Skip to content
Find my data room
Data room terms / Security and compliance

Penetration testing

The short version

A hired security team tries to break into the platform with the owner's permission, then reports the holes it found so they can be closed. Often shortened to pen test.

How it plays out on a deal

Regular penetration tests are standard practice for serious software vendors and often a requirement of their own audits. Frequency, independence of the testers and how quickly findings are fixed are what separate a meaningful program from a box-ticking one.

Vendors rarely share full reports, but many will provide a summary letter from the testing firm under NDA. Some also run a public bug bounty or vulnerability disclosure program, which is a good sign of openness about security.

What to check in a review or demo

  1. 1How often outside penetration tests are run, and when the last one took place.
  2. 2Whether a summary letter from the testing firm is available under NDA.
  3. 3Whether the provider publishes a vulnerability disclosure policy.

Read alongside

Where this comes up on Data Room Review