Let’s talk
Book a demo with our experienced team!
We’ll walk you through how to boost your application’s speed and reduce computational costs.
Stravito is an AI-powered insights platform that helps global enterprises centralize and organize their market and consumer data to drive better, data-informed decisions.
“We’re an AI company with strict security demands and as a SaaS provider, external validation is essential,” says Marcus Södervall, Head of Trust at Stravito.
A different experience from previous penetration tests
Stravito reached out to Cyloq in the summer of 2023 after a client requested a penetration test.
“We’d avoided traditional pentests in the past. Frankly, we never saw much value in the results. Instead, we’ve been running a bug bounty program as our ongoing testing method. But when a customer specifically asked for a formal test, we figured we’d give it a go.”
Marcus admits expectations were low, but the outcome turned out to be more valuable than anticipated.
“We were pleasantly surprised. Cyloq found several issues that hadn’t been caught by previous tests or our bug bounty program. So yeah, we were really happy with the results.”
The process was fast and efficient. Cyloq worked within a defined timeline, delivered a clear report, and outlined practical fixes the team could implement themselves – which they did.
“It was fast, frictionless, and communication was easy. Everyone at Cyloq was great to work with. They were professional and straight to the point. Compared to past penetration tests we’ve done, both the expertise and final report were at a completely different level.”
Red Teaming: Attacking the company on all fronts
After the success of the penetration test, Stravito decided to move forward with a full red teaming operation – a broader simulation where the attacker can come at the company from any angle.
“We told Cyloq what absolutely couldn’t end up in the wrong hands and asked them to go after it, using whatever means they had.”
Just like before, Cyloq kept communication clear, understood the assignment right away, and maintained alignment throughout the engagement. They kept a tight feedback loop during the test and wrapped up with a well-structured report outlining what worked, what didn’t, and what could be improved.
“It took longer and was more comprehensive than a standard test, but it was incredibly valuable. Both for the security team and the entire organization.”
“Everyone should experience a planned attack”
The red teaming exercise led to immediate changes across the business.
“We’ve already made several improvements based on Cyloq’s findings. This partnership has made us better prepared, no doubt about it.”
But the real value wasn’t just technical. The simulation had a tangible impact on awareness across the company.
“It really raised the bar. Our employees now understand how attacks actually play out and what they personally need to pay attention to. If you haven’t gone through a red teaming exercise, you should. Everyone benefits from experiencing what a real-world attack looks like and how people respond.”
One of the key takeaways Marcus emphasizes is how attackers often don’t go through firewalls - they go through people.
“If someone’s going to breach you, chances are they’ll go through an employee. So we have to support our people and give them the tools to maintain good cyber hygiene.”
A long-term partner for Stravito
With two successful projects, Stravito plans to keep working with Cyloq.
“We’ll definitely keep testing with them. We’re also looking at bringing them in to break down the AI features in our platform, and we’ll likely ask them to run a security training session for our developers too.”
Cyloq hasn’t just delivered solid results, they’ve helped raise the security bar for the whole organization. For Marcus, recommending them is a no-brainer:
“Absolutely. They’re straightforward, easy to work with, and they know what they’re doing. Zero fluff, just real results.”