWAREX](https://www.intelligencex.org/products/cywarex): Phishing simulation and a built-in LMS for programmatic human risk management. - [AIPTX](https://www.intelligencex.org/products/aiptx): AI-augmented penetration testing as a service: continuous, autonomous attack-surface testing with human-validated findings and clear remediation guidance. - [ConsentX](https://www.intelligencex.org/products/consentx): Cookie and tracker consent management for the web: scan what fires on your site, block it until consent is given and keep auditable records, GDPR and DPDP ready. - [TrustDesk](https://www.intelligencex.org/products/trustdesk): Publish your security posture in a live trust center and automate security questionnaire responses, so deals move faster and proof is always one link away. - [Regulatory Bridge](https://www.intelligencex.org/products/regulatorybridge): Stay ahead of changing regulations: track regulatory updates across jurisdictions, map each obligation to your controls and turn new requirements into assigned, audit-ready actions. ## Resources - [What is VAPT? Vulnerability Assessment and Penetration Testing Explained](https://www.intelligencex.org/resources/what-is-vapt): VAPT combines automated vulnerability assessment with manual penetration testing to find and prove exploitable security weaknesses. A clear 2026 guide. - [How Much Does a Penetration Test Cost in 2026?](https://www.intelligencex.org/resources/penetration-testing-cost): Penetration testing typically costs USD 5,000 to 35,000 depending on scope. A breakdown of what drives pentest pricing and how to budget. - [SOC 2 vs ISO 27001: Which Does Your Business Need?](https://www.intelligencex.org/resources/soc-2-vs-iso-27001): SOC 2 is a US attestation report; ISO 27001 is a global certification. A practical comparison to help you choose, or do both efficiently. - [DPDP Act 2023 Explained: Deadlines, Penalties and How to Comply](https://www.intelligencex.org/resources/dpdp-act-2023-explained): India's DPDP Act and 2025 Rules: who must comply, the phased deadlines to May 2027, penalties up to INR 250 crore, and how to prepare. - [CERT-In's 6-Hour Incident Reporting Rule: What You Must Do](https://www.intelligencex.org/resources/cert-in-6-hour-incident-reporting): CERT-In requires cyber incidents to be reported within 6 hours, plus 180-day in-India log retention and NTP sync. A compliance guide. - [MDR vs EDR vs XDR: What's the Difference?](https://www.intelligencex.org/resources/mdr-vs-edr-vs-xdr): EDR and XDR are tools; MDR is a managed service. A clear explanation of how they differ and which your organisation needs. - [OWASP Top 10 2025: The Updated List Explained (A01-A10)](https://www.intelligencex.org/resources/owasp-top-10-2025): A clear guide to the OWASP Top 10 2025: every category A01 to A10 with a crisp definition and one mitigation, plus how to test and fix each risk. - [India Cybersecurity & Data-Protection Compliance: DPDP, CERT-In, RBI, SEBI and IRDAI Explained](https://www.intelligencex.org/resources/india-cybersecurity-compliance-dpdp-certin-rbi): A buyer's guide to India's cybersecurity and data-protection stack: DPDP Act 2023, CERT-In 6-hour reporting, RBI IS audit, SEBI CSCRF and IRDAI obligations. ## Key pages - [About](https://www.intelligencex.org/about) - [Contact](https://www.intelligencex.org/contact) - [Brand kit](https://www.intelligencex.org/brand)