Company / Evidence Register
The evidence register, published
Several pages on this site say the same thing: every factual claim we publish is maintained in an internal evidence register, and you're welcome to ask us to show our work. This page is us showing it, before you ask.
What this page is
Internally, every claim intended for this website gets a register row before it is written into a page: the claim, its source, how it was verified, and any caveat it must carry. The table below is the public view of that register: 37 rows, one per published claim or claim family, each showing the claim as it appears on the site, the class of evidence behind it, the date it was last verified, and the pages where it lives. The row IDs are the real internal ones, so if you ever want a specific claim substantiated, you can cite the row.
Why publish it? Because assurance vendors ask you to take a lot on faith, and we grade other people’s software for a living. A firm that does that should be auditable the same way. Publishing the register also keeps us honest structurally: a claim that can’t survive a row in this table doesn’t ship.
What you won’t find here, and why
- Client names beyond those already public on this site through consented testimonials and the consented logo wall. Our case studies are anonymized by policy: sector descriptors only.
- Claims held back pending evidence. If a fact hasn’t cleared verification, it isn’t on the site, so it has no row here.
- Outcome percentages for our platforms and services. None are measured to a standard we’d publish, so we publish none.
- Internal source files, reviewer notes, and evidence documents. Those are shared under NDA during vendor due diligence.
The register
37 published rows, grouped by subject. Verification dates reflect the most recent dated check recorded on the row; undated rows carry 2026-08-02, the date of the last full-register review.
| Row | Claim as published | Evidence class | Last verified | Where it appears |
|---|---|---|---|---|
| Company facts | ||||
| W1 | “Independent quality engineering and cybersecurity partner” | Owner attestation, dated; independence model published in full | 2026-08-02 | Home · Trust |
| W2 | “We don’t build what we test, and we don’t resell what we recommend” | Owner attestation, dated (business-model fact) | 2026-08-02 | Trust · Why VirtuesTech |
| W3 | “Founded in Hyderabad in 2020” / “since 2020” | MCA registry record | 2026-08-02 | About · Trust |
| W48 | Incorporated January 2020; CIN U72900TG2020PTC138226, ROC Hyderabad | MCA registry record | 2026-08-02 | Trust · Contact |
| W4 | “100+ security and quality engineers” | Owner attestation, dated | 2026-08-02 | Home · About |
| W5 | “63% of our engineers hold industry certifications (CISSP, CEH, eCPPT, ISTQB, AWS)” | Owner attestation, dated (internal certification records) | 2026-08-02 | Trust · Vendor guide |
| W6 | “30+ enterprise engagements · 20+ clients” | Owner engagement records | 2026-08-02 | Home · About |
| W7 | Two delivery hubs with full street addresses: Hyderabad, India and Frisco, TX, USA; published phone numbers and email | Owner-published business records | 2026-07-17 | Contact · Trust |
| Leadership | ||||
| W8 | Founder & CEO Venkata Ramana Pullagoora, 26+ years in IT | Owner attestation, dated | 2026-07-21 | About |
| W39 | Leadership roster: Founder & CEO plus Business Advisor Hemanth Kumar KV (around two decades in IT delivery and product strategy) | Owner-published biographies | 2026-07-17 | About |
| W9 | Cybersecurity practice led by Mahesh Tata, 14+ years in security | Owner attestation, dated | 2026-07-17 | Cybersecurity · Red Teaming |
| Platforms | ||||
| W15 | “2,250+ MITRE ATT&CK-mapped detection rules”; UEBA; autonomous loop in production since June 2026, under analyst supervision with human approval gates | Owner-published product data (live platform dashboard) | 2026-07-16 | VirtueShieldX |
| W17 | VirtueShieldX: AI-driven security operations with analyst supervision of consequential decisions | Owner-published product data | 2026-08-02 | VirtueShieldX · Responsible AI |
| W16 | VirtueThreatX: CTEM platform covering Scope, Discover, Prioritize, Validate, Mobilize; screenshots captured from the live platform (demo organization) | Owner-published product data (live-platform captures) | 2026-07-17 | VirtueThreatX |
| W46 | VirtueThreatX: “9 attack surfaces (web, API, network, code, mobile, cloud, container, identity, and AI/LLM)” | Owner-published product data (engines listed by name on the product site) | 2026-07-21 | VirtueThreatX · Responsible AI |
| W18 | VirtueATLAS: AI-powered quality engineering suite; self-healing automation; Jenkins, GitHub, GitLab, Azure DevOps, and Jira integrations | Owner-published product data | 2026-08-02 | VirtueATLAS |
| Delivery, methodology, and tooling | ||||
| W26 | Testing aligned to the OWASP Testing Guide, PTES, and NIST SP 800-115, with retest included as standard | Owner-published methodology | 2026-07-14 | Methodology · PTaaS |
| W12 | “We test and report against GDPR, HIPAA, PCI DSS, SOC 2, ISO 27001 requirements” (your frameworks; never a certification claim about us) | Owner attestation, dated (capability statement) | 2026-08-02 | Compliance audits · Cybersecurity |
| W25 | Managed SOC standard SLA targets (P1 acknowledged within 15 minutes, tiers to 4 hours at P4), 30-day pilot, onboarding within 90 days: published with the caveat that final SLAs are committed in your service agreement | Owner attestation, dated; caveat published with the claim | 2026-07-15 | Managed SOC |
| W49 | “You’ll hear back from an engineer, typically within one business day” | Owner attestation, dated (“typically” qualifier required; never a guaranteed SLA) | 2026-07-17 | Contact |
| W13 | Security tooling: Burp Suite Pro, OWASP ZAP, Nmap, Nessus, Nuclei, SecurityTrails; AWS, Azure, GCP, Oracle cloud coverage | Owner attestation (capability statement; no partnership implied) | 2026-08-02 | Technology Ecosystem |
| W14 | SOC stack: Wazuh, ThreatFox plus curated feeds, Trivy, in-house SIEM, detection, and SOAR | Owner attestation (capability statement; no partnership implied) | 2026-08-02 | Technology Ecosystem · VirtueShieldX |
| W37 | QE frameworks our engineers work in: Selenium, Playwright, Cypress, Appium, JMeter, k6, Postman/Newman, REST Assured, axe, Lighthouse | Owner attestation (capability statement; no partnership implied) | 2026-08-02 | Technology Ecosystem · Quality Engineering |
| Client proof | ||||
| W19 | Testimonial: Rajasekhara Saidam, Information Security Officer, HackerEarth (three years of working together) | Client-consented testimonial, named, verbatim | 2026-07-20 | Home · Why VirtuesTech |
| W20 | Testimonial: Jonathan Andrews, CEO / President, Weston InfoSec | Client-consented testimonial, named, verbatim | 2026-07-20 | Home · Why VirtuesTech |
| W21 | Testimonial: Damon DeCrescenzo, CEO, The Credit Pros | Client-consented testimonial, named, verbatim | 2026-07-20 | Home · Why VirtuesTech |
| W28 | Client logo wall (17 client logos) | Client-consented logo placement (relationship signal only) | 2026-07-14 | Home |
| W29 | Sample penetration-test report, downloadable without a form | Redacted deliverable from a real engagement (client, endpoints, and evidence removed) | 2026-08-02 | PTaaS · API Security Testing |
| W38 | AI-platform API VAPT case study: three High-severity findings demonstrated, remediated, and verified on a clean retest | Engagement records, anonymized; retest report on file | 2026-08-02 | Case study |
| W24 | Case studies: a 300+ API security assessment, a SaaS platform VAPT, and a three-year continuous VAPT program | Engagement records, anonymized | 2026-08-02 | API assessment · SaaS VAPT · Three-year program |
| W43 | Automotive QE and DevOps case study (scope and approach; no outcome metrics published because none are measured yet) | Engagement records, anonymized | 2026-07-20 | Case study |
| W44 | Banking automation, performance, and security case study (scope and approach; no outcome metrics published because none are measured yet) | Engagement records, anonymized | 2026-07-20 | Case study |
| W47 | 17 anonymized engagement summaries, listed by industry descriptor with the services delivered | Owner engagement records, anonymized by policy | 2026-07-20 | Customer Stories |
| W23 | Industries served: BFSI, healthcare, fintech, retail and e-commerce, edtech, media, energy, and others | Owner engagement records | 2026-08-02 | Industries |
| AI and data commitments | ||||
| W50 | “Client data is never used to train models” (any VirtuesTech platform) | Owner attestation, dated | 2026-08-03 | Responsible AI |
| Third-party statistics | ||||
| W22 | Market statistics used on this site, each with named source and year: IBM 2025 ($10.22M average US breach cost), Verizon DBIR 2025, ISC2 2024, Akamai 2017, Deloitte 2020 | Third-party reports, named source + year | 2026-07-22 | Cybersecurity · Insights |
| Certification status | ||||
| W40 | “We hold no organizational certification today and do not claim otherwise. ISO 27001 certification for VirtuesTech is planned (stated July 2026).” | Owner attestation, dated intent | 2026-07-17 | Trust |
The standing offer
If you find a factual claim on this site (a number, a name, a date, an outcome) that isn’t covered by a row in this table, tell us at info@virtuestech.com. We’ll either add the row with its evidence or correct the page. The same address works in the other direction: cite any row ID above during due diligence and we’ll walk you through the underlying evidence, under NDA where the material requires it.
The wider claim-discipline policy, including what we refuse to publish, is on the Trust & Company Facts page. How engagements themselves are governed is on the methodology page.
Not sure where to start?
A plain-language conversation about your product, your risk, and what to do first.