Skip to main content

Boardroom Answers · Security & Compliance · Security & Cyber Risk

Yes or no: have you had an external penetration test? If not, why should I trust a self-graded exam?

The question a Chief Information Security Officer (CISO) asks.

The short answer

No pen test yet — scheduled Q4 2026 with an accredited firm. Meanwhile CodeQL, weekly ZAP scans, and secret scanning run automatically every week, and you're welcome to attack an evaluation tenant yourself.

The full executive answer

No. We have not yet commissioned an external penetration test, and I won't dress that up. What I can give you is the reason it's a scheduling gap rather than a posture gap: we are pre-launch, and we've sequenced the pen test to land with our first enterprise pilot — targeted Q4 2026 with a CREST-accredited firm — so the report tests the product you'd actually be running, not a build from six months earlier.

On "self-graded exam" — fair challenge, but the grading isn't only ours. Three classes of independent, automated adversaries run continuously: GitHub CodeQL performs static security analysis on every push; a weekly OWASP ZAP scan attacks the running application from outside; and gitleaks scans every commit for leaked secrets. Those are the same tools a pen-test firm uses for the first phase of an engagement, running not once a year but every week, with results retained in CI. Add the structural controls — database-enforced tenant isolation with build-failing CI gates, schema validation on all 414 endpoints, an append-only audit trail — and what's missing is specifically the creative human adversary, which I acknowledge is exactly the part a pen test buys.

Two things I can offer today: first, your security team is welcome to run its own assessment against a dedicated evaluation tenant — several enterprise buyers treat that as stronger evidence than a vendor-supplied PDF anyway. Second, we'll contractually commit to sharing the full pen-test report and remediation plan with you when it completes, and to a defined remediation SLA for any critical finding. If the pen test is a hard gate for your procurement, the honest answer is that our timeline is Q4 2026 and we'd rather lose two quarters than your trust.

Grounded in: SOC 2 TSC CC4.1 (monitoring/evaluations); NIST CSF 2.0 ID.IM-02 (independent testing); OWASP ASVS L2 verification.

Want this answered live, on your data?