PentestOps
  • Home
  • Solutions
    Solutions
    Enterprise Pentesting Continuous Pentesting AI Pentesting Automated Pentesting Web App Pentesting API Pentesting External Network Testing Internal Network Testing
     
    Cloud Pentesting AWS Pentesting Azure Pentesting GCP Pentesting Kubernetes Security Active Directory Security M365 Security EASM Exposure Management Vulnerability Management Integrations MSP Security Platform
    Industries
    Healthcare Financial Services Government Education Manufacturing Retail and eCommerce All industries All solutions
  • Features
  • Agent
  • Pricing
  • Resources
    Knowledge Centre
    What Is Penetration Testing? Continuous Penetration Testing AI in Penetration Testing PTES Explained OWASP Top 10 NIST SP 800-115 All articles
    More
    Methodology Vendor Comparison Release Notes Open-Source Tools
  • Methodology
  • Comparison
  • About
  • Contact
Login Sign Up Free Demo
Trust Centre

Security & Trust

How Extranet Systems protects your data when you use PentestOps. Last updated: June 2026.

On this page

  • 1. Security posture
  • 2. Compliance & certifications
  • 3. Sub-processors
  • 4. Data residency
  • 5. Responsible disclosure

1. Security posture

Security is built into the PentestOps platform rather than bolted on. The controls below describe how we protect customer data day to day.

Encryption at rest

Customer data is encrypted at rest, and all traffic is protected with TLS in transit.

Per-tenant isolation

Every customer runs in an isolated Kubernetes namespace with its own dedicated database. No shared tenant data store.

RBAC & MFA

Role-based access control limits what each user can do. Multi-factor authentication is available on every account and required for administrators.

Secrets in a vault

Credentials and signing keys are held in a dedicated secrets vault and injected at runtime, never committed to source.

365-day audit logging

Security-relevant actions are recorded in a tamper-evident audit log retained for 365 days.

Self-hosted AI

By default, our AI features run on infrastructure we operate, so your scan data is not sent to third-party large language model providers. External providers can be enabled per tenant at your discretion.

Data retention

Assessment findings are retained for your plan's window (Starter 1 year, Professional 3 years, Enterprise and MSP 7 years) and then automatically deleted. Exported reports, signed authorisation records and legal documents are kept and are never removed by this process, and findings can be placed on legal hold when required. Audit logs are retained for 365 days.

2. Compliance & certifications

PentestOps is built and operated by Extranet Systems Pty Ltd, which holds ISO/IEC 27001:2022 certification. The platform is additionally built to SOC 2-aligned controls.

Our certification status, stated plainly

Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. SOC 2 attestation is on our roadmap. A detailed security overview, including our certificate, is available to customers and prospects on request.

Compliance reporting in the product

The PentestOps reporting engine maps findings to 8 compliance reporting frameworks (OWASP, PCI-DSS, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001 and SMB1001), plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes delivered through cloud and Kubernetes scanning. These reports help you evidence your own compliance posture; they are not a statement of PentestOps' certification.

3. Sub-processors

We deliberately keep this list short. The platform runs on infrastructure Extranet Systems operates in Australia rather than on a third-party public cloud, and the AI runs self-hosted by default, so customer scan data does not leave our environment in normal operation. Each sub-processor below is bound by contract to protect customer data.

Sub-processor Purpose Data involved Location
Stripe Payment processing and billing Billing contact and payment details. No scan or finding data. United States, under Standard Contractual Clauses

Customer-enabled processing

The following is not used by default and only applies if you turn it on for your tenant. We list it here because enabling it changes where your data goes.

Service When it applies Data involved
External AI model provider Only if your organisation chooses to switch PentestOps AI from the default self-hosted model to an external provider. Finding and asset context sent for analysis. While the default self-hosted model is in use, no scan data is sent to any external model provider.

Access by Extranet Systems personnel

Extranet Systems operates across three continents. Authorised personnel in our Bahrain and Egypt offices may access customer data where necessary to operate, support and secure the platform. This is staff access rather than a sub-processor relationship, it is role-based and audit-logged, and it is described in section 4 below and in our Privacy Policy.

We give customers advance notice of any new sub-processor so you have the opportunity to object before it takes effect. Our Data Processing Addendum is on the DPA page.

4. Data residency

The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia and is not replicated to infrastructure outside Australia. Specific data-residency arrangements are available to Enterprise customers on request, so you can align hosting with your own data-residency requirements.

Support access from outside Australia. Extranet Systems operates across three continents, and authorised personnel in our Bahrain and Egypt offices may access customer data where it is necessary to operate, support and secure the platform. That access is role-based, requires multi-factor authentication, and is recorded in the tamper-evident audit log described above. Data continues to be stored in Australia; only authorised remote access occurs. This is disclosed in full in our Privacy Policy, and where personal data originates in the European Economic Area or the United Kingdom we rely on the European Commission's Standard Contractual Clauses. Enterprise customers who require support to be restricted to Australian personnel should raise this during contracting.

5. Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability in PentestOps, please contact us privately so we can investigate and remediate before any public disclosure. Please do not access, modify, or delete data that is not your own while testing.

Report a security issue

Email: security@pentestops.ai

Machine-readable contact: /.well-known/security.txt

Response: We aim to acknowledge reports within 5 business days.

Frequently Asked Questions

What security certification does the company behind PentestOps hold?

PentestOps is built and operated by Extranet Systems Pty Ltd, which is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. A detailed security overview, including a copy of the certificate, is available to customers and prospects on request. You can read more about the company behind the platform on our about page.

What is your SOC 2 status?

The platform is built to SOC 2-aligned controls, and SOC 2 attestation is on our roadmap. We state that plainly rather than implying an attestation we do not yet hold. If your procurement process needs evidence today, the ISO/IEC 27001:2022 certificate and a written control summary are available on request through contact us.

Does the compliance reporting mean PentestOps is certified against those frameworks?

No. The reporting engine maps your findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. Those reports help you evidence your own posture to auditors and customers. They are a product capability, entirely separate from Extranet Systems' corporate ISO/IEC 27001:2022 certification.

How long is my scan data retained?

Assessment findings are retained for your plan's window and then automatically deleted: Starter 1 year, Professional 3 years, and Enterprise and MSP 7 years. Security-relevant actions are recorded in a tamper-evident audit log retained for 365 days. Exported reports, signed authorisation records and legal documents are kept and are never removed by the retention process, and findings can be placed on legal hold when a matter requires it. Plan windows are listed on pricing.

Where is customer data stored?

The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia. Specific data-residency arrangements are available to Enterprise customers on request, so you can align hosting with your own obligations. Our sub-processor list is published in the Trust Centre and currently names Stripe for payment processing and billing; our processor commitments are summarised on the DPA page.

How is my data protected in transit and at rest?

Customer data is encrypted at rest, and all traffic is protected with TLS in transit. Every customer runs in an isolated Kubernetes namespace with its own dedicated database, so there is no shared tenant data store. Role-based access control limits what each user can do, multi-factor authentication is available on every account and required for administrators, and credentials and signing keys are held in a dedicated secrets vault and injected at runtime, never committed to source.

Is my scan data sent to third-party AI providers?

Not by default. PentestOps AI is self-hosted by default, running on infrastructure Extranet Systems operates, so scan data is not sent to third-party large language model providers. External providers can be enabled per tenant at your discretion if you prefer them. The design and the trade-offs are covered on AI penetration testing.

How do I report a security vulnerability in PentestOps?

We welcome reports from security researchers. Contact us privately using the security address published in the Trust Centre or the machine-readable security.txt file, and give us the chance to investigate and remediate before any public disclosure. We aim to acknowledge reports within 5 business days. Please do not access, modify or delete data that is not your own while testing.

PentestOps

Enterprise-grade penetration testing platform by Extranet Systems. Secure your digital assets with advanced security assessments and comprehensive vulnerability testing.

pentestops.com

+61 1300 290 196

info@pentestops.ai

Product

  • Features
  • On-Prem Agent
  • Pricing
  • Comparison
  • API

Solutions

  • Enterprise Pentesting
  • Continuous Pentesting
  • AI Pentesting
  • Automated Pentesting
  • Web App Pentesting
  • API Pentesting
  • All Solutions
  • By Industry

Resources

  • Knowledge Centre
  • Sample Report
  • Methodology
  • PentestOps vs Pentera
  • PentestOps vs Horizon3.ai NodeZero
  • PentestOps vs Cobalt
  • Release Notes
  • Open-Source Tools
  • Support

Company

  • About Us
  • Careers
  • Contact
  • Partners

Legal

  • Privacy Policy
  • Terms of Use
  • Trust Centre
  • DPA
  • Free Demo Scan
Penetration testing across: Australia Sydney Melbourne Brisbane Canberra New Zealand

© 2026 Extranet Systems Pty Ltd (ABN 29 632 743 189), Wollongong NSW, Australia. All rights reserved. | PentestOps is a security platform operated by Extranet Systems.