# Bachao.AI — Full Reference > India's first affordable AI-native cybersecurity platform for SMBs. > This document provides comprehensive information about Bachao.AI for LLM consumption. Website: https://www.bachao.ai Founded: 2025 Founder: Shouvik Mukherjee Contact: ceo@bachao.ai LinkedIn: https://www.linkedin.com/company/bachao-ai --- ## Company Overview Bachao.AI is a SaaS platform for Indian SMBs and the auditors + legal partners they hire. We provide automated penetration testing (VAPT), DPDP gap-analysis tooling, and a full suite of cybersecurity scanning + evidence-collection software built specifically for Indian startups, SaaS companies, D2C brands, and digital agencies. 74% of Indian SMBs face cyberattacks, but enterprise security costs INR 16,000+/month. Bachao.AI makes professional-grade scanning and evidence collection accessible starting at INR 0 (first scan free). Your auditor reviews the output and signs the final certification — we are the platform, not the auditor. ### Mission Protect the businesses building India. Every business deserves cybersecurity they can actually afford. ### Target Audience - Indian startups and SMBs (primary) - SaaS companies - D2C e-commerce brands - Digital agencies and web development firms - Any business needing affordable, professional cybersecurity - vCISOs and security consultants looking to white-label --- ## Products & Services — Full Descriptions ### 1. AI VAPT Scanner (Vulnerability Assessment & Penetration Testing) URL: https://www.bachao.ai/vapt AI-powered automated penetration testing for web applications, APIs, and infrastructure. Scans complete in approximately 2 hours using Nuclei (9,000+ templates), OWASP ZAP, Nmap, and SSLyze, all orchestrated and analyzed by Claude AI. **What gets scanned:** - Web Applications: Full-stack scan covering OWASP Top 10, business logic flaws, auth flow issues, injection vectors - REST / GraphQL APIs: Endpoint enumeration, auth bypass testing, injection on every parameter, rate-limit checks - SSL/TLS: Certificate validation, cipher strength audit, HSTS checks, protocol downgrade detection - DNS Security: Zone transfer tests, DNSSEC validation, subdomain takeover checks, dangling CNAME detection - Network / Infrastructure: Port scanning, service fingerprinting, banner grabbing, known CVE matching via Nmap - Cloud Configuration: S3 bucket exposure, IAM misconfigs, security group audits, public endpoint discovery **AI Layer — What Claude AI does with every finding:** 1. VALIDATE: Every finding is re-tested against the target. If it cannot be reproduced, it is dropped. Zero unvalidated false positives. Validated false-positive rate under 3%. 2. TRIAGE: Validated findings scored on CVSS 3.1 with environmental context. Critical issues flagged for immediate action. 3. TRANSLATE: Technical findings translated to business impact. CEO reads the same report as CTO — in English or Hindi. 4. REMEDIATE: AI generates fix code, config patches, and step-by-step remediation guides tailored to the tech stack. **Scan Pipeline:** 1. Scan Request — user submits a domain or IP 2. DNS Verification — TXT record proves domain ownership (IT Act 2000 compliant) 3. Job Queue — scan queued and scheduled in under 60 seconds 4. Firecracker microVM — isolated VM spins up with Nuclei + ZAP + Nmap + SSLyze executing in parallel 5. Claude AI Analysis — findings validated, triaged, translated, remediation generated 6. Report Delivery — PDF + JSON + dashboard delivered within 2 hours **Comparison with Traditional VAPT:** | Metric | Traditional VAPT | Bachao.AI | |---|---|---| | Time to report | 4-8 weeks | ~2 hours | | Cost | INR 40,000-8.5L (industry range) | Free scan; basic and full reports on pay-per-use, 30–65% lower than the industry range | | Report quality | Template-based PDF | AI-written, business-context | | False positives | 30-60% unvalidated | Zero unvalidated | | Re-testing | Extra cost | Included in subscription | | DPDP mapping | Not included | Auto-mapped to DPDP Act | | Languages | English only | English + Hindi | **Technical FAQ:** - Production safety: Scans use non-destructive payloads only. No PUT/DELETE requests, no data mutation. - False positives: Every finding re-tested by Claude AI. Validated false-positive rate under 3%. - CI/CD integration: Growth and Agency plans include API access. Trigger scans from GitHub Actions, GitLab CI, or any pipeline. Results as JSON with webhook support. - Data retention: Reports retained 12 months on paid plans. Scan artifacts purged within 72 hours. All data stored on Indian infrastructure. - Credentials: No credentials required for unauthenticated scanning. For authenticated scans, test account provided, encrypted at rest, purged after completion. --- ### 2. API Security Testing URL: https://www.bachao.ai/api-security Automated API security testing covering full OWASP API Top 10 (2023 edition), with India-specific coverage for UPI callback and Aadhaar verification APIs. **Features:** - Endpoint Discovery: Automated crawling and fuzzing for all endpoints including undocumented shadow APIs - Auth Testing: Broken authentication, JWT misconfiguration, OAuth bypass, session fixation, privilege escalation (OWASP API1, API2) - Injection Attacks: SQL, NoSQL, command injection, SSRF tested on every parameter, header, and path segment - Rate Limiting: Verify rate limits work under load on login, OTP, payment, and data export endpoints - Business Logic Flaws: Price manipulation, coupon abuse, IDOR, order flow bypass — flaws rule-based scanners miss - Data Exposure: Detect APIs leaking Aadhaar numbers, PAN cards, phone numbers. Auto-classify PII fields and flag DPDP violations. **OWASP API Top 10 Coverage:** 10/10 categories covered — API1 through API10. **AI Capabilities for API Security:** - Shadow API Discovery: AI analyzes JavaScript bundles, mobile app traffic, and documentation drift. Average app has 30% more endpoints than documented. - Business Logic Flaw Detection: AI models intended API workflows and tests for logic bypasses (skip payment, modify price, replay coupon). - Context-Aware PII Detection: AI classifies response fields as PII even when field names are obfuscated. Flags DPDP Act violations. --- ### 3. Cloud Security Audit URL: https://www.bachao.ai/cloud-security Cloud infrastructure security assessments for AWS, GCP, and Azure. 500+ security checks. No agent installation required. **What gets audited:** - S3 / Storage: Publicly readable buckets, missing encryption, overly permissive ACLs, unversioned storage (AWS S3, Azure Blob, GCP Cloud Storage) - IAM Policy Analysis: Overprivileged roles, unused service accounts, missing MFA, wildcard permissions, cross-account trust chains - Network Exposure: Every public-facing endpoint, open security group, unrestricted port, misconfigured load balancer - Encryption Gaps: Unencrypted EBS volumes, RDS instances without TLS, missing KMS key rotation, data-in-transit exposure - Compliance Mapping: Findings auto-mapped to DPDP Act Schedule I, RBI IT governance guidelines, ISO 27001 controls - Cost Optimization: Idle resources, oversized instances, orphaned volumes flagged for savings **AI Differentiator:** Traditional scanners report "S3 bucket has public read access." Bachao.AI reports: "CRITICAL: 'prod-uploads' contains 14,000+ Aadhaar card images and is publicly readable. DPDP Act Schedule I violation — up to INR 250Cr penalty." --- ### 4. Dark Web Monitoring URL: https://www.bachao.ai/dark-web-monitoring Continuous monitoring of dark web marketplaces, forums, messaging platforms, and domain registrations for threats targeting your organization. Hindi and Hinglish NLP support. **What gets monitored:** - Credential Leak Detection: Breach databases, paste sites, dark web markets scanned for compromised employee and customer credentials - Typosquatting Alerts: Lookalike domain detection (e.g., bachao-ai.com, bachaoai.in, bachao.co) - Fake App Monitoring: Counterfeit apps on Play Store, APK mirrors, third-party stores. Automated takedown requests. - WhatsApp Scam Detection: Fraudulent WhatsApp Business accounts and groups impersonating your brand - Telegram Channel Scanning: AI crawls Telegram channels where stolen data and exploit kits are traded - SSL Certificate Monitoring: Alerts when new certificates issued for domains containing your brand name **AI Capabilities:** - Hindi + Hinglish NLP: Detects threats in 22 Indian languages, not just English keyword matching - Automated Threat Correlation: Connects credential dump + typosquatted domain + phishing kit purchased = coordinated attack incoming - False Positive Reduction: AI classifies findings by confidence level and business impact; only actionable threats reach inbox --- ### 5. DPDP Compliance Tool URL: https://www.bachao.ai/dpdp-compliance India's Digital Personal Data Protection Act 2023 readiness assessment. Free DPDP compliance score in 5 minutes. **DPDP Act Schedule I — 7 Requirements:** 1. Reasonable Security Safeguards: Encryption, access controls, vulnerability management 2. Consent Management: Free, specific, informed consent in all 22 scheduled languages with withdrawal mechanisms 3. Data Principal Rights: Respond to access, correction, erasure requests within 48 hours 4. Breach Notification: Report to CERT-In within 6 hours, notify affected individuals 5. Data Fiduciary Obligations: Processing records, periodic audits, DPO if classified as Significant 6. Retention Limits: Delete personal data when consent withdrawn or purpose fulfilled 7. Children's Data Protection: Verifiable parental consent for under-18s. No behavioral tracking. **Enforcement Timeline:** - Nov 2025: Data Protection Board constituted (DONE) - Nov 2026: Registration opens - May 13, 2027: Full enforcement begins **Penalties:** - INR 250 Crore: Maximum penalty per contravention (security safeguard failure) - No cumulative annual cap specified in the enacted DPDP Act 2023 - For a startup with INR 2 Crore revenue, a single INR 250Cr penalty = 125 years of revenue **Honest Scope:** Bachao.AI is NOT a certification body. Cannot issue ISO 27001, SOC 2, or DPDP certificates. Bachao.AI DOES: implement technical controls, generate evidence documentation, map infrastructure against DPDP, connect to certified vCISO network. **Free vs Paid:** - Free: DPDP score 0-100, top 5 compliance gaps, severity rating, email delivery - Full Report (pay-per-use, scoped per engagement): Detailed gap analysis, 16 evidence templates, breach notification template, board presentation deck, vCISO review call, re-assessment in 90 days, fix quote --- ### 6. Security Awareness Training URL: https://www.bachao.ai/security-training AI phishing simulations in Hindi and 22 Indian languages. India-specific lures including GST, UPI, and Aadhaar attacks. **Features:** - Native Hindi Templates: Written from scratch in Hindi, Hinglish, and regional languages — not translated English - UPI / GST / Aadhaar Lures: Fake GST notices, UPI payment requests, Aadhaar verification links, EPF withdrawal alerts, Income Tax refund emails - WhatsApp Simulation: Fake HR messages, CEO fraud via WhatsApp Business, supplier payment change requests - Real-Time Dashboard: Click rates, report rates, training completion across departments, industry benchmarks - Automatic Remedial Training: Employees who click are auto-enrolled in 3-minute microlearning modules - Board-Ready Reports: Monthly PDF reports with risk trends, department comparison, DPDP compliance posture **India-Specific Phishing Lures (40-60% click rates):** - Income Tax Notice (High risk) - Aadhaar Update (Critical risk) - EPF Locked (High risk) - Job Offer (Medium risk) - Bank KYC (Critical risk) - GST Notice (High risk) **AI Capabilities:** - Adaptive Difficulty: Adjusts sophistication based on employee track record - Real-Time Threat Integration: New phishing campaigns targeting Indian companies turned into simulations within hours - Contextual Microlearning: Training explains exact red flags missed, in the employee's language **Pricing:** Pay-per-user, India-priced — typically 30–65% lower than KnowBe4 ($12–25/user/year range). Scope confirmed on a call. --- ### 7. Incident Response Retainer URL: https://www.bachao.ai/incident-response Pre-paid retainer for on-call breach response. CERT-In compliant. AI-accelerated forensics. 2-hour response SLA. **What the retainer covers:** - Breach Containment: Isolate compromised systems, block lateral movement, preserve evidence within first 2 hours - Digital Forensics: AI-accelerated log analysis. Root cause in hours, not weeks. Chain of custody for legal proceedings. - CERT-In Notification: Drafts and files CERT-In 6-hour breach notification with all required details - Recovery Planning: System restoration priority, data integrity verification, service-by-service bring-up - Post-Incident Report: Timeline, root cause, impact scope, remediation steps, board-ready executive summary - Legal & Board Communication: Board notification, customer disclosure (DPDP requirement), regulatory filings, media response **Indian Regulatory Context:** - CERT-In 6-Hour Rule (April 2022): All organizations must report cyber incidents within 6 hours. Failure is a separate violation. - DPDP Act Breach Obligations: Must notify Data Protection Board and affected individuals of any personal data breach. - INR 250Cr penalty: A breach that could have been contained with proper IR but wasn't = "failure to implement reasonable security safeguards" **AI Advantage over Traditional IR:** - Log analysis: 2-4 hours (vs 2-5 days traditional) - Root cause: With evidence chain (vs often inconclusive) - CERT-In notification: Auto-drafted (vs scrambled together) - Board report: Same day (vs weeks after incident) **Retainer Pricing:** Pay-per-use retainers — 30–65% less than the standard manual-IR engagement bracket in India. Plans are sized to your scope on a call: - Starter — IR hours, 2-hour SLA, CERT-In notification, post-incident report - Growth — more IR hours, 1-hour SLA, full forensics, board comms, quarterly IR drills - Enterprise — unlimited hours, dedicated IR lead, 24/7 SOC, custom playbooks, on-site support Average breach cost in India: INR 22 crore (IBM 2025). --- ## Pricing — Model Bachao.AI is pay-per-use. The scan and the full report are free. Client pays only for optional add-ons, and pays less when usage is less. All paid scopes are 30–65% lower than traditional vendor engagement brackets — exact pricing is discussed on a call so it fits how much you actually scan and which products you turn on. ### Core VAPT - Free Scan — no credit card required. Summary report, risk score, and top findings visible immediately. - Full Report — free. Complete findings, remediation steps, and DPDP mapping unlock on the web once you verify domain ownership via a DNS TXT record. - Certificate of VAPT — ₹2,000 one-time. Verifiable certificate plus a downloadable PDF of the full report. - Full VAPT (credentialed) — ₹10,000. Black + Grey + White box testing with credentials. - AutoFix remediation — priced per finding as a dynamic quote, not a flat fee. ### Additional Products (all pay-per-use) - DPDP Readiness Score — free - DPDP Compliance Report - Hindi / regional-language Phishing Simulation - Brand & Phishing Monitor - Deepfake Detection - SAST + SCA Bundle - Cyber Insurance Score - Dark Web Monitoring - Cloud Security Audit - Incident Response Retainer ### Competitor approximate pricing (for context) - Astra Security: INR 16,000+/mo - CyberNX: INR 15,000–50,000/mo - HackerOne: $18,000+/yr - Manual VAPT engagements: INR 40,000–8,50,000 per engagement (industry range) - KnowBe4 (training): $12–25/user/year - Bachao.AI: free first scan, then 30–65% lower than the above on a pay-per-use model — exact scope-based quote on a call Contact: https://www.bachao.ai/contact --- ## Technical Architecture ### Scan Infrastructure - Firecracker microVMs for complete isolation of each scan - Tools: Nuclei (9,000+ templates), OWASP ZAP, Nmap, SSLyze running in parallel - AI orchestration via Claude for validation, triage, translation, and remediation generation - DNS-based domain ownership verification (IT Act 2000 compliant) - Report delivery: PDF + JSON + web dashboard - Data stored on Indian infrastructure in DPDP compliance ### Security Scan Methodology - Non-destructive payloads only — no PUT/DELETE requests, no data mutation - Safe for production environments - Unauthenticated and authenticated scan modes - Credentials encrypted at rest and purged after scan completion - Scan artifacts purged within 72 hours; reports retained 12 months on paid plans --- ## Founder & Team ### Shouvik Mukherjee — Founder From INR 4K/month call centres to 90 LPA at Peak XV-backed companies, then left to build Bachao.AI. **Career Timeline:** - 2007-2009: Call Centres — started at INR 4K/month, built SEO/affiliate side income to INR 1-2L/year - 2011-2013: Wipro Technology Division — no degree, self-taught VBA, proved skill beats credentials - 2013-2018: Cantrip Solutions — founded and scaled from INR 20K to INR 2Cr revenue, 46 engineers. Shut down after father's terminal cancer diagnosis. - 2018-2020: Micronic Technologies — Tech Lead at 18 LPA, rebuilt from INR 40L debt - 2020-2022: Intuit — Principal Engineer, 24 LPA, led QBO India compliance systems - 2023: IDFC First Bank — Tech Lead, 55 LPA. Simultaneously launched Zakaria Streets (150+ orders/day, 4.6-star rating) - 2024: K12 Techno (Peak XV/Kedaara) — Principal Software Engineer, 90 LPA. Left after 7 months due to CXO conflicts. - 2025: Bachao.AI — All in. Pivoted from B2C to B2B after investor feedback. **Background:** Self-taught engineer. No CS degree. Built Cantrip Solutions from INR 20K to INR 2Cr revenue with 46 engineers. Survived INR 40L debt. Every role contributed domain expertise: compliance systems at Intuit, banking-grade security at IDFC, scale at K12 Techno. --- ## Key Differentiators 1. **AI-native**: Automated scanning with AI-powered analysis, validation, and remediation — not rule-based templates 2. **India-first**: Pricing in INR, DPDP Act compliance focus, Hindi/regional language phishing simulations, UPI/Aadhaar/GST-specific security testing 3. **Affordable**: Starts free; pay-per-use model is typically 30–65% lower than enterprise SaaS alternatives in the INR 16,000+/mo bracket 4. **End-to-end**: Scan, report, remediate — Bachao.AI can also fix the vulnerabilities for you (fix quote included in every full report) 5. **Zero false positives**: Every finding validated by AI before inclusion in reports. Under 3% validated false-positive rate. 6. **Fast**: 2-hour scan-to-report vs 4-8 weeks for traditional VAPT 7. **Bilingual**: Reports in English and Hindi. Phishing simulations in 22 Indian languages. --- ## Partner Program URL: https://www.bachao.ai/partners Two tracks for earning recurring revenue: **vCISO / Security Consultants (25-30% commission):** - Full white-label platform access - Co-branded reports - BCSP, CEH, CISSP certification support - ISO 27001, SOC 2, PCI-DSS certification referral fees - Dedicated partner dashboard **Digital Businesses (20-25% commission):** - Referral link with attribution tracking - API integration - Bulk scan pricing for client portfolios - Marketing collateral and co-branding - Priority support for partner-referred clients Commission rates: 20–30% recurring on the active subscription. Exact partner economics confirmed on a scoping call so the program fits how you sell. No upfront fees, no minimums. --- ## Frequently Asked Questions **What is included in the free scan?** The full scan runs on your domain — same tools, same depth. You get a summary report with finding counts by severity, overall risk score, and the top 5 critical findings (titles only). No credit card required. **How do I upgrade to the full report?** There is no upgrade needed — the full report (all findings, remediation steps, and DPDP mapping) is free to view on your dashboard once you verify domain ownership via a DNS TXT record. Two paid add-ons are available on top of the free report: a verifiable Certificate of VAPT with a downloadable PDF (₹2,000 one-time), and a credentialed Full VAPT engagement covering Black + Grey + White box testing (₹10,000). Remediation, if you want Bachao.AI to fix findings for you, is priced per finding via AutoFix — a dynamic quote, not a flat fee. **What is in the fix quote?** Every full report includes a fix quote — a timeline and cost estimate for Bachao.AI to remediate the findings for you. Accept it to get vulnerabilities fixed by the team, or use the report to fix them yourself. **Do I need a subscription?** No. First scan is free and paid reports are pay-per-use, one-time. Subscriptions (Starter, Growth) are optional for teams that need regular scanning at lower per-report cost. **What payment methods are accepted?** UPI, credit/debit cards, and net banking — processed securely via Cashfree. Bank transfers for custom plans. **What is the refund policy?** Full refund if a scan fails to complete or produces no results. No questions asked. Only charge for reports that deliver actionable findings. **Will scans affect production?** Scans use non-destructive payloads only. No PUT/DELETE requests, no data mutation. Safe for production. Recommend running during low-traffic windows as a precaution. **How are false positives handled?** Every finding re-tested by Claude AI before inclusion. If a vulnerability cannot be reproduced or validated against the live target, it is excluded. Validated false-positive rate under 3%. **Can I integrate into CI/CD?** Yes. Growth and Agency plans include API access. Trigger scans from GitHub Actions, GitLab CI, or any pipeline. Results returned as JSON with webhook support. **How long is scan data retained?** Reports retained 12 months on paid plans. Scan artifacts purged within 72 hours. All data stored on Indian infrastructure in DPDP compliance. **Do you need production credentials?** No credentials required for unauthenticated scanning. For authenticated scans (behind login), provide a test account. Credentials encrypted at rest and purged after completion. --- ## Blog Post Summaries ### Why Every Indian SMB Needs a VAPT Scan in 2026 Published: March 15, 2026 | Author: Shouvik Mukherjee Summary: CERT-In reported 35% increase in cyberattacks targeting Indian SMBs in 2025. Ransomware gangs specifically targeting Indian SMBs lacking basic security. DPDP Act enforcement deadlines approaching with penalties up to INR 250 crore. Free VAPT scans provide a practical first step toward security and compliance. URL: https://www.bachao.ai/blog/why-every-indian-smb-needs-vapt-scan-2026 ### Understanding the DPDP Act 2023: A Complete Guide for Small Businesses Published: March 10, 2026 | Author: Shouvik Mukherjee Summary: Explains DPDP Act obligations for small businesses — consent, security safeguards, data deletion, breach notification. Covers penalty structure (INR 250Cr for security failures, INR 200Cr for breach notification failure, INR 50Cr for deletion failures). Three practical compliance steps: audit data collection, update privacy policies, run a security assessment. URL: https://www.bachao.ai/blog/understanding-dpdp-act-2023-guide-small-businesses ### 5 Cybersecurity Mistakes Indian Startups Make (And How to Fix Them) Published: March 5, 2026 | Author: Shouvik Mukherjee Summary: Common vulnerabilities found scanning hundreds of Indian startup domains: (1) exposed admin panels, (2) outdated software with known CVEs, (3) default/weak credentials, (4) no HTTPS enforcement, (5) zero logging or monitoring. Each mistake has a straightforward, low-cost fix detailed in the article. URL: https://www.bachao.ai/blog/5-cybersecurity-mistakes-indian-startups --- ## All Pages - Home: https://www.bachao.ai - VAPT Scanner: https://www.bachao.ai/vapt - API Security: https://www.bachao.ai/api-security - Cloud Security: https://www.bachao.ai/cloud-security - Dark Web Monitoring: https://www.bachao.ai/dark-web-monitoring - DPDP Compliance: https://www.bachao.ai/dpdp-compliance - Security Training: https://www.bachao.ai/security-training - Incident Response: https://www.bachao.ai/incident-response - About: https://www.bachao.ai/about - Contact: https://www.bachao.ai/contact - Partner Program: https://www.bachao.ai/partners - Blog: https://www.bachao.ai/blog - Privacy Policy: https://www.bachao.ai/privacy-policy - Terms of Service: https://www.bachao.ai/terms-of-service - Refund Policy: https://www.bachao.ai/refund-policy - LLMs.txt: https://www.bachao.ai/llms.txt - LLMs Full: https://www.bachao.ai/llms-full.txt