I sit on the data side, not security, so my angle on this may be different from most reviewers. What got my attention was how CyStack handled the consulting piece before any testing started. They asked about our data flows: where shipment records move, where payment events get logged, who reads what. That conversation alone exposed two access patterns I'd been uncomfortable with for months but couldn't articulate to engineering as a real risk.
Then on the pentest itself, they hit the API layer hard. Found a horizontal privilege escalation on one of our internal services. That one stung; it had been live for a while. Their write-up included the exact request, the response diff, and a one-line code-level explanation of why authorization was failing. No fluff. Bewertung gesammelt von und auf G2.com gehostet.
The platform UI works fine, but a few things felt clunky for someone who lives in dashboards: the date filters reset when you switch tabs, and I'd love darker theme support for late-night reviews. Nitpicks, honestly. Bewertung gesammelt von und auf G2.com gehostet.
Thanks so much for this detailed review and for highlighting your experience from a data analyst's perspective!
We appreciate you noticing our focus on data flows during the scoping phase, as well as our direct, actionable approach to the API penetration testing write-ups. It’s great to hear that our work helped uncover those hidden vulnerabilities and provided you with clearer signals.
Thank you also for the feedback regarding the UI date filters and dark mode. Our product team has taken note on the issue. Finally, your advice to other users about involving data teams in the kickoff and prioritizing the live debrief is fantastic.
Many thanks for choosing CyStack as your security partner.
Best wishes,
The CyStack Security Team




