External penetration testing

Detect and fix vulnerabilities before hackers do.

Patrowl continuously tests the security of your websites and web applications and alerts you only on what is actually exploitable, today.

Over 100 clients, including CAC 40 companies

A solution built by certified pentesters and recognised by cybersecurity experts.

BOOK A MEETING

Discover your vulnerabilities before hackers do

Patrowl Platform

Launch the right test at the right time

  • Secure

    your sites, apps, and APIs from the start

  • Verify

    existing security or after major changes

  • Prepare

    compliance audits with confidence

  • Respond

    to client or partner security requirements

  • Maintain

    continuous control of critical assets

  • Integrate

    new entities or subsidiaries securely

HOW IT WORKS

From discovery to remediation

  • 1-Discovery

    We map everything you expose on the Internet


    Patrowl inventories all your exposed assets without requiring you to define the scope. Forgotten or unlisted assets are included from the first scan.

    • Websites, subdomains and APIs

    • Staging and test environments

    • Subsidiaries and acquired entities

    • Third-party services exposed on the Internet

  • 2-Vulnerability Detection

    We test your sites the way a hacker would — continuously


    Patrowl combines automated black-box attacks with manual testing on authenticated areas. Any vulnerability exploited in the wild is tested against your assets within the hour.

    • SQL injections, XSS, authentication bypasses

    • Privilege escalations and misconfigurations

    • Automated black box + manual grey box by certified pentesters

    • Critical CVEs tested as soon as they are published

  • 3-Prioritisation

    We tell you what to fix first — and why


    Every vulnerability is manually validated before being reported to you — zero false positives. Your teams receive a prioritised remediation plan based on real risk level, not raw technical scores.

    • Detailed report with reproduction steps

    • Prioritisation by business impact, not just CVSS

    • Ticket automatically created in Jira, ServiceNow or your ITSM

    • Remediation plan delivered within 48 hours

  • 4-Continuous Monitoring

    We verify that every fix is properly applied


    compliant with NIS2, ISO 27001, and CSRB guidelines After remediation, Patrowl automatically retests and confirms the closure of each vulnerability. The attestation is generated for your auditors — available at any time, without waiting for a new engagement.

    • Automated retest after each fix

    • Dated and signed closure attestation

    • Report ready to share with your NIS2, ISO 27001, CSRB auditors

    • Centralised view to manage your entire perimeter

WHY PATROWL

Built for the most demanding environments

  • 1M+

    assets under continuous pentest

  • Continuous 24/7

    not a snapshot frozen in time

  • Live in 30 minutes

    no agent, no configuration

  • 48h

    to receive your first prioritised remediation plan

  • −40%

    cost vs a traditional one-off audit

Testimonials

They took back control of their attack surface.

A solution developed by certified pentesters and recognized by cybersecurity experts.

  • “Our Blue Team was immediately alerted. Notification received at 3:57 PM, alert triggered at 4:36 PM. Thank you for the quality of your active monitoring.”

    Brest Métropole
  • “Instead of dedicating our team's precious time to ad hoc tests, we now continuously receive verified, high-quality results that our engineers can act on immediately.”

    Xplor
  • “Patrowl delivers highly relevant results. The automated monitoring is genuinely appreciated by our teams.”

    Colas
  • “Enhanced security, integrated without friction into our existing workflows. Deployed in 2 days across all our public assets.”

    Heetch
  • “Continuous pentesting is an innovative solution perfectly aligned with the extreme scalability of today's enterprise IT.”

    MGEN
  • “ The use of the Patrowl platform has greatly contributed to improving the monitoring of our assets exposed on the internet. ”

    Arkhineo
  • “We are guided step by step through the process, with a detailed explanation of the alert that was triggered, so that we can understand what is happening and identify which application failed to follow all best practices for a service accessible on the Internet”

    CH Avignon

GARTNER® 2026 MARKET GUIDE

Cited in the "2026 Gartner® Market Guide for Preventive Exposure Management"

Patrowl is featured as a representative vendor in Gartner's 2026 Market Guide for Preventive Exposure Management.

Our pentesting certifications

Our experts are certified to the highest standards in offensive security.

FAQ

What is the difference between a web security audit and Patrowl's pentest?

A one-time audit tests your site at a fixed date. The day after a production release, new vulnerabilities may appear and go undetected for months. Patrowl tests continuously: every change to your site automatically triggers new offensive tests across your entire perimeter.

What types of vulnerabilities does Patrowl detect on my sites?

SQL injections, XSS, authentication bypasses, session management flaws, OWASP vulnerabilities, CVEs on your CMS and libraries, sensitive data exposure, access control errors — and the logic flaws specific to your application that only a manual pentester can uncover.

Do the tests impact production?

No. Patrowl performs no load testing, DoS or DDoS. Scan throughput is controlled and can be restricted to specific time windows. Tests are conducted from fixed, known IP addresses shared with your teams. If a vulnerability is too risky to test automatically, a human operator steps in to perform controlled testing. No destructive tests are carried out.

How much does a web pentest with Patrowl cost?

A traditional one-off web pentest costs tens of thousands of pounds per engagement, with no follow-up or retest. Patrowl operates on a subscription model, with volume discounts based on the number of sites covered. In practice: 30 to 50% cheaper than a traditional audit, for protection that never stops.

Can alerts and reports be customised?

Yes. Reports are customisable by site or asset group. Results integrate directly into Jira, ServiceNow, SIEM, ITSM and SOAR platforms to feed your existing remediation workflows.

START TODAY

Attack yourself before they do.

15 minutes. No slides. A live look at your attack surface and what Patrowl finds that others miss. Pricing adapts to your coverage needs no one-size-fits-all.

13
Overview
Assets
All assets
Asset groups
Technologies
Threats
Qualified vulnerabilities
Risk insights
Trending attacks
CVEs
Remediation plans
Controls
Security checks
Campaigns
Organization
General
Users
Settings
demo
Welcome, 
27KScans
5 940Findings
48Retests
Last 7 days
295
Assets
35
Security checks
36
Active vulns
284
Active risks
Vulnerabilities
See all
Critical 6 vulns
High 2 vulns
Medium 17 vulns
Low 10 vulns
Overdue 17 vulns
Typosquatted domains
See all
ferguson.patrowl.oio Low
On ferguson.patrowl…
Last modification 30/03/2026
johns0n.patrowl.io High
On johnson.patrowl.io
Last modification 22/06/2026
Latest trending attacks
See all
Warning LatePoint
Unauthenticated Authentication Bypass via load_step Function in LatePoint WordPress plugin
Updated on 06/10/2025 15:31:29
Warning
Remote code execution on DrayTek's Vigor routers
Updated on 06/10/2025 15:31:29
c Global Patrowl score
100 80 60 40 20 0 Oct Nov Dec Jan Feb Mar
Latest risk insights
See all
Title Asset Severity Status
Weak ciphersuite on port 443/tcp
moore.patrowl.io
Medium New
Weak protocol on port 8443/tcp
howard-dennis.p…
Medium New
Other dangerous service on port 80/tcp
lee-franklin.patr…
Info New
Database on port 3306/tcp
elliott.henderson…
Critical New
SEG implemented with None
dalton.patrowl.io
Low New