Blacklock Security
Blacklock Security is a New Zealand-based PTaaS vendor offering continuous DAST, SAST, SBOM scanning, CREST-certified manual penetration testing, and an Agentic AI vulnerability validation engine for regulated enterprises, SaaS firms, and government organizations across five global offices.
- Company typePrivate
- Founded2021
- HeadquartersWellington, New Zealand
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Blacklock Security does
Blacklock Security Ltd. is a New Zealand-incorporated Penetration Testing as a Service (PTaaS) vendor that consolidates continuous DAST vulnerability scanning, SAST static code analysis, SBOM generation and management, CREST-certified manual penetration testing, and an Agentic AI vulnerability validation engine into a single subscription platform. The company's technical architecture pairs automated scanning across web applications, APIs, and infrastructure with human-led testing delivered by consultants holding CREST, OSCP, OSCE, and CISSP credentials, and unifies results in a dashboard that supports CI/CD triggers, JIRA-driven remediation, and compliance reporting against PCI DSS, ISO 27001, SOC 2, HIPAA, and GDPR. Differentiated capabilities include an industry-first Agentic AI engine that autonomously verifies findings, simulates exploit paths, and retests fixes, plus a Navigate & Scan Firefox browser plugin for authenticated scanning and a private agent for internal network assessments.
Blacklock operates a hybrid go-to-market combining product-led growth (14-day free trial, self-serve sign-up from USD 85/month) with enterprise field sales (Calendly-driven demos, quote-based manual penetration testing) and channel distribution through AWS Marketplace, Microsoft Azure Marketplace, and the NZ Government Marketplace (Pae Hokohoko). The company serves 150+ customers across financial services, insurance, logistics, government, SaaS, telecommunications, and cybersecurity — including named accounts such as Freightways, Tower Insurance, Parallo, Cin7, Wellington City Council, and Bidfood. Revenue is generated through monthly subscriptions for vulnerability scanning, SAST, and SBOM, plus on-demand CREST-certified penetration testing engagements. Key disclosed operating metrics include 120,000+ vulnerabilities reported, 1,000+ penetration tests performed, 48,656 hours saved, and a 99% Customer Happiness Index.
The company maintains offices in Wellington (HQ), Melbourne, Detroit, Lima, and Singapore, and is supported by an integration ecosystem of 15+ tools spanning code repositories (GitHub, GitLab, Bitbucket, Azure DevOps), ticketing (JIRA), compliance automation (Vanta), identity (Okta, Microsoft Entra ID), and communications (Slack, Teams). Blacklock is privately held with no disclosed institutional funding, no reported revenue, and no published headcount. Certifications and memberships include CREST accreditation, ISO 27001:2022, OWASP corporate membership, and listings on the AWS, Azure, and NZ Government marketplaces.
Blacklock Security firmographics
Firmographics- Name
- Blacklock Security
- Legal name
- Blacklock Security Ltd.
- Website
- https://blacklock.io
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Blacklock Security is a New Zealand-based PTaaS vendor offering continuous DAST, SAST, SBOM scanning, CREST-certified manual penetration testing, and an Agentic AI vulnerability validation engine for regulated enterprises, SaaS firms, and government organizations across five global offices.
- Ownership category
- akta.pro rank
Blacklock Security industry classification
Industry- Product category
- Application Security / Penetration Testing as a Service (PTaaS)
- NAICS
- Testing Laboratories and Services (541380), Security Systems Services (56162)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing Platforms (PTaaS) (HDADAHAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC), Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
Keywords
Where Blacklock Security is headquartered
LocationHeadquarters
- HQ city
- Wellington
- HQ country
- New Zealand
- HQ region
- Oceania
Offices5 records
Markets served
Blacklock Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Vulnerability Scanning Subscription: Monthly or annual subscription model providing continuous vulnerability scanning with tiered pricing based on number of web applications, IP addresses, and code repositories scanned. Plans start from USD 85 per month.
- Penetration Testing Services: On-demand CREST-certified manual penetration testing. Pricing is dependent on size and complexity of the application, assessed during scoping. Offered as an add-on to vulnerability scanning subscriptions or standalone.
- Static Code Scanning: Static Application Security Testing (SAST) as a subscription tier, supporting CI/CD integration and unlimited repository scans per plan.
- SBOM Management: Software Bill of Materials scanning and management, priced per repository on monthly or annual plans. Includes export capabilities in PDF, SPDX, and CycloneDX formats.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Vulnerability Scanning - Entry tier for continuous DAST scanning |
| Subscription | Monthly | Penetration Testing - Full PTaaS with manual testing |
| Subscription | Monthly | Static Code Scanning - SAST for development teams |
| Subscription | Monthly | SBOM Generation & Management - Software supply chain security |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels10 records
Blacklock Security product offering
Product offeringCore offering
Blacklock Security provides a unified Penetration Testing as a Service (PTaaS) platform that combines continuous automated DAST and SAST vulnerability scanning, SBOM generation, and Agentic AI-powered vulnerability validation with CREST-certified manual penetration testing. The platform is delivered via subscription tiers starting at USD 85 per month plus on-demand pen test engagements, targeting security, DevOps, and compliance teams in regulated industries.
Product overview
Blacklock Security offers a unified PTaaS (Penetration Testing as a Service) platform combining continuous DAST vulnerability scanning, SAST static code analysis, SBOM generation and management, Agentic AI-powered vulnerability validation, and CREST-certified manual penetration testing. The platform operates as a single integrated system where automated scanning (DAST/SAST/SBOM) runs continuously alongside human-led penetration testing, with AI-powered validation to reduce false positives and accelerate remediation. Key products include Vulnerability Scanning (DAST), Web Application Penetration Testing, Infrastructure Penetration Testing, Static Application Security Testing (SAST), and SBOM Scanning, all accessible through a centralized dashboard with integrations to developer tools (GitHub, GitLab, Bitbucket, Jira), compliance platforms (Vanta), and alerting systems (Slack, Teams).
Differentiator
Problem solved
Functional benefit
Products and services
- Vulnerability Scanning (DAST) Continuous Dynamic Application Security Testing (DAST) that scans web applications, APIs, and infrastructure for vulnerabilities on demand, on schedule, or triggered via CI/CD pipelines. Covers subdomain enumeration, email breaches, SSL misconfigurations, and targeted CMS attacks. For security, DevOps, and compliance teams needing ongoing vulnerability visibility.
- Web Application Penetration Testing CREST-certified manual penetration testing combined with automated DAST scanning for web applications and REST APIs. Covers OWASP-aligned methodologies, business logic testing, authentication testing, and API endpoint security validation. For organizations needing pre-launch or compliance-driven pen tests.
- Infrastructure Penetration Testing External and internal infrastructure penetration testing covering PTES and OSSTMM methodologies with over 9,000 security test cases. Uses private agents for secure internal scanning without internet exposure. For organizations needing external and internal infrastructure security validation.
- Static Application Security Testing (SAST) Static code analysis supporting 30+ programming languages including JavaScript, PHP, Terraform, Docker, Kubernetes, Ruby, Go, C#, Python, and TypeScript. Identifies security vulnerabilities, code smells, and injection flaws early in the SDLC. For development teams embedding security testing into CI/CD pipelines.
- Software Bill of Materials (SBOM) Scanning SBOM generation and management service that scans code repositories, analyzes software components, identifies vulnerabilities with CVE details, checks license compliance, and exports reports in SPDX, CycloneDX, and PDF formats. For organizations needing software supply chain transparency and compliance.
- Log4j Scanner Free specialized scanner tool for detecting Log4j vulnerabilities in applications and systems, available as a standalone tool on the Blacklock platform. For security teams needing fast triage of Log4j exposure.
- React2Shell Scanner Free specialized scanner tool for detecting React2Shell vulnerabilities, available as a standalone tool on the Blacklock platform. For security teams needing fast triage of React2Shell exposure.
Quantifiable outcome
- 48,656 hours saved with Blacklock PTaaS
- +4 more outcomes
Companies that use Blacklock Security
Customer profileNamed customers21 records
Segments6 records
Ideal customer profiles6 records
Blacklock Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration14 records
AI capability5 records
Feature8 records
Blacklock Security partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered core.
- GitHubcoreSource code repository integration enabling CI/CD pipeline scanning, automated SAST on each deployment, and seamless GitHub Actions workflow integration. Supports vulnerability detection in code repositories.
- GitLabcoreCode repository integration for automated security scanning and SBOM generation from GitLab projects. Enables continuous security testing in GitLab CI/CD pipelines.
- BitbucketcoreIntegration with Atlassian Bitbucket for automated SAST and vulnerability scanning within Bitbucket Pipelines.
- Azure DevOpscoreIntegration with Microsoft Azure DevOps for CI/CD pipeline security scanning, automated vulnerability detection, and developer ticketing.
- JiracoreOne-click ticket creation from vulnerability findings. Developers receive developer-ready tickets with remediation guidance directly in their JIRA workflow.
- VantacoreCompliance automation integration for SOC 2 and ISO 27001 evidence workflows. Blacklock findings sync to Vanta for continuous compliance evidence.
- AWS MarketplacecoreListed on AWS Marketplace enabling AWS customers to discover, purchase, and deploy Blacklock security services through their existing AWS account and billing.
- Microsoft Azure MarketplacecoreListed on Azure Marketplace enabling Azure customers to procure Blacklock services through their enterprise Microsoft agreements.
- NZ Government Marketplace (Pae Hokohoko)coreApproved supplier on New Zealand Government Marketplace, enabling public sector organizations to procurement cybersecurity services through government channels.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
Blacklock Security competitors and assessment
Company assessmentDirect peers
- Intruder: Intruder is a continuous vulnerability scanning platform with both SMB and enterprise tiers, competing directly with Blacklock's vulnerability scanning subscription starting at USD 85/month. Both combine automated scanning with prioritization and integrations to dev tools.
- Invicti (Netsparker): Invicti offers DAST and application security testing through its Netsparker product line, overlapping with Blacklock's DAST scanning and web application penetration testing services. Both serve enterprise AppSec teams with automated and hybrid testing models.
- Cobalt: Cobalt is a leading PTaaS platform that combines on-demand manual penetration testing with a SaaS workflow platform. It is a direct competitor to Blacklock's PTaaS offering, targeting similar developer and security teams with crowdsourced CREST/OSCP-style testers via a subscription model.
- Detectify: Detectify offers continuous web application and external attack surface scanning powered by crowdsourced research, competing with Blacklock's DAST and asset discovery capabilities. Both target security teams needing always-on vulnerability visibility.
- Pentera: Pentera provides automated security validation and penetration testing as a service, emphasizing continuous testing over annual pentests. It competes directly with Blacklock's automated DAST and continuous validation value proposition for enterprise security teams.
Broad incumbents
- Veracode: Veracode is a long-standing application security testing platform offering SAST, DAST, and software composition analysis. It competes with Blacklock's SAST and DAST products in enterprise AppSec deals, particularly with regulated buyers.
- Snyk: Snyk is a large developer security platform spanning SAST, SCA, and container security. It competes with Blacklock's SAST tier and broader DevSecOps positioning, with deeper language coverage and broader enterprise sales coverage.
- HackerOne: HackerOne is a broader security testing platform combining bug bounty, PTaaS, and code security audits. It overlaps with Blacklock's manual penetration testing offering but operates at a much larger scale with a global researcher community.
- Cybereason: Cybereason is a broader endpoint and exposure management vendor that has expanded into attack surface and vulnerability validation. It is comparable to Blacklock through overlapping vulnerability management and security testing capabilities aimed at enterprise security teams.
Emerging players
- Astra Security: Astra Security provides PTaaS-style continuous pentesting and vulnerability scanning with a strong SaaS PLG motion. It is comparable to Blacklock's SMB-friendly self-serve and continuous testing positioning, though smaller in scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Blacklock Security social profiles
Digital presenceBlacklock Security compliance and trust
Trust signalCompliance6 records
Blacklock Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Blacklock Security leadership team
Management profileNumber of profiles
Blacklock Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Blacklock Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Blacklock Security
What does Blacklock Security do?
Blacklock Security provides a unified Penetration Testing as a Service (PTaaS) platform that combines continuous automated DAST and SAST vulnerability scanning, SBOM generation, and Agentic AI-powered vulnerability validation with CREST-certified manual penetration testing. The platform is delivered via subscription tiers starting at USD 85 per month plus on-demand pen test engagements, targeting security, DevOps, and compliance teams in regulated industries.
Is Blacklock Security a public or private company?
Blacklock Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Blacklock Security founded?
Blacklock Security was founded in 2021. It employs 1 to 10 people.
Where is Blacklock Security based?
Blacklock Security is headquartered in Wellington, New Zealand, in the Oceania region.
How does Blacklock Security make money?
Four revenue lines are on record. Vulnerability Scanning Subscription is the primary driver. The others are penetration Testing Services, static Code Scanning and SBOM Management.
Who are Blacklock Security's main competitors?
Direct peers on record are Intruder, Invicti (Netsparker), Cobalt, Detectify and Pentera. Broad incumbents are Veracode, Snyk, HackerOne and Cybereason. Astra Security is listed as an emerging player.
Does Blacklock Security have an API?
Yes. Blacklock provides API access for developers to integrate security scanning capabilities into their workflows. The platform offers access to Blacklock APIs as part of its subscription plans, enabling integration with CI/CD pipelines, vulnerability management, and developer ticketing systems. Specific API types (REST, GraphQL, webhooks), authentication methods, rate limits, and sandbox availability are not explicitly stated on the main pages.
What industry is Blacklock Security in?
Blacklock Security's product category is Application Security / Penetration Testing as a Service (PTaaS). Its primary akta.pro industry code is HDADAHAG, Penetration Testing Platforms (PTaaS), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541380 and its SIC code is 8734.