# HEXBOX — Continuous security validation

Continuous security validation. Evidence, not alerts.

For security and product teams worldwide: validate risks across your applications and APIs, give engineers reproducible evidence, and verify every fix.

HEXBOX serves security and product teams worldwide with remote scoping, reproducible evidence, remediation guidance, and retesting.

## Scope and audience

Web applications, APIs, identities, cloud exposure, and the attack paths connecting them — within an explicitly agreed scope.

Security and engineering teams that need stronger prioritization, reproducible proof, and verified remediation.

## Test. Prove. Fix. Repeat.

### Scope

Together, we agree which assets can be tested, the limits, and when to stop.

What you receive: An agreed testing scope

### Test

Agents look for security weaknesses within your authorized scope.

What you receive: A potential weakness to investigate

### Prove

A finding comes with reproducible evidence so your team can assess the risk.

What you receive: A finding with supporting evidence

### Fix

Your team receives a clear explanation and guidance to correct the issue.

What you receive: A concrete remediation action

### Retest

Test the fix again, then repeat validation as your application changes.

What you receive: A retest result linked to the finding

## Faster. Continuous. More accessible.

### Hours, rather than weeks.

Get initial results in hours on the agreed scope. Your team can start fixing issues sooner.

### Your product changes. Testing keeps up.

A one-off test shows security at one moment. HexBox checks over time and retests vulnerabilities after they are fixed.

### Less manual work. Lower costs.

Automation lowers the cost of repeated checks. Test more often without commissioning a new manual engagement each time.

### Your team. Wherever you build.

Scope your applications and APIs with our team remotely. Share evidence your security and product teams can act on, wherever they work.

## The pentest ends. Your application keeps changing.

When a one-time pentest ends, testing stops. New weaknesses can go unnoticed until the next assessment.

### First assessment

Classic pentest: The engagement ends with a report. Testing stops here.

Hexbox: The report is a starting point. Repeat testing within the agreed scope.

### New release

Classic pentest: New code can introduce new weaknesses. Without another test, they may go unnoticed.

Hexbox: Repeat testing to look for weaknesses introduced by the change.

### Fix deployed

Classic pentest: A fix is deployed. Without a retest, its effectiveness remains unverified.

Hexbox: Replay the attack scenario and document whether the fix works.

### Next change

Classic pentest: More changes arrive. The gap lasts until another test is commissioned.

Hexbox: Repeat the cycle as your application evolves. Keep findings and retests connected.

Comparison of a one-time pentest without follow-up. Hexbox’s testing frequency is agreed within your authorized scope.

## One goal. Two ways to start.

### Security brief

Custom quote in USD

Understand your exposure and decide what to fix first.

- An agreed testing scope
- Evidence-backed, prioritized findings
- Fix guidance and a retest plan

### Continuous validation

Custom quote in USD

Keep testing as your application changes, and verify your fixes.

- Repeated tests within your agreed scope
- Evidence and finding history
- Remediation support and scheduled retests

Before starting: agree the scope, duration, and success criteria together.

## THE FOUNDING TEAM

### Yassine El Jakani

Co-founder & CEO

Vision & product

Email: y.eljakani@hexbox.ma

LinkedIn: https://www.linkedin.com/in/eljakaniyassine/

### Chaimae Zarhane

Co-founder & COO

Execution & operations

Email: c.zarhane@hexbox.ma

LinkedIn: https://www.linkedin.com/in/chaimae-zarhane/

### Mohamed Nadir Rhazi

Co-founder & CTO

Platform & engineering

Email: m.rhazi@hexbox.ma

LinkedIn: https://www.linkedin.com/in/mohamed-nadir-rhazi/

### Moad El Motassadeq

Co-founder & Head of Security & AI

Offensive security & AI

Email: m.elmotassadeq@hexbox.ma

LinkedIn: https://www.linkedin.com/in/moad-el-motassadeq/

## FAQ

### What does HEXBOX validate?

Web applications, APIs, identities, cloud exposure, and the attack paths connecting them — within an explicitly agreed scope.

### Is HEXBOX a vulnerability scanner?

No. Scanners surface possibilities. HEXBOX safely validates whether a path is genuinely exploitable and records the proof.

### How does continuous validation work?

We monitor agreed surfaces, validate meaningful changes, deliver evidence, and retest fixes on a defined cadence.

### How is execution kept safe?

Every engagement uses explicit scope, controls, limits, isolation, and a documented stop process.

### Who is HEXBOX built for?

Security and engineering teams that need stronger prioritization, reproducible proof, and verified remediation.

### Can teams worldwide use HEXBOX?

Yes. Scoping and collaboration happen remotely in English or French. We agree the scope, access, testing cadence, and commercial terms together, with a quote in USD.

## Contact and references

Contact: contact@hexbox.ma

Trust center: https://hexbox-security.com/en/trust

Privacy: https://hexbox-security.com/en/privacy

Business address: 145 avenue Allal Ben Abdellah - Rabat, Morocco

Source: https://hexbox-security.com/en
