getapp-logo

App comparison

Add up to 4 apps below to see how they compare. You can also use the "Compare" buttons while browsing.

GetApp offers objective, independent research and verified user reviews. We may earn a referral fee when you visit a vendor through our links. 

Gordon VAPT Logo

Automated vuln scanning & penetration testing

Table of Contents

Gordon VAPT - 2026 Pricing, Features, Reviews & Alternatives

Verified reviewer profile picture
Verified reviewer profile picture

All user reviews are verified by in-house moderators and provider data by our software research team.  Learn more

Last updated: April 2026

Gordon VAPT overview

What is Gordon VAPT?

Gordon VAPT is a vulnerability assessment and penetration testing platform developed by Mitigata. It combines continuous automated security scanning with expert-led manual penetration testing to identify and remediate weaknesses across organizational digital infrastructures. The platform targets regulated enterprises, financial institutions, software as a service providers and e-commerce organizations that require security evaluations to satisfy compliance mandates set by Indian regulatory bodies. It is designed to reduce the time between vulnerability discovery and remediation while generating reports formatted for Indian compliance frameworks.

The platform’s automated scanning engine operates around the clock across multiple asset types including web applications, application programming interfaces, mobile applications, network devices, cloud environments, container clusters and internal corporate networks. Scanning capabilities leverage dynamic application security testing, static application security testing and software composition analysis methodologies to detect risks across different technology layers. Findings are correlated with the Common Vulnerabilities and Exposures database and assigned risk ratings based on severity and exploitability. Every critical and high-severity finding identified by automated scanners undergoes manual verification by security analysts to prevent false positives from appearing in the dashboard.

Manual penetration testing is conducted by CERT-In empanelled security researchers who perform assessments that extend beyond automated detection. Testing techniques include chaining vulnerabilities, evaluating business logic flaws and simulating advanced attacker behaviors across web applications, APIs, mobile platforms, networks and cloud infrastructure. Penetration test reports are delivered within forty-eight hours of testing completion and include executive summaries alongside developer-ready technical details. The platform provides remediation tracking that monitors each finding through discovery, fix implementation and verified closure with prioritization based on severity, exploitability and business impact. Step-by-step remediation guidance accompanies each finding and automated re-scanning confirms closure without additional verification requests.

Gordon VAPT generates compliance-ready reports formatted for submissions to Indian regulators including the Reserve Bank of India framework, the Securities and Exchange Board of India framework, the Insurance Regulatory and Development Authority guidelines and ISO standards. Attestation letters and compliance certificates are provided as part of every penetration test engagement to eliminate manual report preparation for regulatory deadlines. An executive dashboard translates technical findings into board-level risk communications and historical trend reporting demonstrates improvements in security posture over time. Auditor-ready evidence packages maintain full chain of custody documentation and integration with development and ticketing systems embeds vulnerability management into existing workflows.

Starting price

1787flat rate /
per month

Gordon VAPT’s user interface

Ease of use rating:

Gordon VAPT reviews

Overall rating

empty-state-img

No reviews

Rating breakdown
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend0.00/10
Rating distribution

5

4

3

2

1

0

0

0

0

0

Gordon VAPT's key features

Most critical features, based on insights from Gordon VAPT users:

Access controls/permissions
API
Application security
Asset Discovery
Network scanning
Network security
Reporting/Analytics
Source-Code scanning
SQL injections
SSL security

All Gordon VAPT features

Access controls/permissions
API
Application security
Asset Discovery
Network scanning
Network security
Reporting/Analytics
Source-Code scanning
SQL injections
SSL security
Vulnerability assessment
Vulnerability scanning
Web-Application security
Web Scanning

Gordon VAPT pricing

Pricing plans

Pricing details:

Free plan
Free trial
Subscription

Startup

1,787

Per month

Features included:

  • Attack Surface Monitoring: 1 monitored asset, 12 scans/year, includes exposed subdomains, open ports, SSL/TLS certificate health, DNS anomalies, CVE scoring, and continuous monitoring.
  • SOC Monitoring (24/7): Up to 100 monitored endpoints, AI-powered alert triage, kill-chain reconstruction, automated response playbooks, CERT-In 6-hour incident reporting, and 10 threats with 5 IOCs.
  • Workforce Risk & Security Awareness: Up to 100 monitored employees, email phishing simulation, custom phishing templates, and security awareness training.
  • Dark Web Monitoring: 1 monitored keyword and access to Tor forums, paste sites, Telegram channels, breach databases, and ransomware monitoring.
  • Cloud Security & Billing Monitoring: 1 monitored cloud instance with misconfiguration detection, IAM checks, and cloud billing optimization.
  • GRC & Compliance: 2 compliance frameworks, automated control mapping, AI gap assessment, policy auto-generation, and risk register automation.
  • Third Party Risk Management (TPRM): 100 monitored vendors with AI security questionnaire dispatch, breach alerts, and risk rating.
  • Gordon AI: 500 AI credits for auto-generated risk narratives, remediation playbooks, and executive summaries.
  • Brand Intelligence & Takedowns: 1 monitored brand asset, 20 keywords, and 25 takedowns for rogue apps, phishing pages, etc.
  • Consent Manager (DPDPA): 25K unique consents with granular consent collection, cookie scanner, and data deletion requests.

Mid-Market

3,382

Per month

Features included:

  • Attack Surface Monitoring: 3 monitored assets
  • SOC Monitoring: Up to 500 endpoints, 50 threats, and 20 IOCs
  • Workforce Risk & Security Awareness: Up to 500 employees
  • Dark Web Monitoring: 1 monitored keyword
  • Cloud Security & Billing Monitoring: 2 monitored cloud instances
  • GRC & Compliance: 4 compliance frameworks
  • Third Party Risk Management (TPRM): 250 monitored vendors
  • Gordon AI: 1,000 AI credits
  • Brand Intelligence & Takedowns: 3 monitored brand assets, 60 keywords, and 100 takedowns
  • Consent Manager (DPDPA): 100K unique consents

Enterprise Plan

6,607

Per month

Features included:

  • Attack Surface Monitoring: 10 monitored assets
  • SOC Monitoring: Up to 2,000 endpoints, unlimited threats, and unlimited IOCs
  • Workforce Risk & Security Awareness: Up to 2,000 employees
  • Dark Web Monitoring: 5 monitored keywords
  • Cloud Security & Billing Monitoring: 5 monitored cloud instances
  • GRC & Compliance: 5 compliance frameworks
  • Third Party Risk Management (TPRM): 1,000 monitored vendors
  • Gordon AI: 1,000 AI credits
  • Brand Intelligence & Takedowns: 5 monitored brand assets, 100 keywords, and 125 takedowns
  • Consent Manager (DPDPA): 500K unique consents

User opinions about Gordon VAPT price and value

Value for money rating:

Gordon VAPT integrations (3)

Top integrations

Gordon VAPT support options

Typical customers

Freelancers
Small businesses
Mid size businesses
Large enterprises

Platforms supported

Web
Android
iPhone/iPad

Support options

Email/Help Desk
Phone Support
24/7 (Live rep)
Chat

Training options

Live Online
Documentation
Videos

Gordon VAPT FAQs

Q. Who are the typical users of Gordon VAPT?

Gordon VAPT has the following typical customers:
Small Business, Mid-size Business, Large Enterprises


Q. What level of support does Gordon VAPT offer?

Gordon VAPT offers the following support options:
Email/Help Desk, Phone Support, 24/7 (Live rep), Chat

Related categories