How it plays out on a deal
Regular penetration tests are standard practice for serious software vendors and often a requirement of their own audits. Frequency, independence of the testers and how quickly findings are fixed are what separate a meaningful program from a box-ticking one.
Vendors rarely share full reports, but many will provide a summary letter from the testing firm under NDA. Some also run a public bug bounty or vulnerability disclosure program, which is a good sign of openness about security.
What to check in a review or demo
- 1How often outside penetration tests are run, and when the last one took place.
- 2Whether a summary letter from the testing firm is available under NDA.
- 3Whether the provider publishes a vulnerability disclosure policy.
Read alongside
- SOC 2An attestation from a licensed CPA firm, under AICPA rules, that a software company's security controls are designed well (Type I) or also worked over several months (Type II).
- ISO 27001ISO/IEC 27001 sets out how an organization should run its security program as a managed cycle of risk assessment, controls and review.
- Malware scanningAutomatic checking of uploaded files for viruses and other malicious code before they become available to other users of the room.
- Encryption in transitProtecting data while it moves between a user's device and the provider's servers, normally with TLS, so it cannot be read or altered on the way.