VAPT services in India usually arrive as a PDF of scanner output with a logo on it. Ours arrive with the reproduction steps, the account we reached, and the one fix that collapses the chain. Vulnerability assessment tells you what might be wrong; penetration testing tells you what an attacker can actually do about it.
Aphelion Cyber runs both, in that order, across web applications, mobile apps, APIs, cloud environments, wireless and internal networks. The assessment is broad and automated because breadth is cheap. The testing is manual and narrow because proof is not. What you receive is ranked by what it reaches in your environment, not by a CVSS number copied out of a database.
Most engagements start with a scoped external test and grow inward. If you already know the target is one application, web application penetration testing is the narrower service; if you want an adversary rather than an audit, that is red teaming.