In conjunction with

CREST-Certified Continuous Penetration Testing Delivered as a Platform

Capture The Bug runs a penetration-testing-as-a-service platform built for SaaS engineering teams that want security testing on a sprint cadence rather than a once-a-year audit. Founded by Ankita Dhakar and headquartered in Hamilton, New Zealand, the company grew out of an earlier security consultancy before launching the platform commercially in 2024. Its customer base spans New Zealand, Australia, the United States and India, and includes EROAD, LawVu, PaySauce, Parkable, Whip Around and Blackpearl Group.

Engagements begin in the dashboard, where teams define scope across web applications, APIs, mobile builds, cloud accounts or internal networks, after which CREST-certified testers typically start within 48 to 72 hours. Findings surface live as they are discovered, each one manually reproduced and verified before it reaches the customer, and route into Jira, Slack and GitHub. Customers message the assigned tester through a dedicated channel, request free retests for 90 days, and export audit-ready reports.

Positioning rests on human-led testing rather than scanner output, with the platform layer supplying visibility, workflow and evidence instead of a PDF delivered weeks after fieldwork ends. Coverage spans OWASP ASVS-aligned web testing, MASVS mobile work, OWASP API Top 10 assessments, cloud attack-path review across AWS, GCP and Azure, network and Active Directory testing, and adversarial testing of LLM applications. The company is a founding signatory of the CREST AI Charter and holds SOC 2 Type II and ISO 27001.

Market Segments:

Penetration TestingOffensive Security

Categories:

AS - Bugs