API Security Testing in Delhi NCR · Gov, India Stack & Enterprise
OWASP API Top 10 testing for citizen-facing portals, India-Stack integrations and enterprise B2B APIs — CERT-In and DPDP-aligned across Delhi, Gurugram and Noida.
How a Macksofy api pentest engagement runs in Delhi NCR.
Delhi NCR runs on integration APIs — citizen-facing government and PSU portals, India-Stack consumers (Aadhaar e-KYC, DigiLocker, UPI, e-Sign), and the large-enterprise B2B estates clustered in Gurugram's Cyber City and Noida's Sector-62/Sector-135 belt. These APIs carry identity and entitlement, not just data, which is exactly why their authorization flaws matter more. Macksofy tests them against the OWASP API Security Top 10 (2023), with senior consultants who deliver across the NCR and report in the language CERT-In and departmental auditors expect.
Citizen-facing portals are where BOLA (API1) does the most damage, because the object an attacker pivots to is another citizen's record — a benefit status, an application, a document, a grievance. We test object-level authorization with two authenticated personas, and we pay particular attention to the predictable identifiers (application numbers, beneficiary IDs, sequential references) that make enumeration trivial. Broken function-level authorization (API5) is the companion finding: a citizen token reaching an officer/admin endpoint, or a verification function exposed without the maker-checker control the workflow assumes.
India-Stack integrations carry their own scope. Wherever a portal consumes Aadhaar e-KYC, DigiLocker document-pull, UPI or e-Sign, we test the integration boundary — token and consent handling, response-trust (unsafe consumption of upstream APIs, API10), SSRF on document-pull and callback URLs (API7), and the data-exposure risk of caching or logging identity responses. For Aadhaar-touching flows we test against the data-minimisation and storage expectations the UIDAI framework and DPDP both push toward, because over-retention of identity data is the finding that turns a portal flaw into a notifiable breach.
Enterprise NCR APIs — the Gurugram fintech and insurtech belt, the Noida IT/ITeS and e-commerce estates, the manufacturing and auto majors' partner portals — bring B2B and partner-integration scope: machine-to-machine auth, partner-token scoping, webhook SSRF, and the business-flow abuse (API6) that lives in onboarding, pricing and settlement APIs. We test unrestricted resource consumption (API4) on anything that fronts a cost or an enumeration oracle, and we surface shadow and zombie endpoints (API9) — the forgotten partner API still live after a migration, a recurring source of NCR incidents.
The deliverable is built for the NCR compliance reality: findings map to the CERT-In empanelled audit format and the six-hour incident-reporting posture, to DPDP reasonable-security-safeguards (and the Significant-Data-Fiduciary lens where the operator is large), and — for portals serving notified critical sectors — to the NCIIPC expectations for protected systems. Every High and Critical carries a manual proof-of-exploit, CVSS v3.1, and a remediation an engineering or empanelled-vendor team can action. For government and PSU buyers we provide the documentation and evidence pack a departmental audit or a CAG-aligned review will ask for.
Procurement in the NCR is its own discipline — GeM listings, departmental tender cycles, PSU committee approvals and enterprise vendor-security onboarding. We size proposals to fit, attach the empanelled-auditor letter and the Macksofy ISMS pack up front, and provide the re-test (every Critical and High inside a 60-day window, in the base SoW) that inspection follow-ups require. Onsite is same-day across Gurugram Cyber City, Noida and central Delhi, with the wider NCR — Greater Noida, Manesar, Faridabad — inside the same testing week.
Five phases. Delhi NCR timeline.
Every Macksofy api pentest engagement in Delhi NCR runs through the same phased protocol — adapted to Delhi NCR-specific procurement, regulator and delivery realities.
- Phase 01
Scope & API inventory
Week 1- Reconcile portal and partner API estate from gateway, specs and traffic — surface shadow/zombie endpoints (API9) left by migrations
- Provision two authenticated personas per role (citizen, officer, partner, admin) for authorization testing
- Identify India-Stack integration points (Aadhaar e-KYC, DigiLocker, UPI, e-Sign) and identity-data flows
- Crosswalk CERT-In / DPDP / NCIIPC requirements to target buckets; sign RoE with the department or enterprise security owner
- Phase 02
Auth & access modelling
Weeks 1–2- Token, session and machine-to-machine / partner-token model — scope, expiry and revocation
- Object-ownership map for BOLA (API1) with attention to predictable identifiers and enumeration
- Function-to-role map for BFLA (API5) — citizen vs officer/admin and maker-checker controls
- India-Stack consent and response-trust model for each integration boundary
- Phase 03
Manual exploitation
Weeks 2–4- BOLA/BFLA/BOPLA exploitation across citizen and partner roles; enumeration and mass-assignment proofs
- India-Stack boundary tests — consent handling, unsafe upstream consumption (API10), SSRF (API7) on document-pull/callbacks
- Identity-data exposure checks — caching, logging and over-retention of Aadhaar/KYC responses
- Business-flow abuse (API6) and resource-consumption (API4) on onboarding, pricing and settlement endpoints
- Phase 04
Audit reporting
Weeks 4–5- Per-finding proof-of-exploit, CVSS v3.1 and remediation for engineering / empanelled-vendor action
- Mapping to CERT-In empanelled format, DPDP/SDF and (for notified sectors) NCIIPC protected-system expectations
- Departmental / CAG-aligned documentation and evidence pack
- Findings export with owner, severity, CWE and the six-hour incident-reporting linkage
- Phase 05
Re-test & closure
Weeks 5–6- 60-day re-test of every Critical and High at no extra cost
- CERT-In empanelled closure letter and inspection-defence support
- Gateway and identity-integration hardening guidance
- Carry-forward backlog for the next assessment cycle
- Phase 01Week 1
Scope & API inventory
- Reconcile portal and partner API estate from gateway, specs and traffic — surface shadow/zombie endpoints (API9) left by migrations
- Provision two authenticated personas per role (citizen, officer, partner, admin) for authorization testing
- Identify India-Stack integration points (Aadhaar e-KYC, DigiLocker, UPI, e-Sign) and identity-data flows
- Crosswalk CERT-In / DPDP / NCIIPC requirements to target buckets; sign RoE with the department or enterprise security owner
- Phase 02Weeks 1–2
Auth & access modelling
- Token, session and machine-to-machine / partner-token model — scope, expiry and revocation
- Object-ownership map for BOLA (API1) with attention to predictable identifiers and enumeration
- Function-to-role map for BFLA (API5) — citizen vs officer/admin and maker-checker controls
- India-Stack consent and response-trust model for each integration boundary
- Phase 03Weeks 2–4
Manual exploitation
- BOLA/BFLA/BOPLA exploitation across citizen and partner roles; enumeration and mass-assignment proofs
- India-Stack boundary tests — consent handling, unsafe upstream consumption (API10), SSRF (API7) on document-pull/callbacks
- Identity-data exposure checks — caching, logging and over-retention of Aadhaar/KYC responses
- Business-flow abuse (API6) and resource-consumption (API4) on onboarding, pricing and settlement endpoints
- Phase 04Weeks 4–5
Audit reporting
- Per-finding proof-of-exploit, CVSS v3.1 and remediation for engineering / empanelled-vendor action
- Mapping to CERT-In empanelled format, DPDP/SDF and (for notified sectors) NCIIPC protected-system expectations
- Departmental / CAG-aligned documentation and evidence pack
- Findings export with owner, severity, CWE and the six-hour incident-reporting linkage
- Phase 05Weeks 5–6
Re-test & closure
- 60-day re-test of every Critical and High at no extra cost
- CERT-In empanelled closure letter and inspection-defence support
- Gateway and identity-integration hardening guidance
- Carry-forward backlog for the next assessment cycle
Which Delhi NCR verticals we deliver API Pentest for.
Government & PSU portals
Citizen-facing service and grievance APIs — BOLA on predictable IDs, maker-checker gaps, CERT-In and departmental-audit evidence.
India-Stack consumers
Aadhaar e-KYC, DigiLocker, UPI and e-Sign integrations — consent, response-trust, SSRF and identity-data over-retention testing.
Gurugram fintech & insurtech
Lending, card, wallet and policy APIs — BOLA/BFLA, partner-token scoping and business-flow abuse with DPDP evidence.
Noida IT/ITeS & e-commerce
Order, pricing, catalogue and partner APIs — rate-limit/enumeration abuse and webhook SSRF testing.
Manufacturing & auto (NCR/Manesar)
Dealer, supply-chain and partner-portal APIs — machine-to-machine auth and partner-integration trust testing.
Healthcare & edtech (NCR)
PHI/PII-bearing APIs with strict object-level authorization and data-exposure testing; DPDP-aligned evidence.
The Delhi NCR deliverable pack.
Every Delhi NCR api pentest engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.
- API security report mapped to OWASP API Top 10 (2023) with CERT-In / DPDP / NCIIPC crosswalk
- Manually-validated proof-of-exploit per High/Critical with CVSS v3.1 + remediation
- Authorization evidence — BOLA/BFLA test matrix across citizen, officer and partner roles
- India-Stack integration findings — consent, response-trust, SSRF and identity-data exposure
- Shadow/zombie API inventory with gateway-governance recommendations
- Departmental / CAG-aligned documentation and evidence pack
- Free re-test of every Critical and High inside a 60-day window
- CERT-In empanelled closure letter and inspection-defence support
A Delhi NCR api pentest case study.
API assessment — ~70 endpoints across application, status, document and grievance APIs plus an e-KYC and DigiLocker integration; OWASP API Top 10 with CERT-In/DPDP evidence
BOLA on the application-status API exposing any citizen's record via a sequential ID, and over-retention of full e-KYC responses in application logs, both remediated pre-disclosure; predictable identifiers replaced and identity-data logging redacted before the departmental security review.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions Delhi NCR buyers ask before signing.
Other Macksofy engagements in Delhi NCR.
Same engagement, other Macksofy metros.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
