
Why HockeyStack traded the annual snapshot for a 365 day attack clock

We haven't seen any pentest go this deep. The level CodeAnt gets to is genuinely unprecedented.

Arda Bulut
Co-Founder and CTO, HockeyStack
HockeyStack unifies CRM, ad platforms, product analytics, and sales data into one buyer journey model, and runs AI agents on top of it. Odin for analytics, Nova for sales execution.
CHALLENGE
Customers hand over the full commercial picture of who is buying and why.
That is the most sensitive thing a B2B company owns. HockeyStack's whole value comes from concentrating it in one place, which means the concentration is also the whole risk.
WHY CODEANT
A PDF that is stale by the time it lands does not describe a live platform.
HockeyStack wanted offense on a 365 day clock instead of an annual snapshot, and defense that is actually informed by it. One platform where the attack side proves what is reachable and the defensive side enforces it at the pull request, rather than two vendors producing two lists that never reconcile.
Alongside it: attack surface management across a fast moving platform, shadow IT discovery so nothing ships outside the known perimeter unnoticed, and visibility into leaked credentials and session tokens across their public footprint.
WHAT WE RAN
The full black box engine against the live external estate, and then we left it running. Every finding carries the proof of exploitability, not a severity label.
WHAT CHANGED

