- Home
- Product
SOC 2 Type II, pentest included
A signed SOC 2 report,
and the pentest that earns it.
We build and monitor your controls, attack your live app every month, and an independent US AICPA CPA signs the report your buyers keep asking for. From $6.1k in your first year, under 10 people.
Free to set up. Pay only when you run.
How you run it
One engine,
four ways to use it.
Same plan, same monthly pentest. Pick by how much access you give it.
-
Black-box
No source needed
Attack your live app with nothing but a URL.
Read
-
White-box
Deepest coverage
Read your code first, then attack. Finds the deepest bugs.
Read
-
MCP server
Early access
Start and read pentests from your code editor.
Read
-
The fix, as a pull request
End to end
We open a pull request straight to your GitHub that patches the vulnerability we just proved.
Watch a run
This is an attack,
not a scan.
It hits the target while you watch the timer climb and the moves roll in.
A HackZero live pentest in progress: the engine attacking a sample target, a running timer, a feed of attack moves, and a step-by-step pipeline.
What you get
Proof you can copy,
and a fix you can ship.
Each bug lands in your tracker with three things:
- 01 The exact curl that triggered it.
- 02 A screen recording of the exploit.
- 03 The diff that closes it.
Run it yourself in 10 seconds. No exploit, no finding. Not a 400-page PDF.
See a sample report
Frequently asked
Questions.
A SOC 2 Type II attestation report signed by an independent AICPA-member CPA. To get there we build and monitor your controls, collect the evidence from your stack, and run a penetration test against your live app every month. The pentest is included, not a separate engagement.
An independent US CPA firm that is an AICPA member. They contract with you and bill you directly, and we never take a share of that fee, because a fee split would compromise the independence that makes the report worth anything.
No. Sign up, point it at your app, and launch your first pentest yourself. Most teams run in minutes.
Scanners flag thousands of maybes. We run real attacks and only report what we actually broke, with proof. It replaces the people you would hire to break in by hand, not your scanner.
Each one comes with the exact request that triggers it. Run it yourself. If it does not reproduce, it is not a finding.
Yes, if you turn on write access. By default we are read-only and just hand you the fix.
$299 a month if you are fewer than 10 people, $499 a month if you are 10 or more. Both include SOC 2 Type II controls and one pentest a month, unlimited on your own Anthropic key. The independent CPA's report fee starts at $2,500 and is paid straight to them, so a team under 10 people reaches a signed report for about $6.1k in the first year. A human-validated pentest is $1,500 per engagement. The rest is on the pricing page.