<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Success Stories on ZAP</title>
    <link>/success/</link>
    <description>Recent content in Success Stories on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 07 May 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="/success/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Jit</title>
      <link>/success/jit/</link>
      <pubDate>Fri, 24 Feb 2023 00:00:00 +0000</pubDate>
      <guid>/success/jit/</guid>
      <description>&lt;p&gt;ZAP has changed the adoption of security across the industry, enabling any organization to have better web application security through open source tooling.  That is why after research and benchmarking Jit selected ZAP to be a critical tool in its &lt;a href=&#34;https://www.jit.io/&#34;&gt;DevSecOps orchestration platform&lt;/a&gt;.  As a best of breed OSS DAST tool (dynamic application security testing), it provides development teams with the confidence in their application and API security, enabling them to deploy code at the velocity modern engineering organizations require.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mozilla</title>
      <link>/success/mozilla/</link>
      <pubDate>Wed, 14 Apr 2021 00:00:00 +0000</pubDate>
      <guid>/success/mozilla/</guid>
      <description>&lt;p&gt;ZAP is integral to how Mozilla secures the services powering core Firefox features including Accounts, Addons, and Sync for millions of individuals around the world. We support the  open source development of ZAP, because it helps us ensure the security and privacy of our users keeping the Internet a global, public resource open and accessible to all.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SkypLabs</title>
      <link>/success/skyplabs/</link>
      <pubDate>Wed, 07 May 2025 00:00:00 +0000</pubDate>
      <guid>/success/skyplabs/</guid>
      <description>&lt;p&gt;SkypLabs is an Ireland-based company providing a wide range of IT services&#xA;globally, including security reviews and penetration testing. Created in 2021,&#xA;we have since worked with many different organisations to help them build and&#xA;secure their work.&lt;/p&gt;&#xA;&lt;p&gt;ZAP is our main tool when conducting web application penetration tests,&#xA;and we also use it when analysing the web trafic of desktop and mobile&#xA;applications. Besides its versatility and &lt;a href=&#34;/docs/burp-to-zap-feature-map/#burp-missing-features&#34; title=&#34;Burp Missing Features - ZAP Documentation&#34;&gt;unique features compared to&#xA;competitors&lt;/a&gt;, as being a company focusing on open-source&#xA;and user-respecting software, we love being able to contribute to projects&#xA;that share our values. We have, for instance, added the possibility to &lt;a href=&#34;/blog/2023-09-08-ds-store-parsing/&#34; title=&#34;Parsing .DS_Store files with ZAP - The ZAP Blog&#34;&gt;probe&#xA;and parse &lt;code&gt;.DS_Store&lt;/code&gt; files&lt;/a&gt; to automatically discover new&#xA;resources on a website with &lt;a href=&#34;/docs/team/kingthorin/&#34; title=&#34;Rick Mitchell - ZAP Team&#34;&gt;kingthorin&lt;/a&gt;&amp;rsquo;s help, and the ability of&#xA;searching into notes (that we use a lot during security engagements).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Possible Security</title>
      <link>/success/possiblesecurity/</link>
      <pubDate>Wed, 30 Apr 2025 00:00:00 +0000</pubDate>
      <guid>/success/possiblesecurity/</guid>
      <description>&lt;p&gt;At Possible Security, we deliver specialized, expert-driven cybersecurity services to high-profile clients across industries. Our focus areas include penetration testing, red teaming, premium audits, and consulting. Based in Riga – the capital of Latvia and the jewel of Northern Europe – we are one of the few market leaders in the field – serving government institutions, critical infrastructure providers, and private sector clients with complex security needs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lombiq</title>
      <link>/success/lombiq/</link>
      <pubDate>Wed, 06 Dec 2023 00:00:00 +0000</pubDate>
      <guid>/success/lombiq/</guid>
      <description>&lt;p&gt;ZAP now automatically scans our ASP.NET Core apps for each code change, and we couldn&amp;rsquo;t be happier with it.&lt;/p&gt;&#xA;&lt;p&gt;We at &lt;a href=&#34;https://lombiq.com/&#34;&gt;Lombiq&lt;/a&gt; provide development, training, hosting, and consulting services for open source .NET-based technologies like the ASP.NET Core web CMS and framework &lt;a href=&#34;https://orchardcore.net/&#34;&gt;Orchard Core&lt;/a&gt;. Our clients include Live Nation Clubs and Theaters, the Smithsonian Institution, and Microsoft itself.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Clue Security Services AG</title>
      <link>/success/clue/</link>
      <pubDate>Wed, 21 Jun 2023 00:00:00 +0000</pubDate>
      <guid>/success/clue/</guid>
      <description>&lt;p&gt;The ZAP tool is a significant asset to &lt;a href=&#34;https://clue.ch/&#34;&gt;Clue&lt;/a&gt;, as it is utilized on a daily basis by our security engineers. For the efficient design of a resilient WAF security policy, it is vital to reverse engineer the data flow of an application. ZAP offers an easy way to make the data flow transparent, to visualize the attack surface, and to develop tailor-made policies to minimize it. ZAP is also regularly used in application security consulting. Whether it is to develop and demonstrate a proof of concept for a found code vulnerability, to test an implemented application security function or just to have a function report which is used for threat modeling of an existing function. It is a pleasure to work with ZAP, which we use as a multi-tool for a variety of tasks related to application security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Codific</title>
      <link>/success/codific/</link>
      <pubDate>Wed, 05 Jan 2022 00:00:00 +0000</pubDate>
      <guid>/success/codific/</guid>
      <description>&lt;p&gt;Codific is a developer of secure collaboration tools in Ed Tech, MedTech and HR Tech. Our team of software engineers leverages privacy by design and security by design principles to maximize the security of the applications and the privacy of its users.&lt;/p&gt;&#xA;&lt;p&gt;Codific leverages a security assurance programme for all product development lifecycle. There are many Application Security programmes out there with &lt;a href=&#34;https://codific.com/software-security-with-sammy/&#34;&gt;OWASP SAMM&lt;/a&gt; being by far the simplest of them. SAMM consists of 15 security practices with Secure Deployment and Security Testing amongst them. Both security practices in their higher maturity levels require the use of a dynamic application security testing (DAST) integrated in the CI/CD pipeline. After a time-boxed research into a number of DAST tools we have selected ZAP as our weapon of choice.&lt;/p&gt;</description>
    </item>
    <item>
      <title>we45 and AppSecEngineer</title>
      <link>/success/we45/</link>
      <pubDate>Wed, 11 Aug 2021 00:00:00 +0000</pubDate>
      <guid>/success/we45/</guid>
      <description>&lt;p&gt;We at we45 and our training venture, AppSecEngineer use and train on ZAP extensively. We strongly believe ZAP to be the most programmable DAST tool in its class, regardless of commercial or OSS alternatives.&lt;/p&gt;&#xA;&lt;p&gt;One of the things we do with our clients is to implement continuous DAST scanning as part of their DevSecOps initiatives. Many of our clients run a bevy of automated scans on a periodic basis, triggered through CI tooling with ZAP as the tool. For some of those that have End-to-End Test Automation Scripts with Selenium, Cypress, etc, we set up ZAP to be able to run authenticated, completely automated scanning, which is something we find unique in the DAST space&lt;/p&gt;</description>
    </item>
    <item>
      <title>Orange Business Services</title>
      <link>/success/orange/</link>
      <pubDate>Wed, 21 Jul 2021 00:00:00 +0000</pubDate>
      <guid>/success/orange/</guid>
      <description>&lt;p&gt;At OBS, we strive continually to bring our customers peace of mind with strengthened and reinforced application security.&lt;/p&gt;&#xA;&lt;p&gt;As part of automating our web application and API security, we chose to deploy ZAP as one of our Dynamic Application Security Testing (DAST) technologies. This DevSecOps approach helps our developers and engineering teams to detect vulnerabilities, including the OWASP Top Ten &lt;a href=&#34;https://owasp.org/www-project-top-ten/&#34;&gt;Web&lt;/a&gt; and &lt;a href=&#34;https://owasp.org/www-project-api-security/&#34;&gt;API&lt;/a&gt;, in CI/CD pipelines before releasing our solutions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Banzai Cloud</title>
      <link>/success/banzaicloud/</link>
      <pubDate>Wed, 14 Apr 2021 00:00:00 +0000</pubDate>
      <guid>/success/banzaicloud/</guid>
      <description>&lt;p&gt;At Banzai Cloud we use our dast-operator which leverages ZAP to run baseline scans against the services we deploy on the K8S cluster. This operator deploys ZAP to the K8S cluster and initiates automated security testing for web applications and APIs based on OpenAPI definitions. Besides the operator responsible for starting the scan against a service, it can prevent opening a vulnerable service to outside. The prevention mechanism is based on the built-in admission controller which is watching the ingress resources. The admission controller checks the backend services of the ingress and makes a decision depending on the result of the ZAP scans.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Motorola Solutions</title>
      <link>/success/motorola/</link>
      <pubDate>Wed, 14 Apr 2021 00:00:00 +0000</pubDate>
      <guid>/success/motorola/</guid>
      <description>&lt;p&gt;Motorola Solutions follows S-SDLC (secure software development lifecycle) best practices for&#xA;our product development. Similarly, these best practices can be found in another OWASP&#xA;project, the &lt;a href=&#34;https://owaspsamm.org/&#34;&gt;Software Assurance Maturity Model&lt;/a&gt;. We build our software development approach&#xA;on the OWASP SAMM, to ensure delivery of secure products, from architecture design to the&#xA;deployment in our own or customer’s infrastructure.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
