Penetration Testing & Cybersecurity for AI Solutions Company
- Cybersecurity
- $10,000 to $49,999
- Jan. 2024 - Ongoing
- Quality
- 4.5
- Schedule
- 5.0
- Cost
- 4.5
- Willing to Refer
- 5.0
"Based on the quality of their findings and their collaborative approach, we've chosen to continue working with them."
- Information technology
- Arhus, Denmark
- 1-10 Employees
- Online Review
- Verified
Sekurno provides ongoing penetration testing services for an AI solutions company. The team collaborates with the client to define which areas need testing and how to prioritize them.
The client is pleased with the engagement and the quality of Sekurno's findings. The team has grown from a trial engagement into an ongoing partnership. Sekurno provides useful feedback and helps the client become more security aware. They've remained trustworthy, credible, and communicative. This review is an update by the client company. The original content is located below the new review.
The client submitted this review online.
BACKGROUND
Introduce your business and what you do there.:
I’m Mads, the CTO at Kaunt.
Kaunt provides an AI-driven account coding engine that automates the invoice account coding process, enabling greater efficiency and accuracy in finance operations. We are based in Denmark and operate in a high-trust environment with enterprise clients. As such, we prioritize strong security practices and strict compliance with industry standards such as ISO and SOC 2. Our goal is to maintain trust and credibility by demonstrating a mature and proactive approach to security.
OPPORTUNITY / CHALLENGE
What challenge were you trying to address?
As a company operating in the finance and AI sectors, we needed to demonstrate that our systems were secure and compliant with industry standards like ISO and SOC 2. This was not only a compliance requirement but also a strategic need to earn the trust of large enterprise clients who carefully assess the security posture of their partners.
We hired Sekurno with two key objectives in mind.
First, we wanted a professional penetration test that would go beyond a standard checklist and offer in-depth insights into our systems. We needed a testing partner who would not just validate our security but help us improve it.
Second, we were looking for peace of mind across the organization. This included our engineering team, our leadership, and our salespeople who are often asked to provide proof of security to prospects. The ability to show a rigorous test report and explain how we responded to findings was important to our credibility.
This was our second engagement with Sekurno. After being impressed by their work in the first year, we expanded the scope this time to include more systems and infrastructure.
SOLUTION
How did you find Sekurno?
Online Search
Why did you select Sekurno over others?
- Pricing fit our budget
- Great culture fit
- Company values aligned
How many teammates from Sekurno were assigned to this project?
2-5 Employees
What was the scope of their involvement and team dynamic?
This year, the scope of Sekurno’s work increased significantly. Initially, we focused on backend services, but for this engagement we included the frontend and key parts of our infrastructure as well. The idea was to cover all critical components of our application.
The engagement started with threat modeling sessions, where we worked together to define which areas needed testing and how the testing should be prioritized. This helped us build a more structured and thoughtful security review process.
The team at Sekurno was highly collaborative and technically skilled. One of the things we appreciated the most was having direct conversations with the actual penetration testers. This allowed us to go deeper into the findings and understand the context behind each issue. It was a much more technical and valuable interaction than dealing with general project managers.
A new and very effective improvement this year was the use of a dedicated Slack channel. Communication was fast and fluid, similar to how we work internally. This helped speed up discussions, reduce delays, and made the whole process feel more integrated.
What's the status of this engagement?
The formal penetration testing engagement has been completed, but our collaboration with Sekurno continues. We now involve them whenever we have questions related to security, even when it comes to other companies within our group. They’ve become a trusted partner we can rely on not only for testing but also for general guidance on security architecture, tooling, and best practices.
RESULTS & FEEDBACK
How did your relationship with your partner evolve?
Our relationship with Sekurno has grown from a trial engagement into an ongoing partnership. In the first year, we wanted to see how they worked and whether the collaboration would add value. Based on the quality of their findings and their collaborative approach, we've chosen to continue working with them.
This year, we were able to share part of the penetration testing report with some of our enterprise clients. Their response was very positive. A few even commented that “these guys know what they’re doing,” which helped us build trust and credibility. The depth and clarity of the testing helped us demonstrate that we are serious about security and that we invest in it not just for compliance, but because it matters to our business and our customers.
What was your primary form of communication with Sekurno?
- Virtual Meeting
- Email or Messaging App
In what ways can they improve?
Overall, the engagement was excellent. If there is one area for improvement, it would be to provide more proactive updates during the testing phase. Even short status messages could help give more visibility into the timeline and reassure the client that everything is on track. This is especially valuable when working with tight deadlines.
What advice do you have for clients with similar needs to yours?
If you are going to invest in penetration testing, make sure it is more than just a formality. Work with a partner who helps you learn something from the process and improves your actual security. With Sekurno, we received useful feedback and our team became more security aware as a result.
Also, provide the testers with all the information they need from the beginning. The better the context they have, the more precise and efficient the testing will be. That way, you get real value from the engagement and not just a report to satisfy compliance requirements.
UPDATED REVIEW
This review was published on 02/06/2024
Mads Ellersgaard Kalør
CTO, Kaunt A/SInformation technology
Arhus, Denmark
1-10
Jan 2024 - Jan 2024
$10,000 to $49,999
Verified
Project summary
An IT company hired Sekurno to provide cybersecurity services. The team fulfilled compliance requirements and conducted penetration testing and security risk penetration for the client.
Feedback summary
Thanks to Sekurno, the client met compliance requirements with a detailed and approved report. The team provided valuable security insights, delivered on time, hosted efficient meetings, and adapted to the client's requirements. Sekurno's thorough testing was crucial to the project's success.
BACKGROUND
Please describe your company and position.
I am the CTO of Kaunt A/S
Describe what your company does in a single sentence.
We provide an AI driven account coding engine that automates the invoice account coding process.
OPPORTUNITY / CHALLENGE
What specific goals or objectives did you hire Sekurno to accomplish?
- Compliance Requirement Fulfillment
- Valuable Penetration Testing
- Security Risk Mitigation
SOLUTION
How did you find Sekurno?
Online Search
Why did you select Sekurno over others?
- Pricing fit our budget
- Great culture fit
- Company values aligned
How many teammates from Sekurno were assigned to this project?
2-5 Employees
Describe the scope of work in detail. Please include a summary of key deliverables.
The project commenced with a thorough vendor research phase. We evaluated four offers, considering factors like price, urgency, and the specific nature of our requirements. Sekurno stood out due to their competitive pricing and a deep understanding of our needs, particularly with regard to compliance and penetration testing.
During the pre-sale process, Sekurno distinguished themselves through efficient communication and a personalized approach. The contract and related documents were managed smoothly, a vital aspect given our tight deadlines. In the execution phase, Sekurno's team displayed professionalism and technical expertise. They provided clear guidelines on what was needed from our end, ensuring efficient use of resources.
The engagement with our developers was particularly noteworthy, as Sekurno’s team was open and informative, facilitating productive discussions about security. The reporting was comprehensive and accessible. It detailed the penetration testing process and results, providing valuable insights into our security posture.
RESULTS & FEEDBACK
What were the measurable outcomes from the project that demonstrate progress or success?
The project led to tangible outcomes that significantly impacted our business. Firstly, it enabled us to meet our compliance requirements with a detailed and approved report, reassuring our customers and partners about our security measures.
Secondly, the penetration testing provided invaluable insights, identifying vulnerabilities in our code, which enhanced our overall security. This process also boosted our development team's confidence, validating the security of their work and providing an external perspective on areas for improvement. The thoroughness of Sekurno's testing and their ability to go beyond mere compliance checks significantly contributed to the project's success.
Describe their project management. Did they deliver items on time? How did they respond to your needs?
Sekurno’s project management was exemplary. Despite a short timeline, they delivered the report on schedule and ensured all processes were aligned with our needs. Communication was efficient, and the number of meetings was optimal, avoiding unnecessary time expenditure.
The team was always reachable and responsive, adapting seamlessly to our requirements. The involvement from our side was minimal, mainly overseen by myself, which speaks to Sekurno’s ability to manage projects independently and effectively.
What was your primary form of communication with Sekurno?
- Virtual Meeting
- Email or Messaging App
What did you find most impressive or unique about this company?
The most impressive aspect of Sekurno was their commitment to providing more than just a compliance service. They showcased a deep understanding of security risks and a dedication to thorough testing, distinguishing themselves from other vendors who might focus solely on compliance.
This approach, coupled with their transparent and down-to-earth communication style, made them stand out. Their ability to convey technical details effectively and engage in meaningful discussions about security was particularly noteworthy.
Are there any areas for improvement or something Sekurno could have done differently?
A minor area for improvement would be in communication during the testing phase. Providing a more proactive and frequent update on the progress, perhaps through brief emails, would enhance the overall client experience, especially when working under tight deadlines. This would offer reassurance and a clearer view of the project timeline, ensuring that clients are continually informed about the stages of testing and any developments.
Overall rating: 5
Quality: 5
Cost: 5
Schedule: 5
Willing to refer: 5
RATINGS
-
Quality
4.5Service & Deliverables
-
Schedule
5.0On time / deadlines
-
Cost
4.5Value / within estimates
-
Willing to Refer
5.0NPS