For your role / Procurement
Most of your checklist is already published
Vendor reviews stall on missing facts and inflated claims. Ours are maintained on public pages you can verify against primary sources, and the documents that should never be public arrive under NDA. Work down the list.
Eight checks, eight published answers
Legal identity you can verify at the source
Virtue Software Technologies Private Limited, CIN U72900TG2020PTC138226, registered with ROC Hyderabad, incorporated January 2020, status Active. Delivery hubs in Hyderabad, India and Frisco, Texas, with full addresses published. Check the CIN against the MCA registry yourself; that is what it is published for.
Team facts without inflation
100+ security and quality engineers; 63% of our engineers hold industry certifications (CISSP, CEH, eCPPT, ISTQB, AWS). Those are individual engineer credentials, and we say so, because the organizational question gets its own answer two items down.
A leadership roster that matches reality
The published roster is two profiles: Founder & CEO Venkata Ramana Pullagoora, 26+ years in IT, and Business Advisor Hemanth Kumar KV. No padded advisory board, no stock-photo executives. What you see on the About page is who signs off on your engagement.
The certification answer, in writing
We hold no organizational certification today and do not claim otherwise. ISO 27001 certification for VirtuesTech is planned (stated July 2026), and milestones will be published when they are reached. On the client side, we test and report against GDPR, HIPAA, PCI DSS, SOC 2, and ISO 27001 requirements as an independent testing partner rather than a certification body. If a supplier form needs a certificate we lack, you will know in this paragraph instead of at contract stage.
A conflict-of-interest screen
We don’t build what we test, and we don’t resell what we recommend. There are no development revenues to protect and no tool commissions behind our findings, which is the structural answer to the independence question on most vendor questionnaires.
Methodology and a real deliverable
Testing aligns to the OWASP Testing Guide, PTES, and NIST SP 800-115, with remediation verified on retest as standard. Judge the deliverable directly: a real, redacted penetration-test report is a download with no form in front of it.
References that agreed to be named
Three clients say on the record, with names, roles, and photos, what we are like to work with; every other engagement is published anonymized because those clients did not consent to naming, and we keep it that way. Further references from comparable engagements arrive with the due-diligence pack.
A claim-discipline mechanism, in the open
Every factual statement on this site is maintained in an evidence register and reviewed before publication: no outcome percentages we haven’t measured, no partnerships that don’t exist. The register’s public face explains how that works, and any claim you question, we will substantiate.
The part that arrives under NDA
Serious due diligence asks for documents that don’t belong on a public page, and a vendor who publishes them anyway is telling you something about their data handling. Request the pack through your point of contact or the contact form, and it arrives during vendor onboarding:
- Data Processing Agreement (DPA) and sub-processor information
- Methodology and a sample (redacted) deliverable
- Platform architecture and tenancy documentation
- Personnel-security summary: NDAs and background checks
- References from comparable engagements
Engagements run under mutual NDA, delivered by background-checked engineers, with data handling fixed in the service agreement. The people who scope your engagement are the people who run it.
Three files for your vendor folder
- Company profile (PDF) → The entity, team, and service facts in a document you can attach to the vendor record as-is.
- Sample penetration-test report (PDF) → The deliverable your stakeholders would actually receive, real and redacted rather than a mockup.
- Pentest RFP template → Written to be used on any vendor, including us. If another firm answers it better, that is the outcome an RFP is for.
Ready for the paperwork?
Ask for the NDA-gated due-diligence pack, or send over your security questionnaire. You'll hear back from an engineer, typically within one business day.