Skip to content

For teams

Security testing for companies, and hardware, software and lab programs for teams, universities and training providers.

Services

Authorized testing and tool programs, scoped before any work starts.

API security

API & backend security testing

We look through backend and API behavior for the common issues that actually matter: SQLi, XSS, headers, leaked info, auth bugs, WAF behavior, and unsafe responses.

Request a quote

What it gets you

  • Catch obvious backend mistakes before users do
  • Find exposed info and over-broad API responses
  • Give developers clear fix notes
  • Improve login, headers, and request handling

Engagement models

Typical engagement: 2–5 business days

  • Quick API check

    A focused pass over important endpoints, login, headers, and obvious bug classes.

  • Full backend pass

    A broader review across endpoints, roles, returned data, and backend behavior.

  • Retest

    A quick follow-up after the company fixes the reported issues.

Full scope and process

What we cover

A backend review focused on each request, what it returns, what headers say, what information leaks, and whether common bug classes are present.

  • Request-by-request review of inputs, responses, and behavior
  • SQL injection and unsafe query handling checks
  • XSS and reflected input checks where API responses feed a frontend
  • Headers, cookies, CORS, and security configuration
  • Login, session, token, and API key handling
  • WAF behavior and whether obvious bad requests are blocked
  • Leaked information in errors, debug output, stack traces, or response bodies
  • Overly broad responses, exposed tables, and APIs returning more data than needed

What your team gets

  • List of tested endpoints and requests
  • Finding report with severity and impact
  • Reproduction notes for anything that looks vulnerable
  • Header and configuration notes
  • Suggested fixes written clearly
  • Optional quick retest after fixes

How it runs

  1. Scope the API

    We agree on the endpoints, test accounts, roles, and actions that are approved for testing.

  2. Review requests

    We look at requests, responses, headers, auth behavior, returned data, and common injection points.

  3. Check common bugs

    We test for common issues like SQLi, XSS, weak headers, leaked info, WAF gaps, and auth mistakes.

  4. Report clearly

    You get clear notes with what was found, why it matters, and how to fix or retest it.

Good fit for

  • SaaS platforms
  • Mobile app backends
  • Internal admin panels
  • Customer portals
  • Webhook-heavy products
  • Teams preparing a new backend release

From first message to a useful outcome

One lightweight process for a website check, a backend or API review, or a hardware and software tool conversation.

  1. 1Align

    Define the company goal, test pages or APIs, accounts, approvals, and anything that is off-limits.

  2. 2Check

    Look through the agreed website, API, or hardware request in a practical and authorized way.

  3. 3Report

    Deliver clear findings, screenshots or request notes, fix guidance, and next steps.

  4. 4Improve

    Support remediation, retesting, or follow-up tool rollout planning where needed.

Education

Education and lab programs

Hardware, software and instructor materials for universities, training providers and internal red teams. Procurement-ready, EU-built, custom-quoted to your scope.

students per kit
30+
quote turnaround
3 days
lock-in
0

Lab packages

Three shapes for the most common cases, each with real ZeroTrace hardware and the software stack you actually use. Custom shapes welcome.

  • Starter Lab

    Single course, small workshop, evaluation cohort.

    5 devices

    Custom quote

    • 5× ZeroTrace Dongle or Kit
    • HID Firmware license per device
    • Companion app, lab guide, written quick-start
    • Commercial-use license: instructor + cohort
    • Email support during the cohort
  • Classroom Lab

    Most common

    Full course, multi-section, training provider.

    15–30 devices

    Custom quote

    • 15–30× ZeroTrace Dongle or Kit devices
    • Full software stack: HID + OSINT + Proxy
    • 12-week curriculum starter pack
    • Commercial-use license per cohort
    • Priority email support, named contact
  • Internal Red Team Pack

    In-house red teams in regulated industries.

    Custom

    Custom quote

    • Mixed devices: AirLeak Pro + Echo + USBLogger
    • Org-wide commercial license
    • Audit-ready license documentation
    • Optional named success contact
    • Multi-year terms available

Honest filter: we sell professional tools and lab programs. If you're looking for managed monitoring or “set-and-forget” security, we're probably not your fit, and happy to point you elsewhere.

For universities

Hardware, software and instructor materials for CS and cybersecurity courses. Quoted on the academic year; one kit runs twelve semesters without per-student licenses.

students per kit
30+
hardware life
6 yr
per-seat fees
0
Everything in a university program
  • Academic-year buying cycle

    Most CS and cybersecurity departments commit budget in May–July for September. We quote on the academic calendar.

  • Repeat-cohort hardware

    Devices stay in the lab; students rotate through. A single 30-device kit serves 60–150 students per academic year.

  • Multi-stakeholder buying

    Department head, faculty, faculty IT and the ethics committee each get the document they need, from one PO.

  • Curriculum-aligned materials

    Lab-plan stubs (12-week HID attack lab, OSINT investigation curriculum, 30-student range scenario) that faculty can adapt.

  • ZeroTrace Dongle or Kit in cohort quantity (typically 15–30 per course)
  • Full software stack: HID Firmware, OSINT toolkit, Proxy, Companion
  • Lab-plan stubs the faculty can adapt to their course
  • Authorized-testing language template for ethics-committee review
  • Commercial-use license: instructor team + per-cohort student use
  • Procurement-ready EULA addendum, single-PO invoice, EU VAT compliant
  • Email support for the instructor; named contact on larger orders

Pricing is custom, sized to device count, software mix and term. Quote turnaround typically 3 business days.

Request a quote

For training providers

Boot camps and professional training companies run cohort after cohort on the same hardware. The kit you bought for January's cohort runs March's, June's, and the one after that.

average cohort
4 wk
cycles run
12/yr
PO needed
1
Everything in a training-provider program
  • Faster decision cycle

    Most quotes close in 4–8 weeks. We quote on your cadence, not the academic year.

  • Volume on hardware, full margin on content

    Volume pricing per device; regular margin on curriculum and instructor support. Each layer priced the way the market buys it.

  • Off-the-shelf curriculum

    Lab-plan stubs (12-week HID attack lab, OSINT investigation curriculum) you adapt to your brand, without locking into our way of teaching.

  • Repeatable kits, not one-offs

    Cohort-ready bundles, pre-configured firmware, instructor onboarding pack, recovery and reset playbook. No per-cohort flashing tax.

  • Cohort-sized device packages (typically 25–80 devices per training company)
  • Full software stack: HID Firmware, OSINT toolkit, Proxy, Companion
  • Lab-plan stubs the senior instructor adapts (HID, OSINT methodology, lab scenarios)
  • Pre-configured firmware variant tuned for cohort-onboarding stability
  • Recovery and reset playbook for between-cohort hardware turnaround
  • Commercial-use license: instructor team + per-cohort students
  • Priority email support, named contact for larger volumes

Volume pricing is sized to cohort cadence and total per-year device count. Quote turnaround typically 3 business days.

Request a quote

Commercial licensing

An annual organizational license that lets your seats use ZeroTrace on paid engagements. Custom-quoted against seat count and term.

  • Team

    Small consultancy or internal red team

    For organizations using ZeroTrace on paid client engagements with a handful of operators.

    • Commercial-use rights for client work
    • Priority email support
    • Procurement-ready invoicing
  • Agency

    Mid-size consultancy or in-house security org

    Adds onboarding, a named contact, and a periodic check-in for teams scaling their use.

    • Everything in Team
    • Onboarding session with a senior operator
    • Named support contact
    • Quarterly product check-in
  • Enterprise

    Larger orgs, MSSPs, regulated industries

    For deployments that need an SLA, security questionnaire support, and audit-ready documentation.

    • Everything in Agency
    • Defined SLA + security questionnaire support
    • Audit-ready license docs
    • Custom seat counts

What every order includes

Procurement, jurisdiction and lead times, ticked before any lab program ships.

  • EU jurisdiction

    Hardware designed, cased and shipped from Germany. Customer operational data never leaves your machine.

  • No-log architecture

    Lab dashboards run on your infrastructure or on the user's machine. Vendor-side telemetry off by default.

  • Procurement-ready

    Line-item invoices, VAT compliant, signed EULA addendum, multi-year terms available.

  • Lead times locked

    Assembly capacity reserved for institutional orders. Phase quoting on 6–8 week lead times.

Questions institutions ask first

Can students take the kit home after the course?

Yes. Devices remain functional forever: there is no kill-switch and no required cloud login. Your institutional commercial license covers classroom use; individual students may buy a personal device separately if they want to use it for paid work.

Do you support ethics committee review?

Yes. We provide an authorized-testing legal language template, a responsible-use policy, and a security & transparency one-pager that institutional ethics committees commonly request.

Is there a pilot option before we commit?

Selected institutions can receive a pilot kit at a substantial discount in exchange for a published case study and instructor feedback. Mention “pilot” in your inquiry to be considered.

Why is there no public price?

Lab pricing is custom. The right number depends on device count, software mix, support term, shipping, and whether you need a tuned firmware variant. Quote turnaround is typically 3 business days.

Contact

Request a quote

Tell us what you want checked or supplied. We reply with a scoped next step, usually within 3 business days.

Or write to us directly:

admin@zerotrace.pw

What to expect

  • No-log policy applies

    Your targets, findings, and test scope are not stored on our infrastructure after delivery. The engagement is yours.

  • Direct developer contact

    You talk to the people who built the tools. No ticket queue, no account managers between you and the work.

  • German data handling

    All work operates under German jurisdiction. GDPR-baseline data practices apply by default.

  • Fixed-scope engagements

    Every engagement has a defined scope and deliverable. No open-ended retainers or surprise scope creep.

What is it about? (required)

Good first message: the target type, a rough timeline, whether you need testing or tools, and any domains, APIs, quantities or seats you already know.

Opens your email app with everything filled in. Nothing is sent from this page.