How often are penetration tests conducted?
amaise commissions annual third-party penetration testing, conducted in Q4 and aligned to our ISO 27001 and SOC 2 certification cycle. These tests are performed by independent external firms.
In addition to the annual third-party tests, the security program includes:
Quarterly internal security audits — review of architecture, access controls, and configurations
Continuous external and internal scans — periodic application and infrastructure scans via the compliance platform
Automated vulnerability scans — with every build in the CI/CD pipeline (static code analysis, dependency checks, secret scanning)
Threat detection — continuous monitoring by cloud-native security services
Penetration test reports — including full findings, not just management summaries — are available to customers under NDA upon request.