Penetration Testing for Property Management Platform
-
Application Testing Cybersecurity
-
Application Security Vulnerability Management
- Confidential
- May 2022 - Aug. 2026
- Quality
- 5.0
- Schedule
- 5.0
- Cost
- 5.0
- Willing to Refer
- 5.0
"They behave like an extension of our engineering team rather than an external auditor."
- Information technology
- Auckland, New Zealand
- 51-200 Employees
- Online Review
- Verified
phew provided penetration testing services for a property management platform. The team conducted tests against the client's staging environments using source code access and application credentials.
phew improved the client's overall security and provided continuous assurance to stakeholders. The team delivered on schedule and provided findings that convert straight into prioritized engineering work items. Their team was responsive, flexible, and behaved like an extension of the client's team.
The client submitted this review online.
BACKGROUND
Please describe your company and position.
I am the VP of Engineering of an information technology company
Describe what your company does in a single sentence.
We're a cloud-based property management platform purpose-built for commercial real estate, giving property managers, landlords and investors a single system for lease administration, accounting, maintenance and portfolio reporting.
OPPORTUNITY / CHALLENGE
What specific goals or objectives did you hire phew to accomplish?
- Ongoing penetration testing of our web applications, mobile applications and APIs
- Independent validation of remediation — re-testing to confirm fixes are effective, and certification we can present at annual audit and in customer security reviews
- Assurance for customers and partners that our platform is independently tested on a regular schedule
SOLUTION
How did you find phew?
Referral
Why did you select phew over others?
- High ratings
- Close to my geographic location
- Pricing fit our budget
- Great culture fit
- Good value for cost
How many teammates from phew were assigned to this project?
2-5 Employees
Describe the scope of work in detail. Please include a summary of key deliverables.
Phew run our penetration testing programme on a continuous cycle rather than as one-off engagements.
Scope. Our core applications are tested every round. The remainder of our internet-facing estate rotates through the schedule so that everything is assessed on a frequent known cycle, which lets us extend coverage as we add applications without testing everything every time. Scope for each round is agreed in advance, with credentials, environments and prerequisites confirmed before testing begins.
Approach. Testing is conducted against our staging environments with source code access and application credentials. The code access is deliberate on our part, it means that when a vulnerability is identified, their testers can determine whether the same pattern recurs elsewhere in the codebase rather than reporting a single instance. That has consistently given us more value than black-box testing would.
Key deliverables per round:
- A detailed report of findings, each rated by severity with supporting evidence and remediation guidance
- Findings structured so they translate directly into engineering work items assigned to the owning squad
- A re-test after remediation to independently confirm each issue is resolved
- A certificate of assurance on successful validation, which we use in our annual security audit, in customer security questionnaires, and as public evidence of our security posture
- Comparison against the previous round, so we can see whether the overall trend is improving
Ongoing engagement. Alongside the testing itself, Phew maintain a shared Slack channel with our engineering team for questions during a round, and have provided indicative scoping and pricing advice as our application portfolio has grown, including confirming that pricing flexes down if we reduce targets, not just up if we add them.
RESULTS & FEEDBACK
What were the measurable outcomes from the project that demonstrate progress or success?
With the aim of improving the overall security of the product suite, providing ongoing assurance our company and its stakeholders and partners
The programme delivers on schedule and produces work we can act on immediately. Every round has been completed within the agreed window, and findings arrive structured well enough that they convert straight into prioritised engineering work items on the owning squad's backlog, each with a remediation timeframe tied to its severity. We track closure of those items against those timeframes.
The clearest measure of success is independent verification: after remediation, Phew re-test and confirm resolution, and issue a certificate of assurance. That certificate is the outcome we use in our annual security audit and in customer security reviews, and it's evidence that issues raised have actually been closed rather than just logged.
Beyond individual rounds, the programme has changed how we build. Patterns identified in one round feed into what our engineers watch for in the next, and testing with source code access means a single finding gets traced across the codebase rather than fixed in one place, so remediation is broader than the finding itself.
Describe their project management. Did they deliver items on time? How did they respond to your needs?
Scheduling is the strongest part of it. Rounds are booked well in advance against a fixed cadence, scope is agreed before testing starts, and prerequisites — environments, credentials, target confirmation — are worked through up front rather than surfacing mid-round. Reports have arrived when they said they would, every round. The re-test is scheduled around our remediation timeframes rather than theirs, which matters because it means the verification lands when we're actually ready for it rather than forcing us to rush fixes to meet a testing slot.
Day to day, we run a shared Slack channel between our engineering team and theirs. That's the thing that makes the engagement work. Our engineers can put a question directly to the people who found the issue and get an answer in hours, rather than raising a ticket and waiting for a formal response. We have a consistent named contact across rounds, so there's no re-explaining our environment or our estate each time.
On responsiveness to changing needs: our application portfolio has grown considerably over the course of the relationship, and Phew have adapted the programme with it. When we needed to understand the cost implications of extending coverage, they provided indicative pricing to help us make the decision internally. They've been transparent about their own pricing changes rather than presenting them as a fait accompli. That flexibility on both direction is not something we take for granted in a security vendor.
What was your primary form of communication with phew?
Email or Messaging App
What did you find most impressive or unique about this company?
They behave like an extension of our engineering team rather than an external auditor, and the difference shows up in the quality of what we get back.
Most security testing relationships are transactional, scope goes in, a report comes out, and the tester has no interest in whether you understood it. Phew work the other way. We give them source code and staging credentials, they give our engineers direct access to their testers through a shared channel, and the result is that a finding gets traced to root cause and checked for recurrence across the codebase rather than reported as a single instance and closed. Our engineers learn something from each round, which is not a thing I expected to be able to say about penetration testing.
The other thing worth noting is longevity. We've worked with them for over five years across a product estate that has grown substantially in that time. They understand our architecture, our environments and how we build, so each round starts from context rather than from scratch. For a specialist New Zealand consultancy, they've scaled with us without the relationship losing that closeness.
Are there any areas for improvement or something phew could have done differently?
Nothing significant. The one thing I'd note is a consequence of growth rather than a shortcoming on their part: as our application estate has expanded, the scoping conversation each cycle has become more involved. A consolidated view of findings and trends across rounds, rather than each report standing on its own, would provide value from a trend analysis and would make the internal conversation about coverage easier. That's a refinement to an already strong service, not a gap.
RATINGS
-
Quality
5.0Service & Deliverables
-
Schedule
5.0On time / deadlines
-
Cost
5.0Value / within estimates
-
Willing to Refer
5.0NPS