How Zick Learn Earned Enterprise Trust Without Hiring an Internal Pentester

Link copied!
Jorge Monteiro

Jorge Monteiro

CEOEthiack

May 28, 2025

Zick Learn is an AI-powered micro-learning platform that delivers training through chat. Its customers are enterprises. Its product handles large volumes of employee data. Its competitive position depends on one thing: being the trustworthy choice.

Matteo, the founder and CEO, understood early that enterprise contracts hinge on security posture, and that posture has to be provable, not promised.

The validation gap Zick Learn could not afford

Enterprise customers ask hard questions. NIS2 compliance is non-negotiable. A single security lapse could end a flagship account and damage the brand for everyone else watching.

But Zick Learn is lean. Hiring an in-house pentester would have meant pulling resources from product. Annual pentests would have meant flying blind for 364 days a year, every release introducing new risk that nobody validated until the next snapshot.

Matteo needed continuous proof of what was exploitable, at startup economics.

Continuous testing, validated exposure, no headcount required

Zick Learn deployed Ethiack's platform to bring its entire stack under continuous attack surface management and autonomous pentesting. Hackian runs against new code and new assets the moment they ship, with under 0.5% false positives and over 20% impactful exploitable findings: the kind of precision that lets a small team act on every finding without drowning.

As the CEO of zick learn, I believe it’s my role to make our company secure, not just today, but also tomorrow and the day after tomorrow. We treat a lot of client data, and protection is part of the product. Ethiack makes it possible for us to offer maximum security on every layer.

Matteo PenzoFounder & CEOzick learn

The result: Zick Learn closes enterprise deals faster, answers security questionnaires with proof, and meets EU regulatory expectations without growing the security team.

Building a startup that has to win enterprise contracts? Talk to us about Ethiack Continuous →

Don’t wait for the attack.

Secure Your Future with Ethiack

Try Ethiack

If you're still unsure convince yourself with a 30-day free trial. No obligation. Just testing.

signup(datetime.now());

def hello(self): print("We are ethical hackers")

class Ethiack: def continuous_vulnerability_discovery(self: Ethiack): self.scan_attack_surface() self.report_all_findings() def proof_of_exploit_validation(self: Ethiack): self.simulate_attack() self.confirm_exploitability() self.validate_impact()

while time.time() < math.inf: ethiack.map_attack_surface() ethiack.discover_vulnerabilities() ethiack.validate_exploits() ethiack.generate_mitigations() ethiack.calculate_risk() ethiack.notify_users() log.success("✓ Iteration complete")

>>> show_testimonials() They found vulnerabilities no one else did. Fast, real, and actionable results. It's like having a red team on call. >>> check_socials()

signup(datetime.now()) meet(ethiack)

def actionable_mitigation_guidance(ethiack): ethiack.generate_mitigation_steps() ethiack.prioritize_fixes() ethiack.support_teams() def attack_surface_management(ethiack): while time.time() < math.inf: ethiack.map_attack_surface() ethiack.monitor_changes() def quantifiable_risk_reduction(ethiack): ethiack.check_risk_metrics() ethiack.calculate_delta() return ethiack.report_real_risk()

Activate AI penTesting

Start a Free 30-day trial
Ethiack — Autonomous Ethical Hacking for continuous security Continuous Attack Surface Management & Testing