Skip to main content

Can customers conduct their own penetration tests?

Written by amaise Support

Can customers conduct their own penetration tests?

Yes. Customer-initiated penetration tests are allowed under the following conditions:

  • Coordination: Coordination with amaise’s security officers is required.

  • Scope and timing: These are agreed upon together in advance.

  • WAF configuration: The WAF IP allowlist can be configured for penetration test partners so that test traffic is not blocked.

  • Results: amaise is open to discussing and addressing identified vulnerabilities.

Additionally, amaise conducts annual external penetration tests through independent third parties. Summaries of these reports can be provided to customers under NDA.

For reporting vulnerabilities outside of formal penetration tests, the responsible disclosure process is available ([email protected]).

Did this answer your question?