Skip to main content
Resource library

Everything we have learned from testing other people's software

Customer case studies with the numbers left in, the research behind each detection engine, version-by-version release notes, the webinar slate, and the templates our own team uses. No lead-capture wall on anything that does not need one.

Resources published
21
Customer case studies
6
Downloadable resources
4
Latest release
5.2.14

Latest case study

What changed for a team that stopped testing twice a year

6 studies in total, each with the challenge, the approach, the numbers and the lesson that transfers.

Product news

What shipped, and the detail behind it

Updates explain what changed and why it matters. Release notes list every feature, improvement and fix, version by version.

v5.2

February 12, 2026

Detection

Business logic testing, as a first-class scan type

Twenty-nine abuse patterns (race conditions, IDOR, price manipulation, workflow bypass) now run as their own scan phase, against the class of flaw that has no CVE and no signature.

  • 29 business logic abuse patterns
  • Race condition detection with controlled concurrency
  • IDOR testing across authenticated identities
  • +1 more
Read the update
All product updates

Latest release

5.2.14

February 12, 2026

Business logic testing

Twenty-nine business logic abuse patterns become a first-class scan phase, alongside a substantially expanded SAST ruleset, then a run of patch releases hardening that phase and the reporting behind it.

Features
7
Improvements
8
Fixes
9
Read the release notes

Downloads

Take something with you

Checklists, templates and guides for testing, API security and running an assessment programme. Whether an asset asks for an email is stated on the row, before you click.

  • Web Application Access Control Testing Checklist

    Role combinations to test, what cross-access to attempt, what a failure looks like. Genuinely useful to any team regardless of tooling.

    Checklist · PDF and Markdown · Ungated

    Download the checklist

  • API Security Testing Checklist

    Spec-driven coverage, object-level authorisation, GraphQL introspection concerns, gRPC, token scope verification, response content inspection.

    Checklist · PDF and Markdown · Ungated

    Download the checklist

  • Vulnerability Assessment Programme Template

    Scope definition, cadence by asset criticality, roles and responsibilities, severity handling, acceptance workflow, evidence retention.

    Template · DOCX and Markdown · Ungated

    Download the template

See Your Attack Surface in Real-Time

Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.