Skip to content

Company / Evidence Register

The evidence register, published

Several pages on this site say the same thing: every factual claim we publish is maintained in an internal evidence register, and you're welcome to ask us to show our work. This page is us showing it, before you ask.

What this page is

Internally, every claim intended for this website gets a register row before it is written into a page: the claim, its source, how it was verified, and any caveat it must carry. The table below is the public view of that register: 37 rows, one per published claim or claim family, each showing the claim as it appears on the site, the class of evidence behind it, the date it was last verified, and the pages where it lives. The row IDs are the real internal ones, so if you ever want a specific claim substantiated, you can cite the row.

Why publish it? Because assurance vendors ask you to take a lot on faith, and we grade other people’s software for a living. A firm that does that should be auditable the same way. Publishing the register also keeps us honest structurally: a claim that can’t survive a row in this table doesn’t ship.

What you won’t find here, and why

  • Client names beyond those already public on this site through consented testimonials and the consented logo wall. Our case studies are anonymized by policy: sector descriptors only.
  • Claims held back pending evidence. If a fact hasn’t cleared verification, it isn’t on the site, so it has no row here.
  • Outcome percentages for our platforms and services. None are measured to a standard we’d publish, so we publish none.
  • Internal source files, reviewer notes, and evidence documents. Those are shared under NDA during vendor due diligence.

The register

37 published rows, grouped by subject. Verification dates reflect the most recent dated check recorded on the row; undated rows carry 2026-08-02, the date of the last full-register review.

RowClaim as publishedEvidence classLast verifiedWhere it appears
Company facts
W1“Independent quality engineering and cybersecurity partner”Owner attestation, dated; independence model published in full2026-08-02Home · Trust
W2“We don’t build what we test, and we don’t resell what we recommend”Owner attestation, dated (business-model fact)2026-08-02Trust · Why VirtuesTech
W3“Founded in Hyderabad in 2020” / “since 2020”MCA registry record2026-08-02About · Trust
W48Incorporated January 2020; CIN U72900TG2020PTC138226, ROC HyderabadMCA registry record2026-08-02Trust · Contact
W4“100+ security and quality engineers”Owner attestation, dated2026-08-02Home · About
W5“63% of our engineers hold industry certifications (CISSP, CEH, eCPPT, ISTQB, AWS)”Owner attestation, dated (internal certification records)2026-08-02Trust · Vendor guide
W6“30+ enterprise engagements · 20+ clients”Owner engagement records2026-08-02Home · About
W7Two delivery hubs with full street addresses: Hyderabad, India and Frisco, TX, USA; published phone numbers and emailOwner-published business records2026-07-17Contact · Trust
Leadership
W8Founder & CEO Venkata Ramana Pullagoora, 26+ years in ITOwner attestation, dated2026-07-21About
W39Leadership roster: Founder & CEO plus Business Advisor Hemanth Kumar KV (around two decades in IT delivery and product strategy)Owner-published biographies2026-07-17About
W9Cybersecurity practice led by Mahesh Tata, 14+ years in securityOwner attestation, dated2026-07-17Cybersecurity · Red Teaming
Platforms
W15“2,250+ MITRE ATT&CK-mapped detection rules”; UEBA; autonomous loop in production since June 2026, under analyst supervision with human approval gatesOwner-published product data (live platform dashboard)2026-07-16VirtueShieldX
W17VirtueShieldX: AI-driven security operations with analyst supervision of consequential decisionsOwner-published product data2026-08-02VirtueShieldX · Responsible AI
W16VirtueThreatX: CTEM platform covering Scope, Discover, Prioritize, Validate, Mobilize; screenshots captured from the live platform (demo organization)Owner-published product data (live-platform captures)2026-07-17VirtueThreatX
W46VirtueThreatX: “9 attack surfaces (web, API, network, code, mobile, cloud, container, identity, and AI/LLM)”Owner-published product data (engines listed by name on the product site)2026-07-21VirtueThreatX · Responsible AI
W18VirtueATLAS: AI-powered quality engineering suite; self-healing automation; Jenkins, GitHub, GitLab, Azure DevOps, and Jira integrationsOwner-published product data2026-08-02VirtueATLAS
Delivery, methodology, and tooling
W26Testing aligned to the OWASP Testing Guide, PTES, and NIST SP 800-115, with retest included as standardOwner-published methodology2026-07-14Methodology · PTaaS
W12“We test and report against GDPR, HIPAA, PCI DSS, SOC 2, ISO 27001 requirements” (your frameworks; never a certification claim about us)Owner attestation, dated (capability statement)2026-08-02Compliance audits · Cybersecurity
W25Managed SOC standard SLA targets (P1 acknowledged within 15 minutes, tiers to 4 hours at P4), 30-day pilot, onboarding within 90 days: published with the caveat that final SLAs are committed in your service agreementOwner attestation, dated; caveat published with the claim2026-07-15Managed SOC
W49“You’ll hear back from an engineer, typically within one business day”Owner attestation, dated (“typically” qualifier required; never a guaranteed SLA)2026-07-17Contact
W13Security tooling: Burp Suite Pro, OWASP ZAP, Nmap, Nessus, Nuclei, SecurityTrails; AWS, Azure, GCP, Oracle cloud coverageOwner attestation (capability statement; no partnership implied)2026-08-02Technology Ecosystem
W14SOC stack: Wazuh, ThreatFox plus curated feeds, Trivy, in-house SIEM, detection, and SOAROwner attestation (capability statement; no partnership implied)2026-08-02Technology Ecosystem · VirtueShieldX
W37QE frameworks our engineers work in: Selenium, Playwright, Cypress, Appium, JMeter, k6, Postman/Newman, REST Assured, axe, LighthouseOwner attestation (capability statement; no partnership implied)2026-08-02Technology Ecosystem · Quality Engineering
Client proof
W19Testimonial: Rajasekhara Saidam, Information Security Officer, HackerEarth (three years of working together)Client-consented testimonial, named, verbatim2026-07-20Home · Why VirtuesTech
W20Testimonial: Jonathan Andrews, CEO / President, Weston InfoSecClient-consented testimonial, named, verbatim2026-07-20Home · Why VirtuesTech
W21Testimonial: Damon DeCrescenzo, CEO, The Credit ProsClient-consented testimonial, named, verbatim2026-07-20Home · Why VirtuesTech
W28Client logo wall (17 client logos)Client-consented logo placement (relationship signal only)2026-07-14Home
W29Sample penetration-test report, downloadable without a formRedacted deliverable from a real engagement (client, endpoints, and evidence removed)2026-08-02PTaaS · API Security Testing
W38AI-platform API VAPT case study: three High-severity findings demonstrated, remediated, and verified on a clean retestEngagement records, anonymized; retest report on file2026-08-02Case study
W24Case studies: a 300+ API security assessment, a SaaS platform VAPT, and a three-year continuous VAPT programEngagement records, anonymized2026-08-02API assessment · SaaS VAPT · Three-year program
W43Automotive QE and DevOps case study (scope and approach; no outcome metrics published because none are measured yet)Engagement records, anonymized2026-07-20Case study
W44Banking automation, performance, and security case study (scope and approach; no outcome metrics published because none are measured yet)Engagement records, anonymized2026-07-20Case study
W4717 anonymized engagement summaries, listed by industry descriptor with the services deliveredOwner engagement records, anonymized by policy2026-07-20Customer Stories
W23Industries served: BFSI, healthcare, fintech, retail and e-commerce, edtech, media, energy, and othersOwner engagement records2026-08-02Industries
AI and data commitments
W50“Client data is never used to train models” (any VirtuesTech platform)Owner attestation, dated2026-08-03Responsible AI
Third-party statistics
W22Market statistics used on this site, each with named source and year: IBM 2025 ($10.22M average US breach cost), Verizon DBIR 2025, ISC2 2024, Akamai 2017, Deloitte 2020Third-party reports, named source + year2026-07-22Cybersecurity · Insights
Certification status
W40“We hold no organizational certification today and do not claim otherwise. ISO 27001 certification for VirtuesTech is planned (stated July 2026).”Owner attestation, dated intent2026-07-17Trust

The standing offer

If you find a factual claim on this site (a number, a name, a date, an outcome) that isn’t covered by a row in this table, tell us at info@virtuestech.com. We’ll either add the row with its evidence or correct the page. The same address works in the other direction: cite any row ID above during due diligence and we’ll walk you through the underlying evidence, under NDA where the material requires it.

The wider claim-discipline policy, including what we refuse to publish, is on the Trust & Company Facts page. How engagements themselves are governed is on the methodology page.

Not sure where to start?

A plain-language conversation about your product, your risk, and what to do first.