---
description: Discover the best Penetration Testing in New Zealand. Compare top Penetration Testing tools with customer reviews, pricing and free demos.
image: https://gdm-localsites-assets-gfprod.imgix.net/images/software_advice/og_logo-55146305bbe7b450bea05c18e9be9c9a.png
title: Best Penetration Testing in New Zealand - 2026 Reviews, Pricing & Demos
---

Breadcrumb: [Home](/) > [Penetration Testing](https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software)

# Penetration Testing

Canonical: https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software

Page: 1 / 2\
Next: [Next page](https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software?page=2)

-----

## Products

1. [Beagle Security](https://www.softwareadvice.co.nz/software/213304/beagle-security) — 4.9/5 (51 reviews) — Discover website security issues at the right time and address them in the right way using Beagle Security. With the ...
2. [Keepnet Labs](https://www.softwareadvice.co.nz/software/380477/keepnet-labs) — 5.0/5 (46 reviews) — Keepnet's Extended Human Risk Management (xHRM) platform is a comprehensive cybersecurity solution designed to addres...
3. [Invicti Web + API (formerly Acunetix)](https://www.softwareadvice.co.nz/software/77622/acunetix) — 4.4/5 (35 reviews) — Acunetix is a cloud-based digital security solution that assist security analysts with data protection, manual testin...
4. [Invicti](https://www.softwareadvice.co.nz/software/174628/netsparker-security-scanner) — 4.7/5 (26 reviews) — Invicti is an application security platform designed to identify, validate and prioritize vulnerabilities in web appl...
5. [Red Sentry](https://www.softwareadvice.co.nz/software/334574/red-sentry) — 4.8/5 (23 reviews) — Red Sentry provides penetration testing services designed for organizations that want clear, practical insight into t...
6. [Hackrate](https://www.softwareadvice.co.nz/software/329884/hackrate-bug-bounty-platform) — 5.0/5 (21 reviews) — Hackrate Bug Bounty platform helps organizations to identify software vulnerabilities in a cost-efficient way. A bug ...
7. [HackerOne](https://www.softwareadvice.co.nz/software/363397/hackerone) — 4.6/5 (12 reviews) — HackerOne is a hacker-powered cybersecurity platform that enables organizations within the government and financial s...
8. [Astra Pentest](https://www.softwareadvice.co.nz/software/362981/astra-pentest) — 4.8/5 (12 reviews) — Astra is a leading penetration testing company that provides PTaaS and continuous threat exposure management. Our com...
9. [Aikido Security](https://www.softwareadvice.co.nz/software/433685/aikido) — 4.7/5 (6 reviews) — Aikido Security is a unified application security platform that serves solo developers, startups, mid-market companie...
10. [Intigriti](https://www.softwareadvice.co.nz/software/250089/intigriti) — 4.6/5 (5 reviews) — Intigriti is the trusted leader in crowdsourced security, empowering the world’s largest organizations to find and fi...
11. [Xora](https://www.softwareadvice.co.nz/software/564582/Xora) — 4.8/5 (4 reviews) — Xora is an autonomous pentesting tool that doesn't just scan for vulnerabilities, it answers the question that matter...
12. [Detectify](https://www.softwareadvice.co.nz/software/231004/detectify) — 4.7/5 (3 reviews) — Detectify is a vulnerability management software designed to help security teams and developers automate asset monito...
13. [StealthNet AI](https://www.softwareadvice.co.nz/software/537912/StealthNet-AI) — 5.0/5 (3 reviews) — StealthNet AI is a penetration testing platform designed to deliver security assessments within a short timeframe. It...
14. [Pentera](https://www.softwareadvice.co.nz/software/263028/pentera) — 5.0/5 (2 reviews) — The Pentera automated penetration testing platform uses an algorithm to scan and ethically attack networks, providing...
15. [Pentest-Tools.com](https://www.softwareadvice.co.nz/software/490295/Pentest-Tools-com) — 4.5/5 (2 reviews) — Pentest-Tools.com helps security professionals find, validate, and communicate vulnerabilities faster and with greate...
16. [ZeroThreat](https://www.softwareadvice.co.nz/software/519479/ZeroThreat) — 4.0/5 (2 reviews) — ZeroThreat is an AI-powered web application and API security testing platform built to help teams identify and valida...
17. [WebMaxy Analyzer](https://www.softwareadvice.co.nz/software/373043/webmaxy-analyzer) — 5.0/5 (1 reviews) — Webmaxy Analyzer provides real-time user insights, heatmaps, surveys and polls, funnel view and form analytics. Get a...
18. [Defendify](https://www.softwareadvice.co.nz/software/244161/defendify) — 5.0/5 (1 reviews) — Defendify is a cybersecurity solution that protects businesses from online threats. It caters to small and midsize co...
19. [Reflectiz](https://www.softwareadvice.co.nz/software/192754/reflectiz) (0 reviews) — Take control of your website security with Reflectiz. Our proprietary website security sandbox creates a complete dig...
20. [Ostorlab](https://www.softwareadvice.co.nz/software/356914/ostorlab) (0 reviews) — Ostorlab is a platform that discovers and scans mobile applications, web applications, and external attack surfaces t...
21. [Strobes PTaaS](https://www.softwareadvice.co.nz/software/432627/strobes-ptaas) (0 reviews) — The effectiveness of a SaaS delivery platform and the human knowledge of pentesting are combined in Strobes PTaaS to ...
22. [Core Impact](https://www.softwareadvice.co.nz/software/388261/core-impact) (0 reviews) — Fortra's Core Impact is a powerful penetration testing tool that not only saves time through centralization and stand...
23. [Veracode Application Security Platform](https://www.softwareadvice.co.nz/software/267250/enablon-air-compliance-management) (0 reviews) — Veracode Application Security Platform is an application security solution that helps enterprise organizations in tec...
24. [Cyver Core](https://www.softwareadvice.co.nz/software/191308/cyver) (0 reviews) — Cyver is a cloud-based pentest management platform enabling businesses to deliver cybersecurity through client and vu...
25. [YesWeHack](https://www.softwareadvice.co.nz/software/508030/Bug-Bounty) (0 reviews) — YesWeHack is a leading Offensive Security and Exposure Management platform. It provides a comprehensive suite of inte...

-----

Page: 1 / 2\
Next: [Next page](https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software?page=2)

## Related Categories

- [Threat Intelligence Platforms](https://www.softwareadvice.co.nz/directory/3995/threat-intelligence/software)
- [Vulnerability Scanner Tools](https://www.softwareadvice.co.nz/directory/4415/vulnerability-scanner/software)
- [Security Awareness Training Programs](https://www.softwareadvice.co.nz/directory/4454/security-awareness-training/software)
- [Website Security Solutions](https://www.softwareadvice.co.nz/directory/4431/website-security/software)
- [Governance, Risk and Compliance (GRC)](https://www.softwareadvice.co.nz/directory/3843/grc/software)

## Links

- [View on SoftwareAdvice](https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software)
- [All Categories](https://www.softwareadvice.co.nz/directory)

## This page is available in the following languages

| Locale | URL |
| de | <https://www.softwareadvice.de/directory/4745/penetration-testing-software/software> |
| en | <https://www.softwareadvice.com/category/4745-penetration-testing/> |
| en-AU | <https://www.softwareadvice.com.au/directory/4745/penetration-testing-software/software> |
| en-GB | <https://www.softwareadvice.co.uk/directory/4745/penetration-testing-software/software> |
| en-IE | <https://www.softwareadvice.ie/directory/4745/penetration-testing-software/software> |
| en-NZ | <https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software> |
| fr | <https://www.softwareadvice.fr/directory/4745/penetration-testing-software/software> |

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":null,"address":{"@type":"PostalAddress","addressLocality":null,"addressRegion":null,"postalCode":null,"streetAddress":null},"description":"Software Advice helps businesses in New Zealand find the best software. Compare software options and learn more from our research and user reviews.","email":"info@softwareadvice.co.nz","url":"https://www.softwareadvice.co.nz/","logo":"https://dm-localsites-assets-prod.imgix.net/images/software_advice/logo-white-d2cfd05bdd863947d19a4d1b9567dde8.svg","@id":"https://www.softwareadvice.co.nz/#organization","@type":"Organization","parentOrganization":"G2.com, Inc.","sameAs":[]},{"name":null,"url":"https://www.softwareadvice.co.nz/","@id":"https://www.softwareadvice.co.nz/#website","@type":"WebSite","publisher":{"@id":"https://www.softwareadvice.co.nz/#organization"},"potentialAction":{"query":"required","target":"https://www.softwareadvice.co.nz/search/?q={search_term_string}","@type":"SearchAction","query-input":"required name=search_term_string"}},{"name":"Penetration Testing","description":"Discover the best Penetration Testing in New Zealand. Compare top Penetration Testing tools with customer reviews, pricing and free demos.","url":"https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software","about":{"@id":"https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software#itemlist"},"breadcrumb":{"@id":"https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software#breadcrumblist"},"@id":"https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software#webpage","@type":["WebPage","CollectionPage"],"isPartOf":{"@id":"https://www.softwareadvice.co.nz/#website"},"inLanguage":"en-NZ","publisher":{"@id":"https://www.softwareadvice.co.nz/#organization"},"mainEntity":{"@id":"https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software#itemlist"}},{"@id":"https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software#breadcrumblist","@type":"BreadcrumbList","itemListElement":[{"name":"Home","position":1,"item":"/","@type":"ListItem"},{"name":"Penetration Testing","position":2,"item":"https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software","@type":"ListItem"}]}]}
</script><script type="application/ld+json">
  {"name":"Best Penetration Testing in New Zealand - 2026 Reviews, Pricing &amp; Demos","@context":"https://schema.org","@id":"https://www.softwareadvice.co.nz/directory/4745/penetration-testing-software/software#itemlist","@type":"ItemList","itemListElement":[{"name":"Beagle Security","position":1,"description":"Discover website security issues at the right time and address them in the right way using Beagle Security.\n\nWith the ability to automate vulnerability assessment and accelerate remediation, you can secure your web applications from the latest cyber threats easily. Security tests can be scheduled on a recurring basis to have vulnerability assessments on an ongoing basis and keep track of website security. \n\nThe DevSecOps CI plugins allow one to automate regular vulnerability assessment in the CI/CD pipeline to get real-time updates of an application's security on Slack, Jira, Asana, or Trello right during the development phase.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/d64bd889-0939-4439-8b97-c160f6f51aa8.png","url":"https://www.softwareadvice.co.nz/software/213304/beagle-security","@type":"ListItem"},{"name":"Keepnet Labs","position":2,"description":"Keepnet's Extended Human Risk Management (xHRM) platform is a comprehensive cybersecurity solution designed to address the human element in organizational security. Recognizing that human error accounts for a significant portion of security breaches, Keepnet integrates advanced technologies to foster a security-conscious culture and mitigate risks associated with employee behaviors. AI-Driven Phishing Simulations.\n\nThe platform offers a suite of AI-powered phishing simulators that replicate various social engineering attacks, including:\n\n- Email Phishing: Crafts realistic email scenarios to test and educate employees on identifying malicious emails.\n\n- Smishing (SMS Phishing): Simulates deceptive text messages to train users in recognizing fraudulent communications.\n\n- Vishing (Voice Phishing): Utilizes interactive voice call scenarios to help employees detect and respond to voice-based scams.\n\n- Quishing (QR Code Phishing): Generates scenarios involving malicious QR codes to educate users on the potential risks of scanning unknown codes.\n\n- Callback Phishing: Assesses and educates employees on handling deceptive callback requests that could lead to security breaches.\n\nThese phishing simulations are dynamically adjusted based on individual performance, ensuring personalized and effective training that enhances employees' ability to recognize and thwart sophisticated phishing attempts.\n\nAdaptive Security Awareness Training\n\nBeyond simulations, Keepnet provides adaptive security training tailored to individual risk levels, roles, and cognitive behaviors. This personalized approach ensures that training content is relevant and engaging, promoting lasting behavioral change. By focusing on measurable behavior change over compliance-based training, organizations have reported up to a 90% reduction in high-risk security behaviors. \n\nAutomated Phishing Analysis and Response\n\nKeepnet empowers employees to report suspicious activities through user-friendly tools, facilitating immediate threat identification. The platform's AI-driven analysis and automated response capabilities enable security operations centers (SOCs) to handle reported phishing emails efficiently. For instance, Vodafone's SOC team experienced a 168-fold increase in response speed, automating the handling of reported phishing emails and reducing analysis time by 95%. \n\nUnified Platform for Comprehensive Protection\n\nIn 2024 where 84% of organizations focus on employee behavior to detect and prevent security incidents, Keepnet's xHRM platform stands out by integrating multiple security functions into a single, cohesive system. This unification simplifies security management, reduces complexity, and enhances efficiency. Features such as autopilot and self-driving capabilities in automated phishing simulations and security awareness training have been shown to reduce operational time by up to 95%, allowing security teams to focus on strategic initiatives. \n\nSuccess Stories\n\nOrganizations across various sectors have leveraged Keepnet's platform to strengthen their cybersecurity posture. For example, Pegasus Airlines prioritized measurable behavior change over compliance-based training, resulting in a significant reduction in phishing risk and the cultivation of a robust security culture. \n\n\nKeepnet's Extended Human Risk Management platform offers a holistic approach to cybersecurity by addressing the often-overlooked human factor. Through AI-driven simulations, adaptive training, and automated response mechanisms, it empowers organizations to build resilient security cultures, effectively mitigating employee-driven threats, insider risks, and social engineering attacks.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/95ea39e4-b65c-4ad7-8187-cbc99534d44f.jpeg","url":"https://www.softwareadvice.co.nz/software/380477/keepnet-labs","@type":"ListItem"},{"name":"Invicti Web + API (formerly Acunetix)","position":3,"description":"Acunetix is a cloud-based digital security solution that assist security analysts with data protection, manual testing and compliance reporting. It is primarily designed to scan websites and identify vulnerabilities that can compromise networks.\n\nKey features include site crawling, analysis, threat detection, SQL injection testing, network scanning and testing. Its vulnerability scanner crawls through open-source software and custom-built applications using black box and grey box techniques. With its network security module, users can test routers, firewalls and switches and detect misconfigurations.\n\nAcunetix comes with an application programming interface (API) that enables firms to integrate it with their workflows and processes. It if offered on a one-time subscription basis and support is provided via phone and email.","image":"https://images.g2crowd.com/uploads/product/image/6a3238e4d612493df71f3d4551d4b90b/invicti-web-api-formerly-acunetix.png","url":"https://www.softwareadvice.co.nz/software/77622/acunetix","@type":"ListItem"},{"name":"Invicti","position":4,"description":"Invicti is an application security platform designed to identify, validate and prioritize vulnerabilities in web applications and APIs. It incorporates Application Security Posture Management capabilities to support security operations across large application portfolios. The platform is used by organizations in sectors such as government, IT, telecommunications, financial services and healthcare to help maintain compliance standards and manage security at scale.\n\nThe platform includes Dynamic Application Security Testing, Static Application Security Testing, Software Composition Analysis, container security scanning and API security testing. Its scanning engine validates detected vulnerabilities to confirm they are exploitable. It identifies websites, applications, APIs and hidden assets within an organization and prioritizes high-risk applications for testing. The Application Security Posture Management feature consolidates findings from various security tools, providing a centralized view for vulnerability management and risk assessment.\n\nInvicti offers AI-powered remediation guidance, identifying the exact code locations of vulnerabilities and providing detailed resolution steps for developers. It supports integration with various development and security tools through a REST API and is compatible with CI/CD pipelines and DevOps workflows. The platform includes flexible deployment options and role-based access control to manage security across extensive application environments while maintaining accuracy and performance.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/d386ac3d-34c6-4fa7-a326-728dc8167276.png","url":"https://www.softwareadvice.co.nz/software/174628/netsparker-security-scanner","@type":"ListItem"},{"name":"Red Sentry","position":5,"description":"Red Sentry provides penetration testing services designed for organizations that want clear, practical insight into their security posture. Instead of relying solely on automated tools, Red Sentry uses experienced ethical hackers to simulate real-world attacks and determine whether vulnerabilities can actually be exploited.\n\nThis approach helps teams move beyond long lists of scanner findings and focus on issues that pose meaningful risk to the business. Testing can be performed across applications, APIs, cloud infrastructure, and networks, with results documented in structured reports that explain impact, severity, and recommended next steps.\n\nRed Sentry is commonly used by security, IT, and compliance teams that need defensible testing results to support internal decision-making, customer assurance, and regulatory requirements such as SOC 2 or ISO 27001.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/394d0ea1-a32b-4c88-b6f6-14d618fdffab.png","url":"https://www.softwareadvice.co.nz/software/334574/red-sentry","@type":"ListItem"},{"name":"Hackrate","position":6,"description":"Hackrate Bug Bounty platform helps organizations to identify software vulnerabilities in a cost-efficient way.\n\nA bug bounty is about utilizing the power of crowdsourced security to secure businesses. During a bug bounty program, an organization offers rewards to ethical hackers for reporting vulnerabilities.\n\nCybersecurity threats are evolving, and malicious hackers don’t follow\na predefined security methodology. These risks impact your company’s growth. So how can you protect confidential information? How can you avoid your website being hacked? This next-generation security testing can help you to prevent potential data breaches and reduce cybersecurity risks.\n\n\nThis global community of ethical hackers is a guarantee against software bugs.\nThe bug bounty program helps businesses build trust with all of their stakeholders.\nWith incentivized security testing, teams can optimize their costs on cybersecurity.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/ed22b2cf-56b6-4703-bfd3-8678cf718471.png","url":"https://www.softwareadvice.co.nz/software/329884/hackrate-bug-bounty-platform","@type":"ListItem"},{"name":"HackerOne","position":7,"description":"HackerOne is a hacker-powered cybersecurity platform that enables organizations within the government and financial service industries to identify, capture, and resolve security vulnerabilities that were discovered by hackers. HackerOne is designed to help users receive and monitor vulnerabilities through secure channels, conduct continuous vulnerability testing for specific features or in-house apps, and implement security assessments to ensure products meet security compliance requirements for secure product launches. HackerOne also provides advisory and triage services that help teams launch and scale security programs, validate vulnerabilities, and develop remediation plans.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/048fef9b-484d-42b7-9d56-60f5d0a5e097.png","url":"https://www.softwareadvice.co.nz/software/363397/hackerone","@type":"ListItem"},{"name":"Astra Pentest","position":8,"description":"Astra is a leading penetration testing company that provides PTaaS and continuous threat exposure management. Our comprehensive cybersecurity solutions blend automation and manual expertise to run 15,000+ tests and compliance checks, ensuring complete safety regardless of the threat or attack location.\n\nWith a 360° view of an organization’s security posture, proactive, continuously delivered insights, real-time reporting, and AI-first defensive strategies, we aim to help CTOs shift left at scale through continuous pentests. The offensive scanner engine, seamless tech stack integrations, and expert support help make pentesting simple, effective, and hassle-free for 1000+ businesses worldwide.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/2d2e4f85-ddef-4533-87d5-af3eba481207.png","url":"https://www.softwareadvice.co.nz/software/362981/astra-pentest","@type":"ListItem"},{"name":"Aikido Security","position":9,"description":"Aikido Security is a unified application security platform that serves solo developers, startups, mid-market companies, and large enterprises across industries including SaaS, fintech, health tech, legal tech, and smart manufacturing. It is deployed as a cloud-based SaaS platform, with an on-premises local scanner option available for teams that need source code to remain off external servers.\n\nThe platform consolidates code scanning, cloud security, container scanning, secrets detection, and runtime protection into one system. Core features include static application security testing (SAST), software composition analysis (SCA), infrastructure-as-code scanning, dynamic application security testing (DAST), cloud security posture management (CSPM), and AI-powered penetration testing. An AutoFix feature generates pull requests to help developers resolve issues without manual research. Reachability analysis filters out false positives by determining whether a vulnerable code path is actually exploitable. Compliance automation covers SOC 2 Type II, ISO 27001:2022, CIS, and NIS2 controls.\n\nAikido Security integrates with GitHub, GitLab, Bitbucket, Azure DevOps, Jira, and Slack. Support is available through a knowledge base and direct support channels.","image":"https://images.g2crowd.com/uploads/product/image/94d889d0ae592ea0ec1ff00c075582b1/aikido-security.png","url":"https://www.softwareadvice.co.nz/software/433685/aikido","@type":"ListItem"},{"name":"Intigriti","position":10,"description":"Intigriti is the trusted leader in crowdsourced security, empowering the world’s largest organizations to find and fix vulnerabilities before cybercriminals can exploit them. \n\nSince 2016, the company has helped its customers reduce risk with the expertise of 125,000+ global security researchers, enabling real-time vulnerability detection and preventing costly breaches.\n\nIntigriti's flexible platform offers a full suite of solutions, including Bug Bounty, Managed VDP, PTaaS, Focused Sprints, and Live Hacking Events, tailored to your evolving digital needs and delivered through a pay-for-impact model,  meaning you only pay for valid vulnerabilities submitted.\n\nWith industry-leading triage, commitment to legal compliance, and exceptional customer service, Intigriti is the go-to choice for organizations like, Nvidia, Coca-Cola, Microsoft, and Intel to secure their digital assets and stay ahead in a changing world.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/92173af5-2690-437e-a624-4c08a1314500.png","url":"https://www.softwareadvice.co.nz/software/250089/intigriti","@type":"ListItem"},{"name":"Xora","position":11,"description":"Xora is an autonomous pentesting tool that doesn't just scan for vulnerabilities, it answers the question that matters: \"which ones are actually exploitable\". \n\nActing like a \"red-team in a box\" Xora's agents scan at the source code level, and catches security issues prior to deploy. \n\nTraditional penetration tests have always been limited in scope, lacked unique business context, and resulted in disagreement about what really needed to be fixed. Additionally legacy SAST tools flagged everything, which resulted in fixing nothing.\n\nXora is the solution. Invest in frontier application security for a new era of threats.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/fc101e42-542c-4952-ab60-be1781a17055.jpeg","url":"https://www.softwareadvice.co.nz/software/564582/Xora","@type":"ListItem"},{"name":"Detectify","position":12,"description":"Detectify is a vulnerability management software designed to help security teams and developers automate asset monitoring processes to secure web applications. Businesses can scan crawled URLs to identify security threats and manage remediation processes in a centralized dashboard.\n\n\nThe platform allows administrators to detect issues including server-side request forgery, SQL injections, directory traversal attack, DNS misconfigurations and cross-site scripting across web applications. Detectify lets managers login across applications using single sign-on and secure accounts through two-factor authentication or role-based configurations. Additionally, it enables developers to protect confidential data across internal or in-house applications and page responses including passwords from being exposed.\n\n\nDetectify offers an application programming interface (API), which lets businesses integrate the system with several third-party applications including JIRA, Slack, Splunk, Zapier, PagerDuty and Trello. Pricing is based on monthly and annual subscriptions and support is extended via FAQs, phone, knowledgebase, email and live chat.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/7f9a350c-9c53-4fa9-918f-9e8022f9eb54.png","url":"https://www.softwareadvice.co.nz/software/231004/detectify","@type":"ListItem"},{"name":"StealthNet AI","position":13,"description":"StealthNet AI is a penetration testing platform designed to deliver security assessments within a short timeframe. It combines autonomous AI agents with experienced ethical hackers to provide audit-ready results. The platform supports organizations in regulated industries such as SaaS, FinTech, healthcare, e-commerce, AI, and government contracting. It aligns with compliance frameworks including SOC 2, PCI DSS, HIPAA, ISO 27001, CMMC, FedRAMP, and FDA standards.\n\nThe platform uses a hybrid testing model where AI agents conduct continuous vulnerability discovery and exploitation. Senior penetration testers validate findings and perform advanced assessments. The AI agents autonomously handle tasks such as reconnaissance, scanning, and initial exploitation across various environments, including web applications, APIs, networks, cloud infrastructure, AI systems, hardware, IoT devices, WiFi networks, mobile applications, and source code. This approach aims to deliver context-aware results with minimal false positives. The testing methodology addresses a wide range of vulnerabilities, including OWASP Top 10 issues, business logic flaws, authentication bypasses, and privilege escalation paths.\n\nStealthNet AI provides multiple delivery models to address different security needs. The autonomous model focuses on AI-only testing for continuous coverage. The hybrid model combines AI agents with certified penetration testers who hold credentials such as OSCP, OSWE, OSEP, CISSP, and GPEN. The traditional model offers fully manual testing for sensitive environments. Each engagement includes a remediation retest to confirm that vulnerabilities have been resolved. Reports are structured to meet auditing standards and include executive summaries, severity scoring, and prioritized remediation details.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/21f35a68-b113-40a0-9aeb-47f2b90e797d.jpg","url":"https://www.softwareadvice.co.nz/software/537912/StealthNet-AI","@type":"ListItem"},{"name":"Pentera","position":14,"description":"The Pentera automated penetration testing platform uses an algorithm to scan and ethically attack networks, providing real-time penetration tests at scale. Pentera safely performs the actions that a malicious adversary would — reconnaissance, sniffing, spoofing, cracking, (harmless) malware injection, file-less exploitation, post-exploitation, lateral movement and privilege escalation — all the way to data exfiltration. Without requiring agents or pre-installations, the platform gives security teams a complete attack operation view providing a true assessment of their resiliency against real attacks, and prioritizes remediation efforts with a threat-facing perspective. Pentera also applies the latest hacking techniques, including ransomware strains, enabling organizations to focus their resources on remediation of the vulnerabilities that take part in a damaging “kill-chain”. \n\nWith Pentera, a company can continuously reduce cyber exposure and maintain the highest possible resilience posture by performing validation tests as regularly as needed - either daily, weekly, or monthly. This gives the organization a better grasp not only on security gaps, but also allows them to test the efficiency of their security stack and maintain consistency across the entire organization.\n\nPentera does this by providing an automated security validation platform that gives organizations the remediation roadmap they need to confidently reduce cybersecurity exposure.","url":"https://www.softwareadvice.co.nz/software/263028/pentera","@type":"ListItem"},{"name":"Pentest-Tools.com","position":15,"description":"Pentest-Tools.com helps security professionals find, validate, and communicate vulnerabilities faster and with greater confidence - whether they’re internal teams defending at scale, MSPs juggling clients, or consultants under pressure.\n\nWith comprehensive coverage across network, web, API, and cloud assets, and built-in exploit validation, it turns every scan into credible, actionable insight.\n\nTrusted by over 2,000 teams in 119 countries and used in more than 6 million scans annually, it delivers speed, clarity, and control - without bloated stacks or rigid workflows.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/2bc70b88-f8bd-4078-9ac5-6b4715a624a0.png","url":"https://www.softwareadvice.co.nz/software/490295/Pentest-Tools-com","@type":"ListItem"},{"name":"ZeroThreat","position":16,"description":"ZeroThreat is an AI-powered web application and API security testing platform built to help teams identify and validate real, exploitable vulnerabilities, FAST.\n\nZeroThreat redefines application security testing by combining Agentic AI pentesting with a high-performance scanning engine to deliver fast, accurate, and actionable results. It continuously analyzes emerging threats and newly disclosed CVEs, mapping them to detection logic in near real time, so your applications are always protected against the latest vulnerabilities.\n\nThe platform executes dynamic, attacker-like workflows that adapt to application behavior, enabling it to uncover complex issues such as authentication bypass, business logic flaws, and multi-step workflow abuse, areas where traditional DAST tools typically fall short.\n\nWith native Nuclei template execution and over 100,000 vulnerability checks, ZeroThreat provides broad coverage across modern web and API attack surfaces. Every finding is validated through live exploit execution, ensuring only real vulnerabilities are reported, complete with proof of impact and exposed data, eliminating false positives.\n\nZeroThreat is built for modern applications, including SPAs and JavaScript-heavy environments, with advanced browser automation that supports authenticated testing and complex user flows. It integrates seamlessly into the SDLC, enabling continuous, production-safe security testing without manual overhead.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/420ad3d9-2f7a-4c40-83fe-ce0986bd2373.jpeg","url":"https://www.softwareadvice.co.nz/software/519479/ZeroThreat","@type":"ListItem"},{"name":"WebMaxy Analyzer","position":17,"description":"Webmaxy Analyzer provides real-time user insights, heatmaps, surveys and polls, funnel view and form analytics. Get access to your users’ journey videos and know the features that appeal the most to your customers. By knowing your visitors, you can enhance their website experience and boost conversion rates. \n\nWebMaxy analyzer is used by digital marketers, owners, product marketers and other decision-makers to make informed decisions. It is simple to use, powerful and easily integrates with your present tech sack. It helps you find the missing dots in analyzing user behavior. \n\nGet qualitative data that improve your web app and website by understanding how your users interact with your website and where they click through heatmaps, you can position your CTAs accordingly. Webmaxy analyzer can help you make data-driven and informed decisions. With Webmaxy Analyzer, you can know and understand your visitors, enhance their website experience and boost conversion rates. \n\nTop Features of WebMaxy Analyzer - \n\nBehavior Analytics  - \nBehavior analytics helps you identify anomalies or issues that might be causing the users to get stuck or frustrated. Resolving these can promptly improve customer experience and, added bonus, bring down your website’s churn rate.\n\nSession Replay\nSession replay is essentially the process of seeing through the user’s eyes. It’s a walkthrough presentation that reconstructs the user’s journey. You can watch every click, scroll and mouse movement that happens during a session. \n\nHeatmap\nHeatmap is a website analysis technique that allows you to visualize user data as a graph, with values depicted by colors. Variations in the color’s intensity are indicative of the changes in the corresponding value. \n\nForm Analyzer \nAnalyze the funnel more gradually with accurate data and desired view. Get started with the WebMaxy Funnel today.\n\nUser Insights \nConnect the missing dots to build a future-proof strategy with WebMaxy user insights.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/2101b715-2f3c-40cf-9755-763e436cd3ad.jpeg","url":"https://www.softwareadvice.co.nz/software/373043/webmaxy-analyzer","@type":"ListItem"},{"name":"Defendify","position":18,"description":"Defendify is a cybersecurity solution that protects businesses from online threats. It caters to small and midsize companies and organizations without security teams, including IT and technology providers across all industries.\n\nDefendify offers an integrated suite of cybersecurity tools for prevention, detection, and response. It uses artificial intelligence (AI) to help users detect anomalies and stop attacks in real time. The platform enables businesses to set security policies, conduct phishing simulations and vulnerability scans, and get support from cybersecurity experts. Additionally, Defendify allows organizations to automate cybersecurity assessments, testing, policies, training, detection, and response through a unified platform. \n\nDefendify is cloud-based for easy deployment and maintenance. It provides ongoing software updates to defend against the latest cyber threats. Businesses get dedicated support from Defendify's cybersecurity specialists who monitor networks, investigate alerts, and contain incidents when they occur.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/a2f9a2cc-ba88-49cb-869a-64515ab96424.png","url":"https://www.softwareadvice.co.nz/software/244161/defendify","@type":"ListItem"},{"name":"Reflectiz","position":19,"description":"Take control of your website security with Reflectiz. Our proprietary website security sandbox creates a complete digital application inventory in minutes — the first of its kind. This inventory displays all the external applications used on your website; third party and beyond. With immediate visibility into every single app, you can map and detect any risky or uncommon behaviours these apps perform. You can also see where your risks are coming from, including all internal or external domains, all of that, without adding a single line of code.\n\nSecurity teams can finally identify risks as they happen, with ongoing alerts and monitoring. Reflectiz scans thousands of assets globally, constantly keeping your team up-to-date on the latest threats. You can protect your website against supply-chain attacks, unplanned vendor configuration changes and any suspicious behavior.  \nYour business is always one step ahead of the next emerging threat.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/75d40a5a-4644-4ebe-8a0a-3a25beea49dd.png","url":"https://www.softwareadvice.co.nz/software/192754/reflectiz","@type":"ListItem"},{"name":"Ostorlab","position":20,"description":"Ostorlab is a platform that discovers and scans mobile applications, web applications, and external attack surfaces to identify vulnerabilities and security & privacy weaknesses.\n\n- Manage attack surfaces and discover assets.\n\n- Run scans on mobile applications, web applications & APIs, and networks, all on the same platform.\n\n- Follow code call traces, API calls, and traffic. Get into the attacker's shoes and see exactly what they would see.\n\n- Aggregate vulnerabilities into tickets, assign them to developers, set timelines, and let Ostorlab verify the fixes.\n\n- Effortlessly & automatically trigger a scan with every change, from a new application release to an API schema change.\n\n- Integrate Ostorlab to the existing CI/CD pipeline in Jenkins, Github, or GitLab, and make sure applications are secure before being shipped.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/c301a066-8007-4f5d-9c4c-f8393ad8c679.jpeg","url":"https://www.softwareadvice.co.nz/software/356914/ostorlab","@type":"ListItem"},{"name":"Strobes PTaaS","position":21,"description":"The effectiveness of a SaaS delivery platform and the human knowledge of pentesting are combined in Strobes PTaaS to enable real-time cooperation and quicker response.\n\nUsers can start pentest in 4 steps. Create assets with required details like URL, IP, business sensitivity etc. Provide Strobes PTaaS with the information like scope, VPN details, test accounts, and schedule the assessment for today or next month, and the platform will notify automatically. Finally, world class hackers will start the test in less than 48hrs from the scheduled date.\n\nBenefits of PTaaS are faster reporting, taxanomy mappings, integrate with Jira & Slack, World Class Hackers, etc.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/d6e99ee9-f4d1-47ce-80ef-2e74b376f523.png","url":"https://www.softwareadvice.co.nz/software/432627/strobes-ptaas","@type":"ListItem"},{"name":"Core Impact","position":22,"description":"Fortra's Core Impact is a powerful penetration testing tool that not only saves time through centralization and standardization, but also through its automation and ease of use. Those newer to pen testing benefit from the step-by-step Rapid Penetration Testing guided wizards, while those with experience can automate routine tasks and leverage the tool’s flexibility to execute more advanced testing tactics.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/ce37c9a2-770b-4b26-8760-5d5049ba2ef9.png","url":"https://www.softwareadvice.co.nz/software/388261/core-impact","@type":"ListItem"},{"name":"Veracode Application Security Platform","position":23,"description":"Veracode Application Security Platform is an application security solution that helps enterprise organizations in technology, finance, healthcare, and other industries find and fix security vulnerabilities in their software. The platform is deployed via the cloud, so no on-premises installation is required. Veracode Application Security Platform offers static analysis, dynamic analysis, software composition analysis, and penetration testing to scan code at multiple stages of development. Development and security teams can view scan results in a centralized dashboard, prioritize vulnerabilities by severity, and track remediation progress over time. Policy management tools let organizations define and enforce security standards across all applications. Support is available through email, phone, and an online knowledge base with documentation and training resources.","image":"https://images.g2crowd.com/uploads/product/image/8fef93b7d94c7b2bdd99f728d9df42ab/veracode-application-security-platform.png","url":"https://www.softwareadvice.co.nz/software/267250/enablon-air-compliance-management","@type":"ListItem"},{"name":"Cyver Core","position":24,"description":"Cyver is a cloud-based pentest management platform enabling businesses to deliver cybersecurity through client and vulnerability findings management, report automation and tool integration capabilities, Key features include compliance management, dashboard, team collaboration and real-time alerts.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/1e04e49d-eb65-4200-a154-ece733b30216.png","url":"https://www.softwareadvice.co.nz/software/191308/cyver","@type":"ListItem"},{"name":"YesWeHack","position":25,"description":"YesWeHack is a leading Offensive Security and Exposure Management platform. It provides a comprehensive suite of integrated, API-based solutions designed to secure organisations’ growing attack surfaces.\n\nThe YesWeHack platform comprises:\n- Bug Bounty: Crowdsourced vulnerability discovery leveraging a global community of 135,000+ skilled ethical hackers through a cost-efficient, platform-driven model.\n- Autonomous Pentest: Comprehensive asset discovery combined with ongoing exposure validation to secure your attack surface against the most exploited vulnerabilities.\n- Continuous Pentesting: Human-led security assessments that ensure 0 false positives and help support compliance at scale.\n- Vulnerability Management: Unified workflows to aggregate and manage findings from external sources.\n\nThis multi-layered approach to offensive security empowers organisations to deploy agile, continuous and exhaustive testing strategies across their entire digital footprint.\n\nAll YesWeHack solutions are built with a human-in-the-loop philosophy, ensuring that critical decisions remain firmly in human hands.\n\nTrusted by organisations worldwide, YesWeHack serves a diverse portfolio of industry leaders and public institutions, including Louis Vuitton, Ferrero, the European Commission, TeamViewer, Tencent, L’Oréal Groupe and GovTech Singapore.\n\nYesWeHack is ISO 27001- and ISO 27017-certified and CREST-accredited. Its EU-hosted infrastructure meets ISO 27001/27017/27018/27701 and SOC 2 Type II standards, with full GDPR compliance and financial traceability built in.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/56776635-052e-4264-ba5b-00436cc37836.png","url":"https://www.softwareadvice.co.nz/software/508030/Bug-Bounty","@type":"ListItem"}],"numberOfItems":25}
</script>
