S
Small-Business (50 or fewer emp.)
"Automated Pentesting Developers Embrace"
We've been pleased with ZeroThreat's developer-centric DAST approach. Setup was almost instantaneous, scans were fast, and findings aligned neatly with OWASP Top 10 issues and included actionable remediation guidance. The CI/CD integrations and GitHub Action make it simple to keep security checks in our pipeline, and the Chrome 'Recorder' extension is great for capturing complex user flows before scanning. It's a smart way to cut down on manual pentest effort while maintaining velocity. The UI is clean, but some areas could benefit from additional tooltips or context to help new users understand how settings affect scans. ZeroThreat replaces our occasional manual pentests with continuous dynamic testing for our web app and APIs. It catches OWASP-class issues early in CI/CD, provides clear fix advice, and reduces noise so engineers can remediate in hours rather than weeks. The result: fewer regressions, faster releases, and a stronger security posture for our customers.
"Valuable Tool Providing Useful Insights"
ZeroThreat lives up to its claims, offering automation, speed, and straightforward vulnerability reports. Setup was easy, and the reports clearly outlined the issues found. There are occasional false positives and some noise, but that's typical for this kind of software. For our ISO certifications, we need to show evidence of completing security compliance tests. Since it's easy to use, ZeroThreat ensures these tests are carried out, and any issues are resolved quickly.
"Comprehensive Feedback with In-Depth Scans"
The scans are thorough and detailed, and the reports are comprehensive, giving our team excellent feedback. Given its comprehensiveness, the initial setup can be somewhat involved. It enables us to run security scans on every software release to maintain our security levels and minimize risk.
"Great Security Tool for Managing Login Credentials"
Delivers essential login information for various platforms in our case, Windows servers and IBMi systems, through a simple dashboard. Occasionally, features may lag or not provide the detailed information we expect. Today, when I clicked on the 'LOG', I got an error saying the event logger couldn't connect. This is the second error I've encountered, but overall, it's been very useful for our company. It offers centralized login data, which is helpful for auditing and compliance. It works across multiple system platforms.
"ZeroThreat - Excellent for External and Internal Infrastructure"
Our client values the comprehensive visibility across all systems, networks, AWS, Azure, and Active Directory, which proves particularly useful during DDoS attacks. Both the NOC team and senior management rely on ZeroThreat's insights across all intrusion attempts. This level of visibility is only achievable with ZeroThreat. We've conducted demos and POCs for a large client base in Australia. So far, we haven't come across any limitations of ZeroThreat. In these uncertain times, when organizations are seeking cost reductions without sacrificing security, ZeroThreat steps in. Additionally, it's easy to set up, has an intuitive UI, and integrates with other third-party tools.
"Smooth Security Integration, Minimal Overhead"
I really appreciate how ZeroThreat slips into our current workflow, keeping our apps and APIs secure without burdening our team. Real-time vulnerability alerts are extremely useful since they appear right in our workflow, allowing us to fix issues promptly before they go live. The interface is clean and easy to navigate, making it user-friendly and effective. The automation is a highlight; it runs quietly in the background, scanning each build with no manual effort required. This greatly reduces the need for manual security checks and third-party audits, speeding up our release process and avoiding delays. ZeroThreat delivers clear, actionable reports without technical jargon, simplifying our security management. It works seamlessly with Jenkins and GitHub Actions, triggering scans automatically on each build. Linking it with Slack and Jira improves team communication and issue tracking, keeping everyone informed with minimal disruption. Setup was quick and straightforward, making initial integration painless. I'm also pleased with its detection accuracy, which has significantly reduced false positives compared to our old tool. Overall, ZeroThreat offers reliability and efficiency, and I highly recommend it. There are a few minor improvements that could be made. The reporting section lacks sufficient filtering and sorting options, making it time-consuming to locate specific scan results or older data. Also, while the UI is generally clean, some areas could load faster when dealing with large projects. A dark mode and additional integrations with tools like GitLab and Bitbucket would also be nice. These are more like nice-to-haves rather than critical issues, but they would enhance the experience. ZeroThreat keeps our apps secure by automating vulnerability scans, saving time on manual checks, and ensuring faster, safer releases. Its real-time alerts and seamless CI/CD integration significantly boost our workflow efficiency.
V
Vice President of Product Development
"Time-Saving and Faster Issue Resolution"
ZeroThreat has proven to be a valuable asset for our team. Setup was a breeze and scans complete in just minutes. The reports are straightforward, cutting down analysis time and allowing us to concentrate on fixing problems. As a Product Owner, I'm most impressed by how well it integrates into our development pipeline, giving us the assurance to address vulnerabilities just as quickly as we ship features. That's been a game changer. So far, no major complaints—just a desire for even more integrations with our existing tools. It eliminates setup hassle and provides clear insights. ZeroThreat addresses critical vulnerabilities, including OWASP Top 10 items, XSS, and MySQL injection. This proactive method helps us maintain website security standards, safeguarding our data, protecting users, and ensuring our online presence remains reliable and trustworthy.
"Rapid AI-Based Vulnerability Validation for CI/CD"
I appreciate ZeroThreat for its AI-driven vulnerability validation, quick scanning, and minimal false positives. It blends well with modern applications and CI/CD pipelines, making continuous testing straightforward, though it's still necessary to pair with manual VAPT for complete security coverage. My main dislike is that it can't match the thoroughness of manual VAPT, especially for complex or business logic issues. Because it relies heavily on automation, some edge cases are overlooked, and occasional false positives still need human review. ZeroThreat addresses the issues of slow testing and excessive false positives by automating validation and accelerating scans, enabling me to concentrate on genuine vulnerabilities rather than wasting time on trivial findings.
"Precise Scanning with Minimal False Alarms"
Having worked with numerous scanners, I'm used to being flooded with false positives. From the very first scan, ZeroThreat.ai stood out. It identified logic flaws in our signup and checkout processes that I didn't think a pentesting tool would catch. As a security engineer, the precision is what impressed me most. I no longer spend hours sifting through false alarms, making my job much more efficient. The one area that could be better is the navigation and filtering of historical scan results; the interface takes some getting used to. Once you're familiar, it works fine, but a more intuitive design would improve the experience. It enables us to spot real, exploitable issues on an ongoing basis rather than waiting for quarterly manual pentests. We primarily use it for continuous web app penetration testing on our customer-facing dashboards. It helps us catch critical security gaps, including business logic errors and API-level vulnerabilities, much earlier. This proactive strategy has strengthened our security stance and reduced our reliance on infrequent manual tests.
"Ongoing Testing and Swift Remediation"
The standout feature for me is how effortless the initial configuration was. Once integrated into our CI/CD pipeline, every build is automatically scanned without any extra thought, functioning like an additional QA layer we don't have to manage. Developers now see issues within their usual workflow, which has encouraged them to take ownership and resolve problems early rather than passing them to the security team. A minor downside is the limited number of native integrations; we had to improvise to make it work with our stack. It's caught issues pre-launch instead of post-deployment. Each build is scanned automatically, saving us time and preventing last-minute fixes. The dev team has become more security-conscious, and our releases have fewer vulnerabilities. Overall, it has integrated security into our development process seamlessly, boosting both our speed and confidence for production deployments.