Customer Stories

Learn about customers’ experience with FAZE

About ourCrowd

OurCrowd is a global venture investing and equity crowdfunding platform that connects accredited individual investors, family offices, and institutions with early-stage and growth-stage private companies.

Today, OurCrowd has over 200,000 registered members, has received more than US $2 billion in commitments, and operates offices in the US, UK, Canada, Australia, Spain, Singapore, Brazil, and the UAE.

THE CHALLENGE

Periodic, human-driven penetration testing “was an exercise of little security value,” said Roy Shapira, CISO and Director of Information Technology at OurCrowd.

That concern drove them to seek an automated solution — which led them to FAZE.

THE SOLUTION

As soon as FAZE was implemented, several critical findings were discovered within days. These findings were not previously discovered by human experts or during periodic pentesting.

THE OUTCOME

FAZE has been, in Roy’s words, “a paradigm shift” that has “helped change the mindset of product and development to much shorter fix cycles.

”At the same time, FAZE proved to be highly competitive against the cost of annual penetration tests — and vastly superior to weekly PT runs — and eliminated the need for an in-house T4-level security analyst.”

THE IMPACT

With FAZE enabling short, shift-left fix cycles, it has helped strengthen OurCrowd’s security culture.

The OurCrowd team now conducts a weekly meeting to review FAZE’s findings, optimize and suggest ongoing improvements.

About Cellebrite

Cellebrite is a digital forensics company, providing tools for law enforcement agencies, enterprise companies, and service providers — enabling them to collect, review, analyze, and manage their digital data at scale.

Founded in 1999, Cellebrite is best known for its Universal Forensic Extraction Device (UFED), a tool capable of extracting data from mobile phones that is now widely used by law enforcement agencies worldwide.

THE CHALLENGE

As a digital forensics company operating under security export controls, Cellebrite faces constraints that rule out most security tooling. The team can't open its network for scanning (whitelisting), and regulation means single-factor login is never permitted. Those two requirements alone eliminate most DAST tools before the first scan.

THE SOLUTION

According to Dor Levy, R&D Director of Product Security at Cellebrite, FAZE “Cleared the bar cleanly,” by providing a broker for on-demand access without leaving the network exposed, real SSO/MFA support, and reproducible findings — which let the team confirm actual risk instead of drowning in hundreds of irrelevant alerts.

THE OUTCOME

Once Cellebrite trusted the results, they wired FAZE straight into their pipeline. So that now, every PR merged to a main branch triggers a scan, automatically — with no schedules to babysit.

THE IMPACT

Dor Levy: “What sets FAZE apart, is that it's built by attackers who genuinely know how to get into systems. It also runs inside CI/CD instead of sitting off to the side. And it adapts to how the team works rather than assuming a standard enterprise setup.” Which, Dor notes, “is rare for an environment as constrained as ours — and it's why I’d point other teams working in complex, sensitive environments straight to it.”

About Hippo

Hippo Insurance is an American property insurance company based in San Jose, California, offering homeowners insurance  — covering everything from homes to possessions and liability from accidents on the insured property.

Selling policies directly to customers and through independent insurance brokers, Hippo uses AI and big data to modernize home insurance by aggregating and analyzing property information, and providing accurate quotes for coverage in under 60 seconds.

THE CHALLENGE

Hippo's penetration testing was largely episodic: external firms were engaged on an annual or project-triggered basis, leaving significant time lapses between assessments.

On the application security side, the team relied heavily on a single AppSec engineer to manually triage findings from static and dynamic tooling, with no unified workflow to track remediation across
engineering teams.

THE SOLUTION

“When we evaluated FAZE what differentiated it was the combination of continuous testing coverage with structured, auditor-friendly reporting,” said Shaun Angley, Senior Manager Cybersecurity at Hippo Insurance. “We hadn’t seen [this] from traditional MSSP-style pentest vendors.

”FAZE’s ability to map findings directly to compliance frameworks was also a meaningful factor for a team managing NYDFS, SOC 2, and SOX obligations simultaneously.

THE OUTCOME

FAZE’s continuous pentest coverage replaced episodic assessments, closing the gaps that come with annual or project-triggered testing.

All findings now map directly to the compliance frameworks Hippo operates under, giving the team credible, risk-connected data in place of manual triage

THE IMPACT

Shawn Angley says FAZE’s “continuous pentest coverage has strengthened our position in carrier reinsurance partner reviews, where security posture is increasingly a due diligence criteria.

”It has also contributed to SOC 2 Type II audit readiness, a direct input to enterprise customer trust. internally, the consistent process has made it easier to resource remediation efforts, While also supporting the case to leadership for security investments. as Shawn Angley states, “the data is there, it's credible, and it connects clearly to risk.”

Put FAZE to work

See what FAZE can do for your security.

Schedule a product walkthrough with one of our security experts.

BOOK A DEMO