Built by operators, not marketers.
White Rose started because too many security reports read like they were written to sound impressive rather than to get fixed. We do the opposite — plain findings, working proof, and an engineering team that can build the fix if you want us to.
From one pentest to a full-stack security firm.
The short version of how White Rose came together.
Founded on a single VAPT contract
Started as a two-person offensive security shop doing web app assessments for early-stage startups.
Red team & network practice launched
Expanded into full red team operations and network penetration testing as client environments grew more complex.
Engineering arm formed
Clients kept asking who could actually fix what we found — so we built an in-house software, app, and web development team.
120+ engagements delivered
Now working across fintech, healthcare, and SaaS, with an annual retainer model for ongoing security partnership.
Principles that shape every engagement.
Proof over theory
Every finding ships with a working proof-of-concept. If we can't demonstrate impact, it doesn't go in the report as critical.
Plain language, always
A report should be readable by your engineers and your board in the same afternoon. Jargon doesn't get things fixed faster.
We fix what we find
Our engineering team can implement remediation directly, so security work doesn't stall waiting on a third-party developer.
Scoped, never oversold
We recommend the engagement that fits your actual risk, not the most expensive package on the list.
Small team, senior people.
Every engagement is led by someone who's done the work firsthand — not handed off to a junior analyst.
Arjun Kapoor
Founder & Head of Red TeamTen years in offensive security across fintech and critical infrastructure engagements.
Sana Mehta
Head of VAPTLeads web, mobile, and API testing with a background in application security engineering.
Rohit Verma
Head of EngineeringRuns the software, app, and web development practice — secure-by-design from day one.
Priya Nair
Head of ConsultingGuides clients through ISO 27001 and SOC 2 readiness, and leads incident response engagements.
Want to see how we work, not just what we say?
Ask for a sample report or a reference call. We'd rather show you than tell you.
Get in touch →