Company

About Onion Infosec

Onion Infosec is a technology and security engineering company. We build technology, secure it and operate it, and we develop our own security products.

On this page
  1. What Onion Infosec is
  2. Company facts
  3. How we work
  4. Team expertise
  5. Where to go next

What Onion Infosec is

Onion Information Security Solutions Private Limited operates under the brand Onion Infosec. The company was founded in 2025 and is headquartered in Mumbai, India. We are a young company and we say so plainly. This site describes our work in enough detail for you to judge it for yourself.

The work is organized in seven service lines: Cybersecurity, AI, Software & Product Development, Cloud, IT, OT and Managed Services & Support.

Two in-house groups sit alongside the service lines. Security Products builds XDR, GRC, Autonomous SOC Analyst L1 & L2 and the OSINT Tool. Each product page shows where it stands. Security Labs is our research function.

The idea behind the company is simple. The same organization can build a system, secure it and run it, and what it learns in that work feeds its research and its products. Each area has its own specialists, and they work side by side: builders hear from the people who run their systems, and testers write findings with the engineers who will fix them.

Our purpose is to build, secure and run technology that organizations can depend on.

Company facts

The facts below are the ones we state about the company.

Legal name
Onion Information Security Solutions Private Limited
Brand
Onion Infosec
Founded
2025
Registered office
1st Floor, 1B-102, Parinee Crescenzo, G Block, Bandra Kurla Complex, Bandra East, Mumbai, Maharashtra 400051, India
Delivery
Remote and on site, for organizations wherever they operate. Project, retainer and managed-service models.
Capabilities
Cybersecurity, AI, Software & Product Development, Cloud, IT, OT, Managed Services & Support, Security Products and Security Labs

How we work

Four principles apply to every engagement, whatever the service line.

Integrity

We recommend only what the risk justifies, and we say so when a piece of work is not needed. Scope, assumptions and limitations are stated in writing before work starts.

Technical rigor

Findings rest on evidence, validated exploits and a reproducible method. If we cannot demonstrate it, we do not report it. The same standard applies to engineering work: designs are reviewed, changes are tested and decisions are written down.

Confidentiality

Every engagement is governed by a non-disclosure agreement and defined data-handling procedures. Details of a client environment stay within the engagement. The Trust & Security page describes how client information is handled.

Client outcomes

We measure success by the improvement in the client’s security and systems, not by the volume of findings or the size of the next proposal.

Team expertise

Our team brings together industry experts and young minds. Each service line, our products and Security Labs is handled by specialists in that field, across security, software, cloud, IT and OT engineering, working with young engineers who bring current tools and fresh thinking. Their backgrounds include incident response, threat hunting, security operations, detection engineering, offensive testing, software delivery and infrastructure operations.

Members of our team hold the certifications listed below, and more. These are individual certifications held by members of our team. They are not company accreditations.

Onion Infosec does not currently claim any company-level certification or accreditation. If that changes, it will be stated here and on the Trust & Security page.

  • OSCP: Offensive Security Certified Professional
  • CISSP: Certified Information Systems Security Professional
  • CISM: Certified Information Security Manager
  • CEH: Certified Ethical Hacker
  • CHFI: Computer Hacking Forensic Investigator

Where to go next

The rest of the site is organized by what you may need from us.

  • Services: the seven service lines and what each one delivers
  • Security Products: what we are developing and its current status
  • Security Labs: research areas, methods and outputs
  • Leadership: the disciplines the company is led across
  • Partner program: referral, delivery, technology, channel and white-label partnerships
  • Trust and security: how client information is handled
  • Contact: start a conversation about a project, a retainer or a managed service