Black-box pentest
Nothing but a URL,
we break in.
No code to share. We attack your live app from the outside, exactly like a real hacker, and prove what they can reach.
Free to set up. Pay only when you run.
What it catches
What an outsider
can break.
The bugs a stranger hits first, with no inside knowledge:
- Data you can reach without logging in.
- One account reading another's records.
- Inputs that let an attacker run their own commands.
- AI features talked into leaking secrets.
The attack
From a URL,
it breaks in.
No code, no logins. It attacks your live app from the outside, like a real hacker, and confirms every exploit with a request you can replay.
A HackZero black-box pentest that confirms three real exploitable vulnerabilities on a sample target: a critical IDOR causing tenant bleed, JWT signing-key reuse, and an SSRF. Each can be replayed to re-run the exploit and verify it is fixed.
Hit replay to re-run the exploit and check if you're safe
What you get
We don't flag it.
We prove it.
Every bug is a real attack we ran, not a guess. It lands in your tracker with three things:
- 01 The exact request that triggered it.
- 02 A screen recording of the exploit.
- 03 The diff that closes it.
One real example: it changed a single ID in a web address and read another customer's invoice. The exact request is attached.
See a sample report
Frequently asked
Questions.
No. Black-box needs only a URL. We never see your code. That is what makes it a true outsider's test, and the fastest way to start.
Minutes. Sign up, enter a URL, and go.
Each one comes with the exact request that triggers it. Run it yourself. If it does not reproduce, it is not a finding.
The deep bugs hidden in your code. For those, point it at your repo with white-box. Same engine, same credits.
From $2,999/mo, or $299/mo for teams of 10 or fewer. The rest is on the pricing page.