B-52 was built by the people who used to do this by hand
B-52 is made by Security Brigade Infosec Pvt Ltd, an assessment firm working from Mumbai. The same company, the same auditors, and all of their work since 2006 sitting inside the platform that now does the testing.
Where it came from
Every assessment since 2006, kept in one place
Security Brigade has been CERT-In empanelled since 2008, and has been running enterprise assessments continuously since the firm started in 2006. Every one of those engagements was worked inside Lemon, the firm’s own assessment platform, which means the test cases written, the vulnerabilities proved and the threat models drawn all stayed with the firm rather than leaving with the auditor who wrote them.
A record like that is easy to lose twice over — once when an engagement closes and the working notes leave with it, and again when the person who did the work moves on. Keeping it was an ordinary operational decision for a long time. It turned out to be the thing that made an autonomous tester possible.
The heritage figure, and where it is held
- 6,700+ assessments of accumulated test cases, vulnerabilities and threat models.
- Lemon holds the count. It is the platform every Security Brigade engagement has been run in, so the figure is a record rather than an estimate.
- That corpus is what our models were trained on, which is why the platform starts from practice rather than from a check list.
Why we built it
We always knew what to test. We ran out of hours
It was hours. A senior assessor can work a finite number of applications in a year, and the applications that miss the annual scope are rarely the ones nobody cares about — they are the ones there was no auditor left to point at. That gap is where an estate quietly accumulates risk between engagements.
So the practice was written into a harness instead: mindmap creation, test-case generation, comprehensive JavaScript analysis and functional flow analysis — the four things our auditors work through on an application assessment — run the same way on every target and worked through in full rather than sampled down to fit the time available.
Then we pointed it at the people it was built from. Run in parallel with Security Brigade’s own expert assessment team on the same targets, B-52 reached 90–95% of the combined findings set and surfaced issues the human team did not. Comparable coverage, different blind spots — which is the honest argument for putting an auditor on top of it rather than instead of it.
What is certified, and what is not
Security Brigade holds the certifications. B-52 does the testing
This distinction decides what you can do with a report, so it is worth being exact about. Empanelment and certification attach to Security Brigade as a firm. They reach an assessment through the auditor who is in it.
| Instrument | Held by | What it covers |
|---|---|---|
| CERT-In empanelment | Security Brigade, the firm | What makes an assessment signable for a regulated filing, provided an empanelled auditor is in the engagement — the expert-verified and human-led models. |
| CERT-In empanelment is a condition of the testing itself, and not only of the vendor who supplies it. That is why the delivery model decides what you can file, rather than the platform. | ||
| ISO 27001 certification | Security Brigade, the firm | How the firm runs itself, and how it handles what a client gives it to test. |
| Platform certification | Not held | B-52 carries no certification of its own. The two instruments above are the firm’s and they cover the delivery. |
The instruments behind a B-52 engagement, and who holds each one
CERT-In empanelment
- Held by
- Security Brigade, the firm
- What it covers
- What makes an assessment signable for a regulated filing, provided an empanelled auditor is in the engagement — the expert-verified and human-led models.
CERT-In empanelment is a condition of the testing itself, and not only of the vendor who supplies it. That is why the delivery model decides what you can file, rather than the platform.
ISO 27001 certification
- Held by
- Security Brigade, the firm
- What it covers
- How the firm runs itself, and how it handles what a client gives it to test.
Platform certification
- Held by
- Not held
- What it covers
- B-52 carries no certification of its own. The two instruments above are the firm’s and they cover the delivery.
The company behind it
Security Brigade Infosec Pvt Ltd is an Indian company, based in Mumbai, and it is the legal entity behind every B-52 engagement. Assessments are delivered by its own auditors, in the two delivery models that carry one.
ShadowMap is the other half of the estate: it discovers what an organisation has exposed to the internet, and B-52 tests what it finds. That is the whole of the relationship, and it runs in one direction. B-52 is subscribed separately and is never a module inside ShadowMap or inside its licence.
Talk to the people who built it
A scoping enquiry is answered by the assessment team. If your output has to be signed for a regulator, say so first — that decides the delivery model before anything else does.