Happy Friday!
Hope you all are ready to read this weekend.
Expect to see our recent benchmark against the leading billion dollar agentic security company.
Complete figures, findings, code, and more.
We��re pursuing both SOC 2 Type II and ISO 27001 certifications, with GDPR already aligned. A major, expensive step, and worth every dollar.
Clearing them opens the door to customers most startups never get to sell to.
zauth to the big leagues.
landing page has been updated, will be adding more with time and growth! vector page will be updated next as well.
coincidentally, today we crossed the line of 50 whitebox scans since release! to all who have scanned - thank you for your lovely feedback, it has helped us improve our methodology greatly.
lots of progress towards enterprise as well - officially GDPR compliant, working towards ISO 27001 as well. we blew our first enterprise customer away - they were shocked at our turnaround time and discoveries on their private subnet. more to come in our blog section soon!
The average penetration test in the US costs about $18,300.
What that buys you: a snapshot. A point-in-time look at your app on the day they ran it. Ship a release next week and the report is stale. Compliance wants this annually. Your code changes daily.
It also buys you a wait. Scoping calls, quotes, contracts, scheduling, one to three weeks of testing. Then the report lands.
Tens of thousands of dollars and weeks of process. Priced for an enterprise security budget. Sold to a company that doesn't have one.
This is ridiculous.
And it's the gap we're building to close.
Real security is not one thing. It is dynamic testing of your live app. It is source level analysis that reads your code and catches the business logic and authorization flaws a black box scan never will. It is testing that runs in your pipeline, on every push and every deploy, not once a year on a contract. You need all of it. Most businesses can only afford a slice of it, once, and call it covered.
We think that's broken. So we're building the whole stack. Black box and white box. Source code analysis and live app testing. Continuous, in your CI/CD, running every time you ship instead of once a year when you can spare $20,000.
Same depth the enterprise contract gives you. Faster. Continuous. And for a small fraction of $18,000.
The barrier to building software collapsed. Eighty million people who were never engineers are shipping code.
The barrier to securing it has not moved. That is the problem worth solving, and it is the one we're solving.
What's next for zauth.
The problem: AI changed who gets to build. Millions of people who never wrote a line of code are now shipping real apps to real users, and they're doing it fast. But security never came along for the ride. It's still priced, packaged, and staffed for enterprises with dedicated teams.
So now, we have an entire generation of builders shipping production software with no one checking whether it can be broken into. The gap between what's getting built and what's getting secured has never been wider.
Vector - our blackbox pentest - closes that gap from the outside in. It finds its own way in, chains the weaknesses together the way an actual attacker does, then tells you exactly how it got there and what to fix. But the hardest bugs don't live on the surface. They live in your business logic, your auth chains, the broken assumptions buried in code paths you only catch when you can see the whole system at once. An attacker on the outside might take weeks to find them. With the source code in hand, we can find them in minutes.
So we're bringing Vector inside with whitebox pentesting. This is full source-level access, paired with the same offensive engine that already attacks your app from the outside. Together, that's the kind of coverage enterprises actually need, and we're wiring it straight into your pipeline so every commit gets attacked before it ships. Continuous pressure on every push, before anything reaches production.
And we're not stopping there.
Testing tells you where you were exposed at a single moment in time. It can't help you when someone is inside your app right now, probing, escalating, looking for the one door you left open. So we're introducing something that watches in real time and fights back the moment an adversary shows up. It closes the gap between scans, the window where you're actually under attack. It's revolutionary and will be a first for the cybersecurity world. More on this soon.
Security has to be autonomous. It has to think like an attacker. And it has to be on your side.
Most importantly, it needs to be accessible.
zauth is building all this and more.
zcash:native lost billions in marketcap because AI found a vulnerability that's existed for four years.
There's a single coin you can buy in this vertical and it's solana:DNhQZ1CE9qZ2FNrVhsCXwQJ2vZG8ufZkcYakTS5Jpump.
zauth's already found year-old dangerous vulns, and is building the future of AI cybersecurity.
It's very free.
Another buyback complete.
We've added $1,000 from revenue to our treasury.
Buybacks continue during each epoch at varied amounts and times.
Over $440,000 has been staked so far.
Read why our community is staking their tokens below.
I believe in what @zauthinc is achieving and going to achieve in the future. Step by step they updated you and don’t leave you in the dark. I truly believe this is just the start to this incredible company and community.
Staking is live with burns and distributions every 60 days.
https://t.co/NdsTQ5swGa
Lots of work in front of us as we look to serve the 80 million new builders that have entered the market in the last 3 years.