R Rajkot  ·  Gujarat  ·  India  ·  Operating since 2020

We are the people you'd call
to break in.

SURAPURA is a small offensive security team out of Rajkot. Pentesters, bug-bounty hunters, red-teamers, SOC analysts — people who've broken into things and people who've cleaned up after the people who broke in. We do for paying clients what we used to do at 2:45 AM for the local SME with no plan and a ringing phone.

2020 First engagement, Rajkot
~6 yrs On the offensive side
0 Repeat breaches on our watch
— 01 · Where we come from

We started by breaking in,
not selling fences.

Most security companies build walls. We learned the trade from the other side — bug bounty platforms, CTFs, and the unglamorous work of triaging real exploits at 3am. By the time we started writing invoices, we'd already written exploit chains.

That's still the lens. Every audit, every program, every incident we touch is shaped by the attacker's mindset, because half the team has actually been the attacker. We are the people you'd want to hire to break in. So you do.

The plan was never to start a company. The plan was to be the team a friend's small business could call when their accounts manager forwarded a phishing email and clicked the link. Everything else came after. — founders' note · 2020
FORTE · OFFENSIVE OUTSIDE · ATTACKER VIEW INSIDE · DEFENDER VIEW we work both sides of the wall attacker probes verified controls
— 02 · Incident response

Six years of 2:45 AM
phone calls.

When a Rajkot SME gets ransomwared on a Tuesday night, when a GIDC factory's OT network stops responding, when a clinic's patient records start moving to a domain registered three days ago — we're the team that picks up.

IR · NIGHT SURAPURA on call ! TONIGHT'S TIMELINE 02:45 phone 03:12 on-bridge 04:30 contained 06:45 recovered 09:00 hardened FIELD-1

SURAPURA was the first responder for cybersecurity incidents across Rajkot and Gujarat for businesses that had nowhere else to turn. We've contained active breaches, recovered encrypted file servers, killed malware mid-spread, and put hardening between the door and the next attempt. Most of those clients are still ours — and have not been hit again.

From ransomware on small businesses to targeted intrusions on industrial networks in GIDC zones, we've seen it, contained it, and prevented its return. The local trade still calls us first. The work taught us everything we now sell as a service.

On-ground response anywhere in Rajkot & Gujarat. When remote isn't enough, the team drives. Some incidents need hands on keyboards in your server room — not tickets in a queue.

<1h
Emergency response
100%
Containment rate
24×7
On-call availability
0
Repeat breaches
Response capabilities
Ransomware containment, recovery, and decryption coordination
Malware analysis and reverse engineering
Breach investigation, forensics, and timeline reconstruction
Network compromise assessment and lateral-movement audit
Post-incident hardening and ongoing detection content
Physical on-site deployment across Rajkot & Gujarat
— 03 · The team

Four roles.
One muscle memory.

Every person here has hands-on offensive experience — pentesting, hunting, red-teaming, or running detection against the same TTPs they used to throw. Nobody on this team has ever been "in security" without first having broken something. The four roles below describe what we sell, but the line between them inside the team is mostly imaginary.

01

Penetration Testers

Web · API · Mobile · Cloud

Manual exploitation that scanners can't replicate. Our pentesters chain low-severity bugs into critical exploits through creative attack paths — IDOR + BAC + SSRF doesn't show up on a scan dashboard. It shows up here.

Burp SuiteCaidoNucleiManual
02

Bug Bounty Hunters

HackerOne · Bugcrowd · Synack

Active hunters with track records on the major platforms. Recon-heavy, business-logic-curious, scope-respecting — we bring the crowd's creativity with the discipline of operators who file reports clients actually want to read.

ReconIDORBACLogic flaws
03

Red Team Operators

Adversary simulation · Purple team

Full-spectrum campaigns — phishing, payload delivery, foothold, lateral movement, exfil. Mapped to MITRE ATT&CK. Debriefed in purple-team sessions so your blue team gets stronger every engagement, not just shamed.

MITRE ATT&CKC2PhishingPivoting
04

SOC Analysts

Detection · Response · Threat hunting

Detection content written by people who've been on the offensive side of the kill chain. They know what attackers look like in logs because they've generated those logs themselves — for paying clients, on purpose.

SIEMThreat huntingIRForensics
— 04 · House rules

Six rules.
We'd lose a deal
before we'd break them.

Principles forged in real engagements. Most weren't written; they were learned the hard way and got pinned to the wall after. They're the difference between a security partner and a vendor with a logo.

RULE / 01

Think like the threat.

Every assessment starts with one question: "If I wanted to destroy this company, where would I begin?" That perspective shapes everything — scope, depth, and what the final report leads with.

RULE / 02

If we can't exploit it, we don't ship it.

No theoretical risks. No scanner noise. No padding the report to look thorough. Every finding lands in your tracker with a working PoC. If it's there, it's reproducible. If we can't reproduce it, you'll never see it.

RULE / 03

Rajkot grounded. Globally operational.

We started by protecting local businesses from real, dangerous threats. That urgency — the 2 AM call, the on-site drive — never left the operating model. We serve clients across continents, but the muscle memory is local.

RULE / 04

Zero ego, your team is our team.

We work alongside your engineers, not above them. Knowledge transfer is part of every engagement — not an upsell. When we leave, your team is genuinely stronger than when we arrived. That's the whole point.

RULE / 05

Continuous offence.

Attackers don't stop after a quarterly review, so neither do we. Our managed programs deliver continuous offensive pressure — not annual checkbox exercises that expire the day after the certificate is printed.

RULE / 06

CVSS scores don't pay fines.

We prioritise findings by real-world business impact — revenue loss, regulatory exposure, contract risk, reputational damage — not just the score on top of a CVE entry. The auditor will love it. So will your CFO.

written by people on the keyboard · not the marketing deck
Rajkot. Where it started. Where the on-call lives. The local trade still calls us first.
Gujarat. On-ground field response across GIDC, Ahmedabad, Surat, Vadodara — same-day if the road allows.
India. Remote engagements for product and SaaS teams from Bengaluru to Pune to Gurgaon.
Globally. Clients across UAE, EU, and the US. Async-first when needed; on a bridge call when it isn't.
— Want to work with us?

Hand us your
riskiest thing.

30 minutes. No deck. Tell us what's keeping you up — pre-launch app, audit deadline, noisy alerts, missing playbook, an incident in progress — and we'll tell you exactly how we'd handle it, what the timeline looks like, and whether we're the right team to call.

What you walk away with
  • A scoped engagement plan you can actually approve
  • Sample deliverables from a similar prior engagement (sanitized)
  • A fixed price, fixed timeline, named lead consultant
  • An honest read on whether we're the right team for it