zetVisions AMI in the hosting context tested again without critical vulnerabilities

11.08.2025
News
An article by:
Kerstin Heck

In May 2025, our AMI web application in the hosting environment was subjected to a comprehensive penetration test (pentest) for the second time in a row - carried out by our experienced IT security partner MindBytes. The aim was to once again put the security of our application in the hosting environment to the test and identify potential vulnerabilities at an early stage.

"The pentest is a central component of our security concept and therefore also of our responsibility towards our customers. Especially since the introduction of access to zetVision's AMI via a public URL with 2-factor authentication, we have placed particular emphasis on the highest security standards," says Thorsten Deuter, Head of AMI Development & Support.

What is a pentest?

A pentest uncovers potential attacks on IT systems. By uncovering vulnerabilities, the existing security level can be assessed. By using independent experts such as MindBytes, we can have the robustness of our systems objectively assessed.

What was tested?

Special attention was paid to:

  • the security of the public access interface,
  • the implementation and effectiveness of 2-factor authentication,
  • Robustness against cross-site scripting
  • Security of the web server configuration
  • Security of application data
  • Protection of user data and accounts


"Our testing methodology is based on recognized standards such as the OWASP Testing Guide. We discussed worst-case scenarios in advance. We were unable to achieve any of them, such as unauthorized access to data."
Nina Wagner, Managing Director, MindBytes GmbH

Result

The pleasing result: the pentest revealed no significant security gaps. The security measures we have taken, particularly with regard to authentication, access protection and hardening of the application infrastructure, have proven to be effective. Any vulnerabilities found in non-critical areas were dealt with immediately by the development team and IT.

In the next test cycle, the findings are put to the test again to determine whether the weak points have been closed. "We have thoroughly tested the AMI environment and have not identified any critical vulnerabilities. The security measures implemented are in line with current best practices and show that security is actively practiced here."
Nina Wagner, Managing Director, MindBytes GmbH

Nina Wagner, Managing Director, MindBytes GmbH

IT security as a continuous process

The successful completion of this pentest underlines our commitment to data security and reliability. At the same time, we do not see security as a one-off project, but as an ongoing process. Regular tests like this are an integral part of our quality and security promise to our customers.

About MindBytes
MindBytes is a specialized provider of IT security services with a focus on pentesting and red teaming. Through a hands-on, risk-based approach, MindBytes helps organizations secure their IT systems against real-world threats.(www.mindbytes.de)

Webinars

Get to know our data management solutions

In our 30-minute webinars, you will learn about our solutions for your investment and master data management - compact, interactive and free of charge.

And this is how it works: Choose a date that suits you. Please register at least two days before the respective date. We will then send you all the information and links you need to take part.

What makes us special

We are data experts

We are specialists in data management - and data experts with a passion. For more than twenty years, we have been creating added value for companies of all sizes and industries with excellent data management solutions.

30/09/2025
News
With zetVisions AMI Basic, zetVisions GmbH is launching a new solution on the market that makes legal entity management easier, faster and more efficient than ever before. The software is aimed at companies with up to 100 holdings and manageable requirements - a market segment with great potential.
16/09/2025
legal entity management
The more complex corporate structures become through investments, the more important effective investment controlling becomes. This is because transparency is the best basis for recognizing risks in good time and leveraging potential.
13/06/2025
News
Following our successful certification last year, we have now reached the next milestone: we have successfully passed the transition audit and are now officially certified in accordance with the current ISO/IEC 27001:2022 standard.
26/05/2025
News
Through integration with SAP S/4HANA Enterprise Management, SAP Business Technology Platform, SAP Build Work Zone, SAP ERP and SAP S/4HANA Cloud Private Edition, the zetVisions CIM solution from zetVisions GmbH offers customers a software solution for participation management.
15/05/2025
Master data management
Data management ensures clean master and reference data that is seamlessly integrated internally into methodologies, processes, workflows and platforms.
15/05/2025
Master data management
Data quality management is essential for a constantly up-to-date and reliable master data basis for the entire company.

Get in touch with us

* Mandatory field

This field is used for validation and should not be changed.

Register for the event now

* Mandatory field

This field is used for validation and should not be changed.
Select date*

Register for the event now

* Mandatory field

This field is used for validation and should not be changed.
Select date*

Register for the event now

* Mandatory field

This field is used for validation and should not be changed.