Penetration Testing Services Cloud Pentesting Penetration Network Pentesting Application Pentesting Web Application Pentesting Social Engineering October 8, 2026 On this page PTaaS Case Study: Why Softdocs Chose BreachLock Softdocs replaced its annual, point-in-time pentest with BreachLock Penetration Testing as a Service (PTaaS) and now gets the vulnerability findings its previous pentests never surfaced and continuous visibility into its security posture. In a recent testimonial, the Softdocs team explained what changed after the switch, from deeper scoping to results developers can easily understand and fix without extra training. “The depth that BreachLock went was above and beyond our expectations, and we truly appreciate that.” – Terri McKinney, Director of Operations and Compliance, Softdocs Security That Goes Beyond the Compliance Checkbox When more than 1,000 universities, school districts, government agencies, and utilities companies trust you to digitize their paper processes, a passing pentest report isn’t enough. You need to know your controls actually hold. Softdocs has always had annual SOC 2 penetration testing done by a third-party as part of its SOC 2 compliance program. However, the team found that its past one-time pentests confirmed security measures were in place without digging into underlying vulnerabilities thoroughly. In some cases, Softdocs was finding more issues on its own that its third-party penetration testing vendor missed. The team wanted a partner that would go deeper and stay engaged, not a vendor that delivered a report and moved on. “We don’t want just a checkbox for compliance. We want to actually create a secure product.” – Stephen Lowder, Security Architect, Softdocs Why Softdocs Chose BreachLock Softdocs wanted pentesting that was flexible and ongoing, with results its engineers could fix rather than file away. BreachLock PTaaS delivered on four things that mattered most. 1. Scoping built around the application: BreachLock took the time to understand the Softdocs application before testing started, so the engagement covered everything that mattered. The team shared that unlike past engagements, the team didn’t have to rush every target into a two-week window before a report landed. 2. Testing that goes layer by layer: When Softdocs security controls held, BreachLock communicated that clearly. Then, the two teams worked together to open that defense layer so testing could continue into the next one. Softdocs got proof that its controls work and visibility into what sits behind them –– something they had not been getting with their previous vendor. “They’re clearly communicating, ‘We’ve confirmed we can’t get to X, Y, or Z. Can you now open that defense layer, and let’s go to the next layer.’” – Cameron Armistead, Cloud & Information Security Manager, Softdocs 3. Findings developers can act on without training: Softdocs application security team previously relied on DAST tooling that took a lot of effort to configure, run in the pipeline, and translate results into something developers could easily read and act on. With BreachLock, the team schedules a scan and gets clear findings with severity ratings and detailed explanations, which flow straight into its task management system. The team at Softdocs shared that with BreachLock, developers can now easily spot false positives quickly and move on to real fixes. “I don’t have to train devs how to read the results from BreachLock. They can see what the problem is, click on it, and get the severity and a detailed explanation of why it’s a vulnerability.” – Stephen Lowder, Security Architect, Softdocs 4. Enterprise-level security without a large team: Softdocs has a relatively small in-house security team. BreachLock gives the team enterprise-level testing and a clear path to remediation without needing dedicated staff to configure and manage tools. From an Annual Pentest to an Ongoing Partnership Softdocs’ move to BreachLock shows what penetration testing looks like when it’s built for how software teams actually work: Continuous coverage, not point-in-time Collaborative Built for impactful remediation The BreachLock team works with Softdocs through its own Microsoft Teams channel and meets with the team monthly, something a one-time pentest never offered. The reporting also changed conversations inside the company. Softdocs used BreachLock findings to make the case for security fixes that leadership hadn’t previously prioritized, moving work forward that would otherwise have taken much longer. Today the team has confidence in its security posture and a clear plan for the issues BreachLock identified. “With BreachLock, we had enough ammunition to advocate for change that otherwise would have been really slow to complete.” – Cameron Armistead, Cloud & Information Security Manager, Softdocs Watch the full Softdocs testimonial: See how BreachLock PTaaS can turn your annual pentest into an ongoing program. Talk to an offensive security expert today. Author BreachLock Labs Industry recognitions we have earned Tell us about your requirements and we will respond within 24 hours. Fill out the form below to let us know your requirements. We will contact you to determine if BreachLock is right for your business or organization.