White-box pentest

We read your code,
then break in.

Give us your repo. We map every route, check, and data path, then attack your live app knowing exactly where the deep bugs hide.

Start a pentest

Free to set up. Pay only when you run.

A bold ink fingerprint pressed onto cream paper, dissolving into long streaks. Reading the unique structure of your code.

What it catches

What only
the code reveals.

The deep bugs a black-box test and scanners walk past:

  • An access check missing on one of forty routes.
  • Business logic you can abuse across several steps.
  • Data that leaks between customers, deep in the code.
  • Secrets and trust boundaries an outsider can't see.
A lone figure descending a vast brutalist spiral, dissolving into ink. Going deep, level by level.

Code-aware

It reads every line,
then traces the flaw.

It reads your whole repo, then traces each deep bug to the exact line and data path, and proves it. Coverage a black-box attack can't reach.

A HackZero white-box pentest reading a sample repository. It maps the whole codebase (2,000 files across TypeScript, Python, Go, and SQL; 18,402 functions, 312 entry points), surfacing every attack vector and result.

What you get

Proof,
down to the line.

Every bug is a real attack we ran. And because we read the code, we point to the exact spot. It lands in your tracker with:

  • 01 The exact request that triggered it.
  • 02 A screen recording of the exploit.
  • 03 The file and line to change, with the diff.

One real example: a single route missing its login check, deep in your auth handler. We show you which line.

See a sample report
A top-down concrete labyrinth with a lone lit figure tracing one path. The exact route to the flaw.

Frequently asked

Questions.

A repo and a URL. We read the code, then attack the running app.

We read it during the run, with read-only access by default, and we never change it unless you turn that on. Full details are in our privacy policy.

Black-box attacks from the outside with just a URL. White-box reads your code first, so it finds the deep bugs an outsider would never reach. Same engine, same credits.

Each one comes with the exact request that triggers it. Run it yourself. If it does not reproduce, it is not a finding.

From $2,999/mo, or $299/mo for teams of 10 or fewer. The rest is on the pricing page.