Sandeep's claim is that most Indian companies have bought security without acquiring it. They hold ISO certificates, run HTTPS, sit on AWS or GCP, own every scanner on the market — and are still taken apart by someone tampering with a quantity parameter to pay a tenth of the price for a ₹1 lakh iPhone, or bypassing a payment link to order coffee the counter never knows was unpaid. AppSecure sells the missing perspective: offensive security, a third eye that replicates a real-world attack on the application, the API and the cloud rather than auditing for compliance. The craft came from bug bounty — within a week of starting in 2016 he found a bug exposing seller data at a Dubai e-commerce store, was paid $1,000, roughly ₹62,000 at the exchange rate then, and bounty income sustained the company through the years when Indian startups did not believe they needed it. His second claim is about the shape of failure: breaches are rarely exotic. They are cloud credentials a developer left on the internet, storage buckets holding KYC data that nobody knew were public, missing validation at code level, and frauds of ₹10–15 crore that run unnoticed because no one built anomaly detection. His third is about leverage — fifteen people, no sales team, 300-plus clients split evenly between India and abroad, growth entirely on referrals, one customer eight years deep — and about AI, which now writes anyone's first exploit script but leaves untouched the 80% that matters: the research into how to bypass a fix that is already in place. The stakes: India is putting 100,000 brands and its whole payments layer online, and the state, which runs the largest attack surface of all, still has no bug bounty programme.
Worth your time if you are
CISOs who own every scanner and still get breached
Fintech and e-commerce engineers shipping payment flows
Bootstrapped founders selling a high-trust service without a sales team
Students plotting a security career without an IIT badge
Policy people wondering why government sites run no bug bounty