Acunetix has helped make our application stronger and given our clients the assurance that their data is safe.
CaterTrax is a catering management software company based in Rochester, New York, offering solutions for non-commercial food service operations. Their web-based software is designed to work as a full platform with solutions for catering, take-out, floor stock, and webstarter. Sensitive customer data is transmitted and stored online, which if stolen by cyber criminals, could result in immense financial repercussions both to the company and clients. Since CaterTrax also handles financial transactions, they maintain PCI Compliance and with a client base of over 2500 companies, security is of extreme importance. CaterTrax chose Acunetix Vulnerability Scanner to for their web application security.
CaterTrax previously used a competing product offered by Qualys but they wanted a product that was more affordable yet was still able to detect a wide range of vulnerabilities. The online version of Acunetix Vulnerability Scanner fit the bill perfectly for its affordability and also because it is more flexible than the on-premises solution which would be restricted to one machine. Acunetix complemented other security tools used by CaterTrax including Imperva ‘SecureSphere web application firewall and Alert Logic Threat Manager.
CaterTrax websites are hosted on IIS servers using a mix of ASP.NET, HTML5, JavaScript, REST and SOAP technologies. With these specific technologies in place, they needed a web application scanner which was equipped to effectively read and crawl their applications. Acunetix was designed with these technologies in mind so it was the obvious choice. As an added bonus, Acunetix is priced far more competitively than other products on the market and is also equipped to scan mobile friendly web applications, which is essential for CaterTrax.
CaterTrax uses a number of the reports provided by Acunetix, including the developer report and the executive summary. Having a developer report is extremely valuable in being able to scan applications throughout their development lifecycle. CaterTrax is also PCI Compliant so being able to run the PCI DSS report designed for this purpose makes maintaining compliance so much easier to do. The report details individual elements of being compliant such as system security parameters, encryption, injection flaws and broken authentication. This helps CaterTrax to prioritize any vulnerability found and to confirm compliance when this report is run and found to be free of any vulnerability.
The company now regularly scans their web applications with the ability to detect a wide range of vulnerabilities, especially those found in the OWASP Top 10 report which include Cross Site Scripting, SQL injection and DOM-based Cross Site Scripting. Being able to easily locate and fix these vulnerabilities means CaterTrax can offer their customers confidence in the security of their products.
CaterTrax is the industry leading online solution developed by hospitality professionals proven to promote, grow, manage, and sustain profitable foodservice businesses. The co-founders of CaterTrax started out with a family-owned catering business where they developed efficient processes for managing large-scale food service operations. These processes became the core of our web-based solutions platform. CaterTrax was created by passionate professionals who understand the realities of managing high volume food and hospitality businesses.
"Having used Acunetix since 2009, we find it an essential tool in protecting our interior critical systems and helping our customers protect their own systems."
Chen Chiu Lin Researcher"The company needed a ‘digital fortress’ to protect the private/personal information and monitor any security vulnerabilities ongoing. Acunetix is instrumental in massively reducing online risk – making sure there are no black holes which could be exploited"
Anthony Sinclair Managing Director"Acunetix is used in a complementary way with other Web Scanners to achieve the best vulnerability detection coverage possible"
Nicolas Pougetoux Manager of the Audit Department