cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
2012
Newcomer II

Reputed Pen Testing Companies to use

Hello,

 

Sorry if this post does not fit the content here. I would appreciate if esteemed members could suggest reputed names for engaging them for pen testing of SaaS-based service with desktop/mobile and browser clients.

 

Thanks in advance.

12 Replies
karishmaqualyse
Newcomer II
Caute_cautim
Community Champion

@karishmaqualyse 

 

A quick question on Google AI came up with the following companies:

 

Several companies offer reputable SaaS-based penetration testing services, including Cybri, NetSPI, Cobalt, Bishop Fox, Rhino Security Labs, Informer (Bugcrowd), and Veracode. These companies provide various levels of service, from expert-led, compliance-focused testing to continuous, automated assessment platforms. 

 

 
Here's a more detailed look at some of these companies and their offerings:
 
2. NetSPI: Known for enterprise-grade PTaaS, NetSPI integrates with CI/CD pipelines and DevOps workflows. 
 
3. Cobalt: Offers agile PTaaS with a focus on rapid launch and a global network of testers. 
 
4. Bishop Fox: Specializes in red teaming and continuous offensive testing for complex SaaS platforms. 
 
5. Rhino Security Labs: Provides in-depth manual testing, particularly for cloud-native and high-risk SaaS applications. 
 
6. Informer (Bugcrowd): Offers real-time PTaaS with continuous asset discovery capabilities. 
 
7. Veracode: Provides a unified AppSec platform with both PTaaS and AI-powered remediation features. 
 
8. Astra Security: Offers a SaaS platform that combines automated vulnerability scanning with manual penetration testing, focusing on SaaS applications. 
 
9. Rapid7: Known for its robust automated penetration testing solutions and integration with existing security frameworks. 
 
10. Qualysec: Offers comprehensive security assessments for SaaS applications, combining automated tools with manual testing. 
 
When selecting a SaaS penetration testing company, consider factors 

such as: 

 
 
  • Scope of testing: Does the company offer testing for web applications, mobile apps, APIs, cloud infrastructure, etc.?
  • Testing methodology: Do they offer automated scanning, manual penetration testing, or both?
  • Integration capabilities: Can their platform integrate with your existing security tools and workflows?
  • Reporting and remediation: Do they provide clear, actionable reports and guidance on how to fix vulnerabilities?
  • Compliance requirements: Do they have experience with relevant compliance standards for your industry (e.g., PCI DSS, HIPAA, SOC 2)?
  • Pricing and scalability: Does the pricing model fit your budget and can they scale with your needs?

Regards

 

Caute_Cautim

karishmaqualyse
Newcomer II