
How Phunware pressure-tested its entire application estate before the audit cycle, not after.

CodeAnt is the most advanced and thorough penetration test we've run to date. It delivered superior results in a fraction of the time of our previous engagements.

Jason Powell
SVP, Engineering & Product, Phunware (Public Company)
Phunware runs the mobile layer for large venues and brands. Indoor mapping, wayfinding, guest engagement, and an AI Concierge product built on top of all of it.
CHALLENGE
A public audit calendar that never stops.
Every product Phunware ships is a web application holding guest data. Hotels, resorts, healthcare systems, Fortune 500 brands. And because Phunware is a public company, there is always another compliance and audit cycle coming, which means the security question is never closed for long.
WHY CODEANT
They asked for depth and speed, which usually means picking one.
Phunware wanted a deep dive penetration test across all of their web applications, and they wanted it fast. Not a document to hand the auditor. They wanted to know where the real problems were while there was still time to fix them before the next cycle.
Traditional engagements make you choose. A multi week window buys you thoroughness. Anything faster buys you a scan.
What we ran
Blackbox test
Full black box coverage across the external application estate. Every finding shipped with a working proof of concept and a fix path attached, so the engineering team could act on it directly rather than triaging a severity label first.
Delivered in days rather than the usual multi week window.
What changed

