White-box pentest
We read your code,
then break in.
Give us your repo. We map every route, check, and data path, then attack your live app knowing exactly where the deep bugs hide.
Free to set up. Pay only when you run.
What it catches
What only
the code reveals.
The deep bugs a black-box test and scanners walk past:
- An access check missing on one of forty routes.
- Business logic you can abuse across several steps.
- Data that leaks between customers, deep in the code.
- Secrets and trust boundaries an outsider can't see.
Code-aware
It reads every line,
then traces the flaw.
It reads your whole repo, then traces each deep bug to the exact line and data path, and proves it. Coverage a black-box attack can't reach.
A HackZero white-box pentest reading a sample repository. It maps the whole codebase (2,000 files across TypeScript, Python, Go, and SQL; 18,402 functions, 312 entry points), surfacing every attack vector and result.
What you get
Proof,
down to the line.
Every bug is a real attack we ran. And because we read the code, we point to the exact spot. It lands in your tracker with:
- 01 The exact request that triggered it.
- 02 A screen recording of the exploit.
- 03 The file and line to change, with the diff.
One real example: a single route missing its login check, deep in your auth handler. We show you which line.
See a sample report
Frequently asked
Questions.
A repo and a URL. We read the code, then attack the running app.
We read it during the run, with read-only access by default, and we never change it unless you turn that on. Full details are in our privacy policy.
Black-box attacks from the outside with just a URL. White-box reads your code first, so it finds the deep bugs an outsider would never reach. Same engine, same credits.
Each one comes with the exact request that triggers it. Run it yourself. If it does not reproduce, it is not a finding.
From $2,999/mo, or $299/mo for teams of 10 or fewer. The rest is on the pricing page.