Company
Engineers who got tired of writing reports nobody acted on.
KnightGrid is the managed security practice of ByteKnight Security Private Limited. We started as a testing firm, kept getting asked who would defend what we had just fixed, and built the answer.
Why we exist
The gap between finding a problem and fixing it
Most security spending in India buys either a tool or a document. Both are useful and neither, on its own, changes what happens at three in the morning when a valid credential logs in from somewhere it should not.
We built KnightGrid around the part that is usually missing: continuous operation by people who know your environment. Not a ticket queue, not an alert forwarded to your inbox, but engineers with pre-agreed authority to contain the thing while you sleep.
That shapes how we sell. Remediation sits inside the engagement rather than being quoted afterwards, we hold no resale quota so we can tell you which licences to cancel, and every claim we make about your posture points at evidence you can inspect yourself.
History
How we got here
- 2019
ByteKnight Security incorporated
Founded in Gurgaon by engineers out of enterprise SOC and endpoint management backgrounds, initially running device and identity projects on retainer.
- 2021
The first managed pod
Clients kept asking who would watch the fixes we had just shipped. The pod model — one named team, continuous coverage — came out of answering that honestly.
- 2023
Compliance practice added
ISO 27001 and SOC 2 work moved in-house after too many clients were handed a policy pack by someone else and asked us to make it true.
- 2025
KnightGrid launched
The managed practice took its own name and its own operating model, with the DPDP Act reshaping what Indian companies had to prove.
Principles
What we hold ourselves to
We do the work
Plenty of firms sell you a report. We would rather be measured on what actually got fixed, so remediation is inside the engagement rather than quoted separately afterwards.
Tool-agnostic by default
We have no resale quota to hit. If the licence you already pay for can do the job, we will configure it properly and tell you which of the others to cancel.
One pod, not a ticket queue
The engineers who onboard you stay with you. They learn your environment, and that knowledge is the difference between a fifteen-minute triage and a two-hour one.
Plain language
Reports go to boards and to engineers, so we write them for both. If a finding cannot be explained without a vendor acronym, it is not yet understood.
Evidence over assertion
Every claim we make about your posture is backed by something you can inspect. Dashboards are yours, not a screenshot we email monthly.
Honest about limits
If a control will not survive contact with how your teams work, we will say so at design time rather than write it into a policy nobody follows.
Frameworks
What we align to
These describe how we work. Where a certification is held rather than aligned to, we will show you the certificate — ask.
Find us
Where we are
Working together
We will tell you in the first call if we are not the right fit.
It saves everyone a quarter, and it is the reason our clients send us their peers.