ISO/IEC 17025:2017Accredited testing laboratory
CMMI Maturity Level 3The process is written down and repeats
ISO 9001:2015Quality management
ISO/IEC 27001Information security
Phishing, Pretexting and Impersonation
This is a short sub-page for the people layer. Phishing, pretexting and impersonation are tested against agreed in-scope people and channels, with 100% coverage of agreed in-scope. US product and security teams get this work in US hours, 9am to 1pm Eastern, with delivery from India, under ISO/IEC 27001. Written permission and named targets come first. We do not phish a neighbour you did not name. We do not claim certified security staff. A free external attack-surface check of one domain is the first look from the outside.
Phishing Simulation
Emails that ask for a credential, a click or a file, sent only to the agreed in-scope inboxes. A finding is a person who handed something over, not a screenshot of a template. Retesting after awareness work is part of the original engagement. 100% coverage of agreed in-scope.
Pretexting
A caller or a message that pretends to be IT, finance or a vendor the staff already trust. Scope is the agreed in-scope people and channels. We will not pretend a phishing click-rate is a pretexting pass. The rules of engagement are written down before anyone picks up a phone.
Impersonation
An executive, a helpdesk or a partner that is not who they say they are. Tested on the agreed in-scope set, with a risk-ranked report. Full product VAPT sits on penetration testing. This page is the people slice.
Need the people layer tested, not another application scan? Book a scoping call, or start with a free external attack-surface check of one domain.
Book a Call
What This Page Covers and What the Other Security Pages Cover
The overview that routes the rest of the set is security testing. Full VAPT sits on penetration testing. Hosts sit on infrastructure security testing. Stay here when the problem is phishing, pretexting or impersonation on the agreed in-scope people and channels. Every engagement ends with a retest of those assets.
Stay on This Page
The problem is a person who clicks, a caller who is believed, or an inbox that still forwards a secret. You want those agreed in-scope people and channels tested, a risk-ranked report, and a retest. 100% coverage of agreed in-scope.
Go to Penetration Testing
You need an authorised attacker across the application, API, mobile and infrastructure. Penetration testing is that method. We do not run both as two invoices for the same week unless you asked for both.
Proof From Delivery
Sector only. The anonymous bank numbers, then four further engagements. They are security delivery, not a claim that each was a social-engineering-only job.
Anonymous bank · VAPT and audit evidence
Before: vulnerability noise was burying the work that mattered, fixes took over 40 days, and audit preparation took five days. After: 68% less vulnerability noise, time to fix under 16 days, audit preparation from 5 days to 5 hours, and a 3.5 times high-risk closure rate.
68% less vulnerability noise
TTF from 40+ days to under 16
Audit prep 5 days to 5 hours
3.5x high-risk closure
Digital recharge and payments platform
Infrastructure VAPT across the exposed surface. Findings were retested after remediation. Sector and work type only.
Payments platform
Global marine technology organisation
Web and infrastructure work against the agreed in-scope assets. Sector and work type only.
Marine technology
UAE · fintech
API and network-adjacent exposure on a fintech platform. The client stays unnamed.
UAE fintech
SaaS gaming platform
End-to-end work across the agreed in-scope product, with a retest after fixes. Sector only.
SaaS gaming
One domain, from the outside
Book a Call
Tell us the people and the channels. We will come back with the agreed in-scope list and a quote. Or start with a free external attack-surface check of one domain.
ISO/IEC 27001 · 275+ engineers · US-hours coverage
Frequently Asked Questions
Price follows the agreed in-scope people and channels: how many inboxes, whether pretexting and impersonation are in, and that a retest is part of the work. We quote after that list is written down. We do not publish a day-rate on this page. This URL is the people layer, not a full VAPT. A free external attack-surface check of one domain is the first look from the outside.
Application, API, mobile, network, infrastructure, wireless, social engineering and a full penetration test. This URL is social engineering testing: phishing, pretexting and impersonation on agreed in-scope people and channels. The overview that routes the rest is security testing. VAPT across the product sits on penetration testing. Pick the layer you actually have, not a catalogue of every check.
Unauthorised testing is illegal. Authorised testing of agreed in-scope people and channels, with written permission, is the engagement. We do not phish a neighbour you did not name. This page is the people layer. A full authorised attacker across applications sits on penetration testing. Book a scoping call before anyone sends a bait email. The rules of engagement are written down first. We do not claim certified security staff.
We will not invent a ranked five. This URL is the people layer, not a tool catalogue. A template dump with no owner is not the engagement. Judge a vendor on written permission, agreed in-scope people and channels, and a retest after awareness work. Book a scoping call if the question is which check you are buying, not which logo. The free domain check is how we see the outside first.
A penetration test is quoted after the agreed in-scope product is written down: applications, APIs, mobile and infrastructure. That work sits on penetration testing, not on this page. This URL is social engineering testing. Price follows people, channels and whether pretexting is in. We do not publish a project total here. A free external attack-surface check of one domain is the first look. Book a scoping call for the people slice.
Judge a vendor on written permission, agreed in-scope, a retest after fixes, and whether they will say this page is the people layer rather than a full VAPT. Ranked lists are not that. Vervali is an ISO/IEC 17025 accredited lab with CMMI Level 3 process, US-hours coverage and delivery from India. We do not rank ten firms. Penetration testing is the VAPT page. This page is the social engineering sub-page.
No. AI can draft a bait email. A person still confirms a finding is real, stays inside agreed in-scope, and retests after awareness work on the people you named. This page is social engineering testing. A generated campaign with no owner is not the engagement. We do not claim certified security staff. Book a scoping call if you want that confirmation, not a bot-generated PDF.
It is an authorised test of a web application for exploitable gaps, with a retest after fixes. That method sits on penetration testing. This URL is social engineering testing: phishing, pretexting and impersonation on agreed in-scope people and channels. The overview is security testing. We will not pretend a phishing pass is a web app pentest. Book a scoping call for the layer you actually have.