Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> When you get audited by potential customer, it usually involves not having code access and trying to penetrate the app without that access.

Is this in reference to on-prem / enterprise software and is this typical? I haven't heard of customers doing this but it certainly makes sense (might as well invest thousands to test before spending magnitudes more on the product itself only to find it having a huge security hole). Then again I'm not sure I've worked with potential customers who have access to do something like that.



We just signed a big deal with a Google subsidiary, and part of that deal required us to go through a third party penetration test (no code access).


Well today I learned. Thanks!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: