Security testers and auditors under one roof.
SECOMPS was founded on a simple observation: companies hire one firm to attack their systems and another to certify them, and the two never compare notes. We built a team that does both.
At a glance
- Based in
- Thane, India. Working worldwide.
- Disciplines
- Offensive security and compliance consulting
- Team
- Certified testers and audit practitioners
- Model
- Fixed-scope engagements, not open-ended retainers
The gap between attack and audit.
Most organisations buy security testing and compliance separately. The testing firm produces a report written for engineers. The compliance firm produces policies written for auditors. Neither document references the other, and the organisation ends up paying twice to answer one question: are we actually secure, and can we prove it.
We built SECOMPS to close that gap. Our penetration test reports are structured from the outset as audit evidence, with findings mapped to the controls your assessor will test. Our compliance work is grounded in what we find breaking real systems every week, rather than in a control library copied from a template.
We are a specialist team, not a testing factory. That shapes what we take on: we scope engagements we can staff properly, we tell you when you are buying the wrong service, and we would rather turn down work than deliver a report we would not sign our name to.
How we work
We are a specialist team, not a testing factory. That shapes what we take on: we scope engagements we can staff properly, we tell you when you are buying the wrong service, and we would rather turn down work than deliver a report we would not sign our name to.
Founder and senior team profiles are coming soon - buyers of boutique security services are buying specific people, and we will not ship anonymous placeholder bios.
What we believe.
We do not report theoreticals as criticals. If we could not demonstrate it, we say so plainly and let you prioritise accordingly.
A finding your engineer cannot reproduce is not a finding, it is a support ticket you now have to answer.
Every call is with a security engineer. You should be able to ask a technical question and get a technical answer.
If a service will not help you, we will tell you, including when that means a smaller invoice or none at all.
Work with people who will tell you the uncomfortable part.
Tell us about your environment and we will come back with a scoped quote and a start date.