// about

A focused team.
A serious mission.

Xyron is a penetration testing team of five security professionals. Between us we have responsibly disclosed vulnerabilities to more than 75 organizations — including Fortune 500 companies, government platforms, payment processors and high-growth startups.

Expert Team

Meet Our Security Experts

Our team combines deep expertise in offensive security, application testing, and responsible disclosure — guiding you from gaps to hardened systems, fast and flawlessly.

Aditya Kumar

Aditya Kumar

Security Researcher · OSINT

Sakshi

Sakshi

VAPT Analyst & Reporting Specialist

Prachi Raj

Prachi Raj

Customer Support Specialist

Ankit Singh

Ankit Singh

Founder · Team Lead · Red Team Specialist

Yogi Atram

Yogi Atram

Co-founder · Security Analyst · API & Mobile

Aditya Kumar

Aditya Kumar

Security Researcher · OSINT

Sakshi

Sakshi

VAPT Analyst & Reporting Specialist

Prachi Raj

Prachi Raj

Customer Support Specialist

Ankit Singh

Ankit Singh

Founder · Team Lead · Red Team Specialist

Yogi Atram

Yogi Atram

Co-founder · Security Analyst · API & Mobile

Aditya Kumar

Aditya Kumar

Security Researcher · OSINT

75+
Organizations responsibly disclosed
5
Security professionals
US / EU / IN
International client base
100%
Manually verified findings

Companies we've reported to

Through responsible disclosure programs and coordinated reports, our team has helped secure platforms used by billions of people:

Dell
Meta
Adobe
Google
Apple
Amazon
Audible
Linktree
Bajaj Finance
Pine Labs
Govt. platforms
Payment processors

// team

Meet the operators.

Five specialists. Hands-on offensive testing, manual verification, and a deep bench of responsible disclosures across Fortune 500.

Prachi Raj

Prachi Raj

Customer Support Specialist

Client success · Engagement coordination · Communication

experience
Customer Support Specialist — Xyron Security
Current
  • First point of contact for scoping requests, engagement coordination, and post-delivery follow-ups.
  • Keeps clients informed across kickoff, testing, reporting and retest stages.
  • Owns feedback loops to continuously improve the Xyron engagement experience.
core skills
  • Client Communication
  • Engagement Coordination
  • Support Ops
Ankit Singh

Ankit Singh

Founder · Team Lead

Security Analyst · Penetration Tester · Red Team Specialist

certifications
  • Certified Ethical Hacker (CEH v13) — EC-Council
experience
Project Trainee & Cybersecurity Intern — Softsense Technoserve Pvt. Ltd.
Jun 2025 – Apr 2026
  • Performed WAPT & API security testing focused on OWASP Top 10 vulnerabilities using Burp Suite Pro.
  • Identified and validated vulnerabilities including IDOR, auth bypass, broken access control, session flaws, and business logic issues.
  • Delivered professional VAPT reports with PoCs, CVSS scoring, and remediation guidance.
  • Conducted MAPT, reconnaissance, and manual security assessments across client environments.
  • Responsible disclosures across Dell, Meesho, Frontegg, Poorvika, Napkin AI, and Audible (Amazon).
core skills
  • WAPT
  • API Pentesting
  • MAPT
  • VAPT
  • OWASP Testing
  • Burp Suite Pro
  • OSINT
  • Recon
  • CVSS Scoring
  • Secure Reporting
Yogi Atram

Yogi Atram

Co-founder · Security Analyst

Penetration Tester · Bug Bounty Researcher · Mobile & API Security

certifications
  • Certified Ethical Hacker (CEH v13) — EC-Council
experience
Security Analyst Intern — FORnSEC Solutions, Nagpur
2025 – 2026
  • VAPT, WAPT, and API security assessments with Burp Suite & Postman following OWASP Top 10 methodology.
  • Discovered hardcoded AWS Cognito Identity Pool IDs in the Audible Android APK — unauthenticated write access to production Kinesis across 4 AWS accounts.
  • Identified SSO login bypass on Swayam (Govt. of India) via unverified Firebase token acceptance for arbitrary government email accounts.
  • Disclosures: one-click ATO via Stored XSS on Kimi AI, CORS + credential exfil on Frontegg/DevRev, payment callback tampering on Poorvika.com, Sensitive Info Disclosure in NASA, ATO via Stored XSS in Skispace, Firebase misconfig in Napkin AI.
core skills
  • WAPT
  • API Testing
  • MobSF
  • JADX
  • Network Auditing
  • OWASP Top 10
  • Burp Suite
  • Postman
Aditya Kumar

Aditya Kumar

Security Researcher

OSINT Specialist · Independent Bug Bounty Hunter · Web App Tester

certifications
  • Diploma — Information Technology & Systems Management
experience
Independent Security Researcher
Ongoing
  • Responsibly disclosed vulnerabilities across 75+ organizations worldwide — consistently locating high-impact weaknesses without institutional support.
  • Notable: Dell, Meta, Adobe, Google, Apple, Linktree, Bajaj Finance, Audible (Amazon), Pine Labs, Red Pharmacy, ABB Information Systems Ltd.
  • Collaborates with Xyron on multi-vector assessments — deep OSINT-driven recon and manual testing.
core skills
  • OSINT
  • Passive & Active Recon
  • Web App Testing
  • Business Logic
  • Responsible Disclosure
Sakshi

Sakshi

VAPT Analyst & Reporting Specialist

VAPT execution · Client-ready reporting · Remediation guidance

experience
VAPT Analyst — Xyron Security
Current
  • Runs vulnerability assessments across web and API scopes with manual verification of each finding.
  • Owns client-ready executive and technical reports with CVSS ratings, PoCs and prioritized remediation.
  • Coordinates retest cycles and closure documentation with client engineering teams.
core skills
  • VAPT
  • OWASP Top 10
  • Reporting
  • CVSS
  • Remediation Guidance
Prachi Raj

Prachi Raj

Customer Support Specialist

Client success · Engagement coordination · Communication

experience
Customer Support Specialist — Xyron Security
Current
  • First point of contact for scoping requests, engagement coordination, and post-delivery follow-ups.
  • Keeps clients informed across kickoff, testing, reporting and retest stages.
  • Owns feedback loops to continuously improve the Xyron engagement experience.
core skills
  • Client Communication
  • Engagement Coordination
  • Support Ops
Ankit Singh

Ankit Singh

Founder · Team Lead

Security Analyst · Penetration Tester · Red Team Specialist

certifications
  • Certified Ethical Hacker (CEH v13) — EC-Council
experience
Project Trainee & Cybersecurity Intern — Softsense Technoserve Pvt. Ltd.
Jun 2025 – Apr 2026
  • Performed WAPT & API security testing focused on OWASP Top 10 vulnerabilities using Burp Suite Pro.
  • Identified and validated vulnerabilities including IDOR, auth bypass, broken access control, session flaws, and business logic issues.
  • Delivered professional VAPT reports with PoCs, CVSS scoring, and remediation guidance.
  • Conducted MAPT, reconnaissance, and manual security assessments across client environments.
  • Responsible disclosures across Dell, Meesho, Frontegg, Poorvika, Napkin AI, and Audible (Amazon).
core skills
  • WAPT
  • API Pentesting
  • MAPT
  • VAPT
  • OWASP Testing
  • Burp Suite Pro
  • OSINT
  • Recon
  • CVSS Scoring
  • Secure Reporting

Our positioning

US/EU-grade penetration testing at offshore rates. We deliver the same quality, methodology and documentation as top-tier security firms — at a price point that lets startups and mid-market companies actually afford serious offensive testing.

Get in touch