PENTEST OF WEBSITES & WEB APPLICATIONS

Detect and fix vulnerabilities before hackers do.

A one-time audit tells you where you stood yesterday. Patrowl continuously tests the security of your websites and web applications and alerts you only on what is actually exploitable, today.

Over 100 clients, including CAC 40 companies

  • heetch
  • heetch
  • heetch
  • heetch
  • heetch
  • heetch

A solution built by certified pentesters and recognised by cybersecurity experts.

USE CASES

The right test, at the right time

SECURE

All your websites and applications

at once Patrowl tests them simultaneously from a single place, without requiring you to define the scope.

VERIFY

Every deployment creates new vulnerabilitie

Patrowl detects them automatically within hours of your production release.

PREPARE

For your security audits

Patrowl automatically generates a dated and signed pentest report, ready to share with your auditors.

RESPOND

Your clients are requesting a recent pentest.

Patrowl provides it continuously. The report is available at any time, without waiting for a one-off engagement.

MONITOR

Your site changes every week

Patrowl tracks every change and automatically tests new exposed surfaces, 24/7.

INTEGRATE

New entities or subsidiaries with no blind spots.

Patrowl maps and tests every entity from day one, including acquisitions and mergers.

HOW IT WORKS

From discovery to remediation

  • 1-Discovery

    We map everything you expose on the Internet


    Patrowl inventories all your exposed assets without requiring you to define the scope. Forgotten or unlisted assets are included from the first scan.

    • Websites, subdomains and APIs

    • Staging and test environments

    • Subsidiaries and acquired entities

    • Third-party services exposed on the Internet

  • 2-Vulnerability Detection

    We test your sites the way a hacker would — continuously


    Patrowl combines automated black-box attacks with manual testing on authenticated areas. Any vulnerability exploited in the wild is tested against your assets within the hour.

    • SQL injections, XSS, authentication bypasses

    • Privilege escalations and misconfigurations

    • Automated black box + manual grey box by certified pentesters

    • Critical CVEs tested as soon as they are published

  • 3-Prioritisation

    We tell you what to fix first — and why


    Every vulnerability is manually validated before being reported to you — zero false positives. Your teams receive a prioritised remediation plan based on real risk level, not raw technical scores.

    • Detailed report with reproduction steps

    • Prioritisation by business impact, not just CVSS

    • Ticket automatically created in Jira, ServiceNow or your ITSM

    • Remediation plan delivered within 48 hours

  • 4-Continuous Monitoring

    We verify that every fix is properly applied


    compliant with NIS2, ISO 27001, and CSRB guidelines After remediation, Patrowl automatically retests and confirms the closure of each vulnerability. The attestation is generated for your auditors — available at any time, without waiting for a new engagement.

    • Automated retest after each fix

    • Dated and signed closure attestation

    • Report ready to share with your NIS2, ISO 27001, CSRB auditors

    • Centralised view to manage your entire perimeter

WHY PATROWL

Built for the most demanding environments

  • 1M+

    assets under continuous pentest

  • Continuous 24/7

    not a snapshot frozen in time

  • Live in 30 minutes

    no agent, no configuration

  • 48h

    to receive your first prioritised remediation plan

  • −40%

    cost vs a traditional one-off audit

TESTIMONIALS

What our clients say

  • “Traditional penetration tests have one major drawback: they are outdated the day after the report is delivered. Continuous pentesting is perfectly aligned with the extreme pace of change in today's enterprise IT environments”

    MGEN
    National mutual insurance
  • “Patrowl has changed the way we manage security. No more one-off tests: our engineers continuously receive verified results they can act on immediately.”

    Xplor
    International SaaS publisher
  • “We received the preventive notification at 3:57 PM and, by 4:36 PM, an alert had been triggered within Brest Métropole. Thank you for the quality of your active monitoring and the reliability of your support”

    Brest Métropole
    Local authority

GARTNER® MARKET GUIDE 2026 Patrowl

Patrowl, "Representative Vendor" Gartner® 2026

Patrowl has just been named a "Representative Vendor" in the Gartner® Market Guide 2026 for preemptive exposure management.

A recognition by the world's most influential analyst firm that the continuous and validated approach we apply to penetration testing has become the new market standard.

Our pentesting certifications

Our experts are certified to the highest standards in offensive security.

BOOK A MEETING

Discover your vulnerabilities before hackers do

Patrowl Platform

FAQ

What is the difference between a web security audit and Patrowl's pentest?

A one-time audit tests your site at a fixed date. The day after a production release, new vulnerabilities may appear and go undetected for months. Patrowl tests continuously: every change to your site automatically triggers new offensive tests across your entire perimeter.

What types of vulnerabilities does Patrowl detect on my sites?

SQL injections, XSS, authentication bypasses, session management flaws, OWASP vulnerabilities, CVEs on your CMS and libraries, sensitive data exposure, access control errors — and the logic flaws specific to your application that only a manual pentester can uncover.

Do the tests impact production?

No. Patrowl performs no load testing, DoS or DDoS. Scan throughput is controlled and can be restricted to specific time windows. Tests are conducted from fixed, known IP addresses shared with your teams. If a vulnerability is too risky to test automatically, a human operator steps in to perform controlled testing. No destructive tests are carried out.

How much does a web pentest with Patrowl cost?

A traditional one-off web pentest costs tens of thousands of pounds per engagement, with no follow-up or retest. Patrowl operates on a subscription model, with volume discounts based on the number of sites covered. In practice: 30 to 50% cheaper than a traditional audit, for protection that never stops.

Can alerts and reports be customised?

Yes. Reports are customisable by site or asset group. Results integrate directly into Jira, ServiceNow, SIEM, ITSM and SOAR platforms to feed your existing remediation workflows.