Solid platform, worth investing
I've been using Beagle Security for a couple of weeks and used it on a handful of sites.
PROS:
- The penetration testing seems very deep. I get Wordfence alert of attack every time I run a pen-test.
- Timeline of what has been fixed and what is still outstanding / new vulnerability created a invaluable timeline of the state of the application, something I haven't seen in other products (pen-tests.com)
- The UI is easy and very well designed.
- Scheduling is really helpful, along with login and user input
- Rejah is super responsive and responds extensively to the support question through chat.
CONS:
- Mitigation of vulnerability is very slow and almost impossible as you have to re-run the test again to check if you have indeed fixed the issues. On average the sites we tested took 2 days each test.
This also use an extra test away from your allowance.
Rejah says they are working on a solution for this, which I appreciate - but for what it is now, makes it very hard to work with.
- Reports have BEAGLE SECURITY all over it. This makes it impossible to send the report to the client. I honestly do not understand the reasoning behind not allowing us to add our logo. It can even be "AGENCY NAME" powered by "BEAGLE SECURITY". I am not pretending us to get the kudos for the work of the software, but the work that we do as an agency is as important as the work that Beagle Security does.
To start with, we get the client into the Beagle Security software (eg. that test would never take place if it wasn't for us, professionals, suggesting a pen-test) - and we do all the remediation work. So I really believe the final outcome is a partner between the agency and beagle.
Unfortunately Rajah said white-label is NOT part of the deal. This is really disappointing and potentially a complete deal breaker.
- The vulnerability findings could be more detailed on how to fix - especially indicating if it is an application vulnerability or a server vulnerability. This will allow us to go back to the hosting with the server ones.
I hope this will improve overtime.
All considered I am pleased with the platform, but because I see the potential, I am even more upset about the cons, especially when they are a "policy" and not an application technical limitation.
Hope this helps!
Rejah_BeagleSecurity
May 9, 2024Thanks for the in-depth review, marmeodesign! I'm so glad to hear that you love the timeline view, UI, scheduling feature and our support.
Like I mentioned on chat, our team is looking into partial vulnerability re-runs. White-labelled reports are not part of the deal but powered by "BeagleSecurity" is a good suggestion. We'll definitely consider available options to make the experience better for agencies. Making the vulnerability remediation better is something we're addressing on an ongoing basis. It will definitely improve overtime! :slight_smile: