The stack question is the cheap half — @Crypto_Toolbox already handed you that. 
Here’s the part nobody said: you’re optimising supply with zero demand attached. In India the demand isn’t something you find. It’s scheduled. SEBI, RBI and DPDP put regulated companies on a clock — and only CERT-In empanelled firms can sign off many of those audits. There are 237 of them, they’re permanently short of testers, they subcontract, and their names, emails and mobile numbers sit in a public PDF. 
No company. No product. No pitch deck. Your existing VAPT skill, invoiced.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
01 The door — sell to the people who already sold it
They won the contract. They’re short of hands. That’s a market of firms, not strangers.
├─
CERT-In empanelled organisations — the whole list: 237 firms, 326 contact emails, named people, direct mobile numbers, and a per-firm skills & competence snapshot so you know who does web vs cloud vs ICS before you write a word
├─
CREST accredited suppliers — filter India, pitch yourself as overflow capacity on deadline-bound work
├─
PCI QSA directory — every QSA owes annual assessments and outsources the technical half
└─
CPPP / GePNIC tenders — search awarded VAPT / security audit tenders. Two things fall out at once: real contract values → your rate card, and who keeps bidding → your call list
Don’t chase CERT-In empanelment yourself — that gate needs a company, audited turnover and a team. The money is on the other side of the same door.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
02 The clock — who is required to buy, and when
Registries with contact details. Not leads you guess at — entities under a standing obligation.
Registry |
Who’s inside |
The trigger |
SEBI recognised intermediaries |
1000+ brokers, RIAs, portfolio managers — with compliance-officer name, email, phone |
CSCRF audit + VAPT mandate |
RBI NBFC registry |
every registered NBFC |
IS/cyber-audit duty, almost none have an in-house tester |
IFSCA entity directory |
~1,965 GIFT City entities |
newly licensed, cash-rich, building controls from zero |
Visa Global Registry |
validated payment service providers |
must re-validate every 12 months — a dated trigger you can time outreach to |
ransomware.live API |
companies posted on leak sites this week, filterable by country |
the board is asking questions right now |
↳ Qualify before you spend a call: Tofler (directors, financials, filings — can they actually pay?) · bulk prospect building from MCA company master data.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
03 Open the conversation with a finding, not a hello
All public-exposure indexes — the work is already indexed, you’re reading it, not touching them.
├─
LeakIX — already-indexed exposed services and databases, searchable by country
├─
Netlas free tier — map a prospect’s external surface so your first email contains a fact
├─
FOFA + ZoomEye — best coverage of Asian netblocks and the gear Indian SMEs actually run; Western scanners under-index it
├─
CertStream — live certificate feed. New certificate → new subdomain → new asset → reason to call
└─
RansomLook — second leak-site aggregator to catch what the first misses
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
04 Look like a firm on day one
Nobody signs with someone who improvises the paperwork.
├─
SANS pen test scope worksheet — walk the client through it on call one and price the job instead of guessing
├─
GSA HACS pentest SOW — statement-of-work wording written by a government buyer; paste it into your proposal
├─
pentest-report-templates — scoping questionnaire, rules of engagement, report skeleton, whole set
├─
Contract Killer — plain-language contract, signed same day, no lawyer, no entity
└─
engagement folder template — evidence/notes/findings per job, so your reports pile up as a corpus instead of scattered files (that pile is the moat later — hold that thought)
A billable deliverable in one command:
prowler aws # or azure / gcp / kubernetes
Prowler hands back findings already mapped to ISO 27001, SOC 2, PCI and CIS — a report you can charge for on day one. Then Powerpipe benchmark hub turns the same run into a recurring monthly compliance check you white-label and bill every month.
💵 Cash floor while the pipeline fills — USD contracts that need no company
These pay an individual in India directly. No entity, no client hunting, no product.
├─
Mercor — their own board lists Cybersecurity Experts, $70–$90/hr. Remote, hourly, individual contract
├─
Outlier · micro1 · Turing — red-teaming and security tracks pay above the general pool; offensive-security background is the qualifier
├─
Braintrust — 0% talent-side fee, you keep the whole rate you quote
└─
AlphaSights — paid hour-long expert calls on your domain. No deliverable at all, just knowing things
Treat this as the floor, not the plan. It funds the months while 01–03 compound.
🧬 The product only you can build — AI × offsec, with a data moat
Generic RAG wrappers are a commodity. Yours stops being generic the moment it’s fed reports nobody else has — which is exactly what stage 04 accumulates.
├─
SEBI CSCRF ↔ CIS v8.1 crosswalk — clause-to-control mapping. This is the spine of a CSCRF gap-assessment service: the translation layer regulated firms will pay for and can’t do themselves
├─
TSI DPDP consent manager — India’s DPDP creates a statutory consent duty and most SMEs have no software for it. Self-host, deploy, host it for them
├─
LLM Guard — prompt-injection / PII / jailbreak filter you bolt onto a client’s AI app. The one module where your two skills stack into a single sellable thing
└─
Opik — self-hosted RAG tracing + eval, actively maintained. How you prove output quality to a buyer instead of claiming it
↳ The compounding: engagements → domain access → a private corpus of real findings → a RAG product with proprietary data behind it. Same hours, three assets.
🧱 The shell you actually asked about — additive picks, nothing already named above
Clone, don’t build:
├─
Bullet Train (Rails) — teams, invitations, roles, Stripe subs, admin, REST API. The most complete free kit the JS crowd never mentions
├─
BoxyHQ starter — ships SAML SSO, directory sync, audit logs, so a ₹40k/mo “Enterprise” tier exists on day one
├─
Frappe Press — the real control plane an Indian company runs its SaaS business on: provisioning, plans, metering, invoicing, GST. Fork it instead of inventing it
├─
Pagoda (Go) — one binary, auth + admin + jobs, runs on a ₹300/mo VPS
└─
Open SaaS — React/Node with Stripe or Polar or Lemon Squeezy already wired
Two pieces that quietly decide whether B2B works:
├─
Rauthy — full OIDC identity server in ~64–128MB RAM. Auth that costs nothing per user
└─
ZenStack — row-level access rules in your Prisma schema. Kills the #1 SaaS data-leak bug: one tenant seeing another’s rows
Getting paid from India, globally: use a Merchant of Record (Dodo Payments, Polar, Creem) — it rents you the entity, tax, VAT/GST and invoicing so plain-Stripe cross-border paperwork isn’t your problem.
Skip the US LLC at zero revenue — Clemta/doola/Firstbase add formation cost, agent fees and annual US filings you can’t service yet. You can invoice foreign clients as an Indian individual now (PAN + bank + FIRA; GST/LUT only at threshold). Revisit when a client demands a US counterparty.
AWS Activate now requires an account already on a paid tier plan — budget for that before counting on the credits.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
The order that matters: 01 door → 02 clock → 03 finding → 04 paperwork. Stack 05 only after money moves. Burnout isn’t a scheduling problem — it’s what happens when effort has no invoice attached to it.
Empanelment is a queue you can’t join — but every firm in that queue has more deadlines than testers.