Episode 118 · Enterprise · 51 min

Buy the tools, then hire the hacker

AppSecure sells the one thing an ISO certificate and a scanner licence cannot buy — someone who attacks your application, your API and your cloud the way a real attacker would. Fifteen bug-bounty hunters now cover more than 300 companies across India, Singapore and the US, bootstrapped, with no sales team and a pipeline booked six months out.

S
Sandeep
Co-founder, AppSecure Security · with Vishal Krishna
Buy the tools, then hire the hacker — episode thumbnail
51:06
Said in this episode
▶ 19:36
300+
Companies secured globally
Applications, websites and cloud environments covered across India and international markets — served, he says, by a fifteen-person team.
▶ 17:16
15
People on the AppSecure team
Sandeep's claim on air is that the fifteen deliver more than companies staffed with a hundred security engineers; it is his own comparison, not an audited one.
▶ 2:56
$1,000
His first bug bounty payout, 2016
Found in his first week of learning bug bounty — seller-sensitive data exposed at a Dubai e-commerce company — and worth about ₹62,000 at the exchange rate he quotes.
▶ 36:05
20 / 80
Automatable work vs manual research
Roughly a fifth of the job can be scripted; the remaining four-fifths is research into bypassing protections that are already in place.
▶ 13:48
₹10–15 cr
Fraud running before anyone noticed
At an e-commerce company exploiting an application vulnerability; the trail was traced only after five to six crore of fraudulent transactions had gone through.
▶ 45:37
50 / 50
India vs overseas customers
Half the client base is Indian enterprises and startups, half international, with Singapore and the US named as the near-term expansion push.
The brief

The argument in sixty seconds

Sandeep's claim is that most Indian companies have bought security without acquiring it. They hold ISO certificates, run HTTPS, sit on AWS or GCP, own every scanner on the market — and are still taken apart by someone tampering with a quantity parameter to pay a tenth of the price for a ₹1 lakh iPhone, or bypassing a payment link to order coffee the counter never knows was unpaid. AppSecure sells the missing perspective: offensive security, a third eye that replicates a real-world attack on the application, the API and the cloud rather than auditing for compliance. The craft came from bug bounty — within a week of starting in 2016 he found a bug exposing seller data at a Dubai e-commerce store, was paid $1,000, roughly ₹62,000 at the exchange rate then, and bounty income sustained the company through the years when Indian startups did not believe they needed it. His second claim is about the shape of failure: breaches are rarely exotic. They are cloud credentials a developer left on the internet, storage buckets holding KYC data that nobody knew were public, missing validation at code level, and frauds of ₹10–15 crore that run unnoticed because no one built anomaly detection. His third is about leverage — fifteen people, no sales team, 300-plus clients split evenly between India and abroad, growth entirely on referrals, one customer eight years deep — and about AI, which now writes anyone's first exploit script but leaves untouched the 80% that matters: the research into how to bypass a fix that is already in place. The stakes: India is putting 100,000 brands and its whole payments layer online, and the state, which runs the largest attack surface of all, still has no bug bounty programme.

Worth your time if you are

CISOs who own every scanner and still get breached
Fintech and e-commerce engineers shipping payment flows
Bootstrapped founders selling a high-trust service without a sales team
Students plotting a security career without an IIT badge
Policy people wondering why government sites run no bug bounty
Episode map

Where the conversation travels

Every block is a chapter, coloured by what it's about. Click any of it to jump straight to that minute on YouTube.

01Cold open: one password for a whole college 0:00 Vishal frames the coming wave of 100,000 digital Indian brands and their payment, application and storage layers, then Sandeep traces the origin — 1 GB of daily college internet, a password shared by every student, and a self-taught path from Wi-Fi and LAN hacking to bug bounty in 2016. 02Bug bounty as working capital 3:12 A $1,000 payout in the first week produced the naive arithmetic of $365,000 a year, and when it didn't materialise, bounty income became the thing that kept AppSecure alive through the years when startups weren't ready to buy security at all. 03Business logic, not brute force 5:03 The most common e-commerce flaw isn't a break-in but a logic gap — intercept the request, tamper with the API parameters, set the quantity to 0.1 and take a ₹1 lakh iPhone for a fraction of it, or read another user's order and address. 04Injection, ransom, and the limits of tools 7:50 SQL and NoSQL injection let attackers dump, alter or delete a company's database and then demand five or ten Bitcoin for it, and while newer tooling has curbed the easy cases, Sandeep argues professional hackers still get through best-in-breed defences. 05Offensive security, defined 10:00 AppSecure describes itself as an offensive security company that replicates real-world attack scenarios on APIs, applications and cloud — most acutely for banks and fintechs, where a wallet holding ₹1,000 must never be able to send ₹2,000. 06Free coffee, and ₹15 crore nobody noticed 12:10 A payment-gateway bypass buys coffee the counter still records as paid, and the same class of code fault let frauds of ₹10–15 crore run at one e-commerce company until several crore had already gone — detectable only with analytics or anomaly detection. 07Missing checks and the Shopify question 14:40 Most vulnerabilities trace to a missing check at code level or unvalidated database queries, and as India's brands pile onto low-code platforms the risk shifts with the customisation — vanilla Shopify is Shopify's problem, custom code is yours. 08No sales team, 300 clients 16:53 Sales is founder-led and referral-driven with the pipeline already booked out six months on signed master service agreements — the opposite of 2016, when prospects answered that an ISO certificate, HTTPS and AWS meant they were already secure. 09Fifteen people, automation first 19:40 Serving 300-plus companies with fifteen people works, he argues, by automating what can be automated and reserving humans for research, hiring only top rankers from bug bounty programmes into a culture built on protecting the internet. 10What a breach actually is 21:40 Mass breaches come overwhelmingly from the cloud — credentials a developer leaked onto the internet, storage buckets holding KYC data left readable — and the Domino's leak shows the consequence, which is why he insists security is a shared responsibility, not one team's. 11Contracts, cadence, and the third eye 24:00 The offering is a full contract for application and cloud security rather than pay-per-bug, run every six months, quarterly or monthly depending on the data and the release velocity — because clients want a hacker's view, not another scanner run. 12White hats, black hats, thirty years 27:05 Asked whether the dark side simply pays better, Sandeep answers with time horizon and trust — selling data pays now and costs the next thirty or forty years — and argues white hats are currently the more motivated side, steadily making the attacker's job harder. 13The government's missing bug bounty 30:40 He separates UPI WhatsApp scams, which are people falling for social engineering rather than app vulnerabilities, from the real gap — that Indian government infrastructure runs no bug bounty programme and so never gets the researcher's view. 14AI writes the boilerplate; research is the 80% 33:50 Generative tools hand both sides a first script and let AppSecure kill repetitive work across similar engagements, but only about 20% of the job automates — the remaining 80% is research into bypassing a firewall, a fix or an email security tool that already works. 15How to become a bug bounty hunter 38:20 One customer is eight years in and security vendors now ask AppSecure to benchmark their own products, before the advice for beginners: protocols, authentication and authorisation, the OWASP list, one programming language, public disclosure platforms and Medium — and a warning that some companies answer a report with a legal notice. 16Bootstrapped, 50/50, and a first-year founder 44:30 Plans run to a multiplied team and expansion into Singapore and the US on a customer base split evenly between India and abroad, with no VC taken so far, and a closing argument that a tier-three college and an engineering degree chosen because friends did it were never the constraint.
Takeaways

Ideas to carry out of this hour

01

Compliance is not security, and the buyer knows it

The companies engaging AppSecure are not short of tooling — they can purchase n number of scanners, deploy them, and staff an internal security team. What they are buying is a third eye: an attack replicated on their application, API and cloud from the outside, by people who think about how to get in rather than how to pass an audit. In 2016 the standard objection was an ISO certificate, HTTPS and a cloud account; the shift Sandeep points to is that buyers now understand internal security controls and external attack resistance are different products.

02

The dangerous bugs are logic gaps, not exotic exploits

The most common e-commerce vulnerability is a business-logic failure: intercept the request, tamper with API parameters, set a quantity to 0.1 and pay a fraction of a ₹1 lakh iPhone's price, or read another customer's order and delivery address. No internal access is needed — you sign up like any user and change what the app never validated. The same class of gap lets a payment link be bypassed entirely, which is why he traces almost everything back to a missing check at code level.

03

Undetected fraud is the real cost, not the breach headline

Sandeep has seen fraud run at ₹10–15 crore while the company remained unaware it was happening at all; in one e-commerce case the trail was picked up only after five or six crore of fraudulent transactions. Prevention was never the only failure — the missing capability was analytics or anomaly detection that would have flagged an order flow that didn't add up. A bypassed payment gateway looks, to the receiving team, exactly like a completed order.

04

Most breaches walk in through the cloud, not the code

When data leaks at mass scale, he says, the vector is usually a cloud vulnerability rather than an application one — credentials a developer mistakenly published on the internet, or a storage bucket holding KYC and customer records that the team never realised was reachable. The attacker's work is then reduced to downloading. His conclusion is a governance one: the developer writing the code, the engineer deploying it and the security team all own the outcome, so blaming an individual after the fact misses the system.

05

Referrals beat a sales team when the work is verifiable

AppSecure has no sales function — it is founder-led selling on top of referrals from every client since the beginning, and the pipeline is already committed six months out on signed master service agreements. Fifteen people serve more than 300 companies, split evenly between India and overseas, with one customer eight years into the relationship, and the business is bootstrapped. His stated theory is that a service of high enough quality sells itself, which works precisely because a security finding is either reproducible or it isn't.

06

AI lowers the floor for both sides and raises nothing else

Generative tools now write a usable first script for anyone with almost no development background, which arms black hats and white hats identically; AppSecure itself uses them to strip out the repetitive work that recurs across similar engagements. But the split he gives is roughly 20% automatable and 80% manual research, and the 80% is the part that matters — working out how to bypass a fix the company has already deployed, a firewall that already blocks you, an email security tool that already catches phishing.

07

The white hat's advantage is the time horizon

Asked directly whether the dark side pays better, Sandeep concedes it can — and answers with duration rather than morality: selling data makes money in the short run and buys trouble for the next thirty or forty years. The team is recruited out of bug bounty programmes and shared networks, and the stated driving force is protecting data, including the country's. His read on the balance of power is that white hats are currently the more motivated side, steadily hardening postures and making the attacker's economics worse.

08

The state's attack surface has no researcher pipeline

AppSecure does no government work and Sandeep is careful to separate the categories: WhatsApp payment-link scams and shared OTPs are people falling for social engineering, not application vulnerabilities. The genuine gap is structural — Indian government bodies run no bug bounty programmes, so the researchers who would otherwise probe their websites, cloud and network infrastructure have no sanctioned route in. Worse, some companies answer a good-faith disclosure with a legal notice designed to make the researcher stop looking, which he calls a leadership problem rather than a geographic one.

The numbers, drawn

What the episode measures

Every figure below was said on air — timestamps included, caveats kept.

Conversation share

portion of the hour spent on each theme
SaaS & enterprise · 22%Data & digitisation · 16%Payments & fintech · 14%Founder journey · 12%Sales, GTM & growth · 11%Hiring & talent · 10%
SaaS & enterprise22%
Data & digitisation16%
Payments & fintech14%
Founder journey12%
Sales, GTM & growth11%
Hiring & talent10%
Computed from the chapter map of this episode.

What can actually be automated

% of the work
Automatable · 20%Manual research · 80%
Automatable20%
Manual research80%
As stated in conversation: about 20% of the security work can be automated, while the remaining 80% — finding a way past a fix, a firewall or an email security tool that already works — stays manual research.▶ 36:05

Headcount, as claimed on air

security engineers
AppSecure team15Peers he compares ag100
Sandeep's own claim rather than an audited comparison: a fifteen-person team delivering more than companies running a hundred security engineers, on a mix of automation and manual research.▶ 17:16
Worth keeping

Lines that stay

I made $1,000 in one day, so in 365 days I can make 365,000 dollars. But that doesn't happen.

— Sandeep ▶ 3:12

Think you're sitting in Starbucks ordering coffee from your laptop. If there's a vulnerability that lets you bypass the payment, you can — and the receptionist will never know you bypassed the gateway. They only see that you placed the order and paid.

— Sandeep ▶ 13:13

Security is everyone's responsibility. The person writing the code is responsible for the security of his code, the person deploying it on the cloud is responsible, and the security team is responsible. It is a shared responsibility, not one person's.

— Sandeep ▶ 23:45

They can purchase n number of tools, deploy them, run them, even build their own security team. The reason they engage us is to have a third eye — what a hacker thinks from outside.

— Sandeep ▶ 26:48

If we followed a black-hat approach, selling data and making money, we could make a lot — for the short term. And then we'd be in trouble for the next 30 or 40 years.

— Sandeep ▶ 28:43
Clips that travel

Short on time? Start here

Students plotting a security career without an IIT badge

The bug that paid $1,000 in a week

The origin story that doubles as the business model — a first bounty in 2016, the $365k fantasy, and bounty income funding the company before anyone would buy.

2:26 → 5:03 · 3 min ▶ Watch clip
Fintech and e-commerce engineers shipping payment flows

Free coffee, and the fraud nobody noticed

A payment bypass the counter records as paid, and ₹10–15 crore of fraud running unseen for want of anomaly detection.

12:06 → 14:40 · 3 min ▶ Watch clip
CISOs who own every scanner and still get breached

Why every scanner you own isn't security

The contract shape, the engagement cadence, and the argument for a third eye over a compliance scan.

24:00 → 27:05 · 3 min ▶ Watch clip
Security leaders hiring offensive talent

What keeps a white hat white

The blunt question about who the dark side pays better, answered with time horizon, trust and who is actually winning.

27:05 → 30:40 · 4 min ▶ Watch clip
Engineering leaders sizing AI's effect on security

AI writes the script; the 80% is still research

Generative tooling arming both sides, and the concrete research it can't do — bypassing a firewall or an email defence that already works.

34:04 → 38:20 · 4 min ▶ Watch clip
Glossary

The jargon, unpacked

Bug bounty
A programme where a company invites outside researchers to find vulnerabilities in its systems and pays per valid report — the training ground and early revenue source for AppSecure's founders and hires.
Offensive security
Testing by replicating a real attacker's approach against live applications, APIs and cloud infrastructure, rather than checking systems against a compliance checklist or running an automated scanner.
Business logic vulnerability
A flaw in what the application allows rather than in its code syntax — for example accepting a tampered quantity or price parameter, so an order completes at a value the business never intended.
Parameter tampering
Intercepting the request an app sends to its server and editing the values inside it before it arrives, which works whenever the server never re-validates what it is told.
SQL / NoSQL injection
Feeding an application crafted input that reaches its database as instructions, letting an attacker read, dump, modify or delete the data behind the app.
Cloud misconfiguration
Access settings left open by mistake — leaked credentials or a storage bucket holding customer and KYC records left publicly readable — which Sandeep names as the usual route to a mass data breach.
Responsible disclosure
The security policy published on a company's site setting out how researchers may report vulnerabilities and what they can expect in return, from a reward and Hall of Fame listing to, in bad cases, a legal notice.
OWASP Top 10
The standard industry list of the most critical web application security risks, named in the conversation as a fundamental any aspiring bug bounty hunter should know cold.
Connections

If this resonated, go here next

Full transcript

The whole conversation, searchable

196 segments

Auto-generated captions, lightly cleaned. Click a timestamp to open that moment on YouTube.