Company / Trust
The due-diligence page
Everything a vendor evaluation needs, stated plainly. If a fact isn't here or linked from here, we probably can't prove it — and if we can't prove it, we don't publish it.
- Legal entity
- Virtue Software Technologies Private Limited
- CIN
- U72900TG2020PTC138226 (ROC Hyderabad, incorporated 6 January 2020, status: Active)
- Registered base
- AO-06, Block A, Indu Fortune Fields – The Annexe, K P H B Phase 7, Hyderabad, Telangana – 500085, India
- US office
- 10601 Clarence Dr, Ste 250, Frisco, TX 75033, USA
- Contact
- info@virtuestech.com · +91 733 746 2335 (IN) · +1 970 480 7559 (US)
- Team
- 100+ security and quality engineers; 63% hold industry certifications (CISSP, CEH, eCPPT, ISTQB, AWS)
- Track record
- 30+ enterprise engagements · 20+ clients since 2020
- Methodology
- OWASP Testing Guide, PTES, NIST SP 800-115; retest included as standard
- Compliance scope
- We test and report against GDPR, HIPAA, PCI DSS, SOC 2, and ISO 27001 requirements (client-side). We are an independent testing partner, not a certification body.
- Our own certification
- We hold no organizational certification today and do not claim otherwise. ISO 27001 certification for VirtuesTech is planned (stated July 2026) — milestones will be published here when they are reached, not before.
- Platforms
- VirtueThreatX (CTEM), VirtueShieldX (security operations), VirtueATLAS (QE) — built and operated in-house, in production
- Independence
- We don't build what we test, and we don't resell what we recommend. No tool-resale commissions influence findings.
Download company profile (PDF)
How we run engagements
Under NDA
Every engagement runs under a mutual non-disclosure agreement. Scope, rules of engagement, and communication channels are agreed before any testing begins.
Data handling
Findings and reports are shared only through the channels agreed at scoping and retained only for the period needed to deliver and support the engagement. Storage, encryption, retention, and destruction specifics are set in your service agreement.
Methodology & retest
Testing is aligned to the OWASP Testing Guide, PTES, and NIST SP 800-115. Remediation is verified on retest and the report updated to “remediated and retested.”
Personnel security
Engineers who handle client data sign NDAs and undergo background checks. The people who scope your engagement are the people who run it — no anonymous offshore bench.
Platform tenancy
VirtueShieldX is multi-tenant with strict per-tenant data isolation. Deployment and data-handling terms are agreed during the pilot and committed in your service agreement.
Vendor due diligence
Serious procurement asks for documents that don’t belong on a public page. We provide these under NDA during vendor onboarding. Ask your point of contact, or note it on the contact form:
- Data Processing Agreement (DPA) and sub-processor information
- Methodology and sample (redacted) deliverable
- Platform architecture and tenancy documentation
- Personnel-security summary (NDA and background-check practices)
- References from comparable engagements
We publish only what we can prove on this page and provide the rest through contracting — we don’t list certifications we don’t hold or documents we can’t stand behind.
Responsible disclosure
If you believe you’ve found a security issue in a VirtuesTech web property or platform, we want to hear from you. Email info@virtuestech.com with details and reproduction steps. Please give us reasonable time to investigate and remediate before any public disclosure, and avoid accessing or modifying data that isn’t yours. We don’t pursue good-faith researchers who follow this policy.
Our claim-discipline policy
Every factual statement on this website is maintained in an internal evidence register and reviewed before publication. We do not publish outcome percentages we haven’t measured, certifications we don’t hold, or partnerships that don’t exist. If you find a claim on this site you’d like substantiated, ask us — we’ll show our work.