
The testing was independent of our development team, and the findings came back clear and specific enough to act on without a lot of back and forth. Each issue had the context we needed to reproduce and fix it, and the retest verified that every fix was actually closed rather than taking our word for it. The clean health certificate they issue is written so we can share it directly with customers and with SOC 2 and ISO 27001 auditors, which has saved us a great deal of explaining. Review collected by and hosted on G2.com.
Nothing significant. The reporting is thorough, so you do need to set aside proper developer time to remediate before the retest, though that is the point of a real test rather than a tick box exercise. More of the detail sits in the confidential report than on the shareable certificate, which is the right call for security but worth knowing at the start. Review collected by and hosted on G2.com.