"Polished UI, Powerful ASM and AI Features, Smooth Performance"
The ASM feature helps us review all our assets effectively. The UI feels polished and smooth, and generating reports is straightforward. The AI features are a definite plus. Overall, the performance is consistently smooth and reliable. It could be improved by offering better integrations with other tools. I can view vulnerabilities from multiple tools all in one place, under a single umbrella. The risk-based prioritization is very helpful as well, especially for focusing on what matters most.
I
Information Security Engineer
"Unified VM, ASM & CTEM for DevSecOps Excellence"
Strobes provides a unified platform for vulnerability management that makes it easy to prioritize, track, and remediate issues across diverse environments. Its integrations with scanners and ticketing systems significantly streamline our DevSecOps workflows. I especially appreciate the rich automation capabilities and flexibility in defining risk policies, which help align vulnerability management with our organizational security objectives. The dashboards and correlation logic make it effortless to focus on high-impact vulnerabilities first. Beyond core vulnerability management, Strobes makes reporting very straightforward with clear, well-structured report templates that are easy to share with stakeholders. It also integrates smoothly with tools like CodeQL, Dependabot, Qualys, and CrowdStrike, helping aggregate code, infrastructure, and endpoint findings in one place. Its CTEM capabilities, including attack surface management, dark web monitoring, and continuous risk visualization, provide much better visibility into our overall security posture and help us proactively reduce exposure rather than reactively chasing alerts. Nothing significant to report here. Strobes delivers comprehensive functionality across vulnerability management, integrations, reporting, and visibility features without any major shortcomings that impact our workflows. The platform's automation and dashboard capabilities continue to exceed expectations for our DevSecOps needs. Occasional minor UI tweaks could enhance customization, but these are negligible compared to the overall value provided. Strobes solves key challenges in vulnerability management, such as alert overload, siloed data from multiple scanners, and lack of contextual prioritization, by aggregating findings from tools like CodeQL, Dependabot, Qualys, and CrowdStrike into a unified view with AI-driven risk scoring. It tackles fragmented visibility across code, infrastructure, and endpoints through its CTEM platform, attack surface management (ASM), dark web monitoring, and PTaaS (Penetration Testing as a Service), uncovering shadow IT, misconfigurations, and external exposures that traditional tools miss. Key Benefits: These capabilities deliver faster remediation (up to 10x via advanced filters and automation), reduced noise from false positives, and proactive risk mitigation aligned with business impact. For our DevSecOps pipelines across GCP environments, this means seamless CI/CD integration for early vulnerability detection, clear report templates for compliance audits, dashboard visualizations for holistic security posture insights, and on-demand penetration testing to validate fixes. Outstanding Support: Our Customer Success Executive Nikeeta Patil and Team Lead Avinash from the Strobes team provide prompt clarifications and hands-on assistance for any doubts, ensuring smooth adoption and maximizing platform value. Overall, Strobes shifts us from reactive firefighting to continuous threat exposure management, minimizing attack surfaces and enabling efficient focus on high-impact issues.
A
Associate Director - Cloud & App Security
"RBVM Platform That Genuinely Enhances Security"
The executive dashboard offers crystal-clear risk overviews with customizable widgets displaying CVSS trends, asset criticality, and remediation velocity across our GCP multi-project setup. Real-time Slack/Teams alerts and their 200+ integrations (including GCP Security Command Center) give our SecOps team instant visibility. Support is genuinely proactive—last week's critical alert was triaged in 32 minutes with a custom policy fix. Executive reporting templates could include more CISO-level KPIs like "Mean Time to Acknowledge" and board-friendly risk heat-maps. Custom PDF exports work but aren't as polished as competitors for stakeholder presentations. Strobes solves our biggest pain: siloed vulnerability data across 43+ GCP repos, Cloud SQL instances, and compute clusters. RBVM risk scoring replaced manual prioritisation, cutting critical vuln remediation from 45+ days to under 7 days. Custom org policies now auto-enforce across projects, and their CASM module caught 17 high-risk misconfigs last quarter that native GCP tools missed. Compliance audits dropped from 3 weeks to 2 days.
"Outstanding Vulnerability Detection with Actionable Insights"
Strobes assisted us in identifying vulnerabilities in our SDKs that we had missed. They considered all angles and edge cases where a security flaw could be introduced. The best part is that they even pinpoint the exact lines of code where the flaw resides, along with suggestions to fix them! I was pleasantly surprised by their willingness to go the extra mile. I can't think of many downsides. Perhaps a few vulnerabilities were assigned a higher risk score than they deserved, but it wasn't a major issue since the important thing is that they were discovered. Strobes helps us solve the problem of finding lesser-known or almost invisible security flaws that aren't detected in other lenient security audits. They think of edge cases that others overlook and also identify the problematic code causing the vulnerabilities. They have aided us in planning and implementing fixes and optimizations for the future.
"Efficient Vulnerability Management with an Easy-to-Use Interface"
What I like most about Strobes Security is how streamlined and organized the entire vulnerability management process becomes. The platform consolidates data from multiple scanners and tools, then prioritizes everything in a logical manner, so I don't waste time on low-impact issues. I also appreciate the clean interface—it's easy to navigate without being overwhelming. Their support team is responsive as well, making the overall experience reliable and smooth. Regarding dislikes, there's a slight learning curve at the beginning, especially when customizing workflows or integrations. Once you get familiar, it's smooth, but the initial setup could be more intuitive. I've also noticed that some advanced features load slowly when handling large datasets. Nothing major, but there's room for minor usability enhancements. Strobes helps address the challenge of managing vulnerabilities across multiple tools and environments. Instead of juggling different scanners and manually prioritizing issues, everything is consolidated into one place with clear, risk-based prioritization. This saves significant time and ensures we focus on what truly matters rather than getting lost in noise. It has also improved our remediation workflow—teams get better visibility, quicker turnaround, and fewer issues slip through the cracks.
M
Mid-Market (51-1000 emp.)
"Affordable VAPT Services with a Skilled Team"
I appreciate the excellent services provided by a knowledgeable team at Strobes Security for competitive prices. Their outstanding customer support is a standout feature. I chose Strobes because of its extensive test coverage at the lowest cost, and they satisfied our strict requirements for tester certifications, including OSCP and CPTS. I value the excellent findings and in-depth analysis from a competent team, which helps us significantly improve our security posture by identifying and closing gaps we were previously unaware of. The quality of service and analysis is commendable, making it easier for our organization to address issues and enhance security. They need to upgrade most of their VAPT workforce to industry-recognized certifications like OSCP and CPTS. I use Strobes Security for comprehensive VAPT services, which are essential for annual compliance. They provide in-depth analysis and discoveries at a low cost, helping us identify and fix unknown vulnerabilities, thereby improving our overall security.
"Focuses on Real Risks with Smooth DevSecOps Integration"
It doesn't merely dump vulnerability data—it prioritizes what genuinely matters based on risk and exploitability. The integration of SAST, DAST, and dependency issues into a single, actionable view saves substantial time for security and engineering teams. The UI is simple, onboarding is fast, and it blends well into actual DevSecOps workflows instead of imposing theoretical security processes. Overall, it emphasizes fixing problems efficiently, not just reporting them. What I dislike about Strobes Security is the lack of transparency and flexibility in reporting. The reports feel too static and high-level, making it harder to drill down into findings, monitor remediation progress, or customize views for different stakeholders. For a platform focused on actionable risk, the reporting should be more dynamic, offering better filtering, clearer severity breakdowns, trend analysis over time, and export formats that work for engineering, management, and compliance teams. The detection and prioritization are strong, but the reporting layer needs significant improvement to match the rest of the platform. Strobes solves the issue of fragmented application security data. In most environments, findings from SAST, DAST, dependency scanning, and other tools are dispersed across multiple platforms, making it difficult to see real risk or decide what to fix first. Strobes centralizes data from all these tools into a single dashboard, providing a unified view of vulnerabilities across our products. This eliminates duplicate findings, improves visibility, and helps us prioritize issues based on actual risk rather than raw volume. It enhances decision-making, accelerates remediation, and reduces time wasted switching between tools or reconciling inconsistent reports.
M
Manager - Information Security & Compliance
"Unified Security Visibility with Seamless API Integration"
Strobes has enabled us to achieve clear, centralized visibility into all our security issues in a single location, with a dashboard that functions effectively at the management level. What we appreciate most is how straightforward it is to integrate into our environment using its APIs. We can also create views based on custom filters and utilize that data for our own purposes. There's nothing specific I dislike about Strobes. However, we've observed that occasionally, some reported vulnerabilities aren't reflected on the portal despite being present in the system, which makes it challenging to track everything and ensure complete closure. Having a centralized solution where all vulnerabilities are consolidated in one place greatly assists in tracking and presenting our current security posture and trends from an application perspective. Since we have multiple group companies, managing vulnerabilities for each company across different locations would be extremely difficult. Strobes has helped us consolidate everything and monitor it from a single dashboard.
"Practical Security Assessments with Valuable Findings"
What stood out to me about Strobes Security was their team's ability to go beyond automated scanner results and identify meaningful business-logic vulnerabilities. Many of their findings were practical and realistic from an attacker's viewpoint, which made the assessment significantly more useful. I also appreciated that the reports were thorough and easy to leverage during remediation discussions, simplifying alignment on fixes and next steps. There's nothing major to complain about honestly—the only minor issue was that the platform/UI was a bit complex initially and required some time to become familiar with. Apart from that, the overall experience was positive. Strobes supports us with external penetration testing and provides an external attacker's perspective on our applications and infrastructure. It has been particularly helpful in identifying security gaps, especially business-logic flaws and real-world exploitable issues, enabling us to strengthen our overall security posture before launching new features or scaling further.
"Robust Attack Surface Management with a Forward-Thinking Approach"
My favorite aspect of Strobes Security is their strong dedication to cybersecurity innovation and their focus on developing scalable, modern solutions. Their commitment to proactive vulnerability management and ongoing improvement resonates with my own passion for achieving efficiency and measurable outcomes through clear KPIs and structured processes. I also value the collaborative atmosphere and the chance to work on impactful projects addressing real-world security issues. The company's progressive outlook and growth-oriented culture allow me to contribute effectively while enhancing my skills. At present, there's nothing I strongly dislike about Strobes Security. However, like many rapidly expanding cybersecurity firms, some processes may still be developing as the company grows. I see this as an opportunity rather than a drawback, as it allows individuals to influence how things are done, boost efficiency, and drive continuous improvement. I'm particularly drawn to roles where I can optimize workflows, establish structured frameworks, and support ongoing enhancements. Strobes facilitates effective attack surface management by evaluating client assets, detecting vulnerabilities, and offering real-time alerts. The detailed dashboard, along with comprehensive weekly and monthly reports, makes monitoring easier and ensures visibility into assets and alerts. Additionally, the filtering options improve usability by enhancing visibility and streamlining daily operations.