Blacklock is an award-winning platform that offers consultant grade testing with an On Demand experience. The platform allows you to perform continuous unlimited vulnerability scanning on an ad-hoc and scheduled basis with the benefit of undertaking manual penetration testing when you need it. Blacklock is the most powerful and advanced scan engine for DAST & SAST testing that combines multiple security tools to cover maximum attack surface area. The service is compliant with industry security standards such as OWASP, ISO and SOC2 requirements.
Blacklock is a penetration testing as a service that automates the discovery of security vulnerabilities in your Internet-facing assets and manages them from a single pane of glass. Key features include:
-Self or assisted onboarding of web applications or external infrastructure
-Continuous unlimited vulnerability scanning
-AI-Powered Scan Engine coupled with manual penetration testing
-Remediation code for developers based on your tech stack
-Retest after remediation
-Automated report generation (executive and developer report)
-Flexible API integration for DevOps
-Integrate with Slack, MS Teams or JIRA for automatic bug reporting and tracking
Whats on offer:
-Continuous vulnerability scanning on external infrastructure, static websites or web applications (unauthenticated and authenticated)
-One-time, annual or continuous manual penetration test, we have it all delivered through one platform
-Powerful scan engine that combines multiple security tools to cover maximum attack surface area
-Unlimited web application or infrastructure vulnerability scanning (on-demand, recurring or scheduled)
-Attack surface testing (subdomain enumeration, email address breaches, SSL misconfiguration, targeted CMS attacks)
-Business logic and access control testing
-Expert manual penetration testing and verification of vulnerabilities
-OWASP, ISO, SOC2 compliant testing, pen test certificate and reports
Highlights
Continuous vulnerability scanning on web application, API endpoints and infrastructure and on-demand pen testing
SAST & DAST service with DevOps, JIRA, Github, Slack, MS Teams integration
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy this service by unit, picking the target you want tested. Each dimension maps to a different asset type. Infrastructure covers up to 10 public IP addresses with over 9,000 vulnerability checks. Unauthenticated Web Application tests public-facing apps and REST APIs using black box scanning. Authenticated Web Application adds gray box scanning, REST API coverage, and DevOps integration. Business Web Application also uses authenticated gray box scanning, REST API, and DevOps support. You can combine units to match the number and type of assets in scope, scaling by adding units.
Top-of-mind questions for buyers
What counts as one unit for the Infrastructure dimension?
One Infrastructure unit covers up to 10 public IP addresses and runs over 9,000 security checks against them. If you have more than 10 public IPs in scope, you add more units. Each unit covers external, cloud, and public-facing assets within that IP count.
How do the web application dimensions differ from each other in what they test?
Unauthenticated Web Application runs black box scanning on public-facing apps and REST APIs without login. Authenticated and Business Web Application use gray box scanning with login credentials, covering user roles, business logic, and access control. All three include REST API coverage and DevOps integration.
Is manual penetration testing included, or is it a separate cost from the scan units?
Automated vulnerability scanning runs continuously under each unit. You can start with scanning and request manual penetration testing on demand when needed. Manual testing pricing depends on the size and complexity of the application, which is assessed during scoping, and is not fixed by unit.
blacklock.io+3
Helpful?
Vendor refund policy
14 day refund
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Due to FDA requirements, we required a penetration test and chose Blacklock based on a referral. Their team efficiently onboarded us, enabling us to begin the pen testing as planned. The thorough manual pen testing led to a comprehensive report, which the FDA highly approved. I strongly recommend Blacklock for their effective and meticulous service. We certainly plan to use their services again for future needs. A special thanks to the customer service and technical teams at Blacklock!
Greg
Happy with choice
Reviewed on Oct 30, 2023
Review from a verified AWS customer
After testing the Blacklock automated penetration tool during a trial period, I decided a subscription was the right choice. Payment via the AWS marketplace was frictionless and the Blacklock team has been extremely responsive with on-boarding and support questions.
I've been very happy with how Blacklock was able to get us to OSWASP Top 10 compliance in only a few days. I was impressed at how our entire attack surface was scanned for common vulnerabilities. The findings generated by the scans are clear and specific. The reports look very professional and the vulnerability lists include references as to how the discovered issues may be corrected
The people behind Blacklock are very knowledgeable and have been helpful tuning the reports to our needs. In my opition Blacklock provides excellent value.
Anuj
Quick & efficient penetration testing results
Reviewed on Sep 08, 2022
Review from a verified AWS customer
We had an urgent penetration test requirement come up from the customer. We came to Blacklock from a reference, and they got onto it very quickly. The onboarding process was quick, and we were able to kick off pentesting as per our schedule. The manual pentesting was very thorough, and the customer accepted the report with high satisfaction. I highly recommend Blacklock and won't hesitate to come back when we have a new requirement. Thank you Blacklock team