Security & Trust
On this page
1. Security posture
Security is built into the PentestOps platform rather than bolted on. The controls below describe how we protect customer data day to day.
Encryption at rest
Customer data is encrypted at rest, and all traffic is protected with TLS in transit.
Per-tenant isolation
Every customer runs in an isolated Kubernetes namespace with its own dedicated database. No shared tenant data store.
RBAC & MFA
Role-based access control limits what each user can do. Multi-factor authentication is available on every account and required for administrators.
Secrets in a vault
Credentials and signing keys are held in a dedicated secrets vault and injected at runtime, never committed to source.
365-day audit logging
Security-relevant actions are recorded in a tamper-evident audit log retained for 365 days.
Self-hosted AI
By default, our AI features run on infrastructure we operate, so your scan data is not sent to third-party large language model providers. External providers can be enabled per tenant at your discretion.
Data retention
Assessment findings are retained for your plan's window (Starter 1 year, Professional 3 years, Enterprise and MSP 7 years) and then automatically deleted. Exported reports, signed authorisation records and legal documents are kept and are never removed by this process, and findings can be placed on legal hold when required. Audit logs are retained for 365 days.
2. Compliance & certifications
PentestOps is built and operated by Extranet Systems Pty Ltd, which holds ISO/IEC 27001:2022 certification. The platform is additionally built to SOC 2-aligned controls.
Our certification status, stated plainly
Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. SOC 2 attestation is on our roadmap. A detailed security overview, including our certificate, is available to customers and prospects on request.
Compliance reporting in the product
The PentestOps reporting engine maps findings to 8 compliance reporting frameworks (OWASP, PCI-DSS, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001 and SMB1001), plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes delivered through cloud and Kubernetes scanning. These reports help you evidence your own compliance posture; they are not a statement of PentestOps' certification.
3. Sub-processors
We deliberately keep this list short. The platform runs on infrastructure Extranet Systems operates in Australia rather than on a third-party public cloud, and the AI runs self-hosted by default, so customer scan data does not leave our environment in normal operation. Each sub-processor below is bound by contract to protect customer data.
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Stripe | Payment processing and billing | Billing contact and payment details. No scan or finding data. | United States, under Standard Contractual Clauses |
Customer-enabled processing
The following is not used by default and only applies if you turn it on for your tenant. We list it here because enabling it changes where your data goes.
| Service | When it applies | Data involved |
|---|---|---|
| External AI model provider | Only if your organisation chooses to switch PentestOps AI from the default self-hosted model to an external provider. | Finding and asset context sent for analysis. While the default self-hosted model is in use, no scan data is sent to any external model provider. |
Access by Extranet Systems personnel
Extranet Systems operates across three continents. Authorised personnel in our Bahrain and Egypt offices may access customer data where necessary to operate, support and secure the platform. This is staff access rather than a sub-processor relationship, it is role-based and audit-logged, and it is described in section 4 below and in our Privacy Policy.
We give customers advance notice of any new sub-processor so you have the opportunity to object before it takes effect. Our Data Processing Addendum is on the DPA page.
4. Data residency
The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia and is not replicated to infrastructure outside Australia. Specific data-residency arrangements are available to Enterprise customers on request, so you can align hosting with your own data-residency requirements.
Support access from outside Australia. Extranet Systems operates across three continents, and authorised personnel in our Bahrain and Egypt offices may access customer data where it is necessary to operate, support and secure the platform. That access is role-based, requires multi-factor authentication, and is recorded in the tamper-evident audit log described above. Data continues to be stored in Australia; only authorised remote access occurs. This is disclosed in full in our Privacy Policy, and where personal data originates in the European Economic Area or the United Kingdom we rely on the European Commission's Standard Contractual Clauses. Enterprise customers who require support to be restricted to Australian personnel should raise this during contracting.
5. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in PentestOps, please contact us privately so we can investigate and remediate before any public disclosure. Please do not access, modify, or delete data that is not your own while testing.
Report a security issue
Email: security@pentestops.ai
Machine-readable contact: /.well-known/security.txt
Response: We aim to acknowledge reports within 5 business days.
Frequently Asked Questions
What security certification does the company behind PentestOps hold?
PentestOps is built and operated by Extranet Systems Pty Ltd, which is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. A detailed security overview, including a copy of the certificate, is available to customers and prospects on request. You can read more about the company behind the platform on our about page.
What is your SOC 2 status?
The platform is built to SOC 2-aligned controls, and SOC 2 attestation is on our roadmap. We state that plainly rather than implying an attestation we do not yet hold. If your procurement process needs evidence today, the ISO/IEC 27001:2022 certificate and a written control summary are available on request through contact us.
Does the compliance reporting mean PentestOps is certified against those frameworks?
No. The reporting engine maps your findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. Those reports help you evidence your own posture to auditors and customers. They are a product capability, entirely separate from Extranet Systems' corporate ISO/IEC 27001:2022 certification.
How long is my scan data retained?
Assessment findings are retained for your plan's window and then automatically deleted: Starter 1 year, Professional 3 years, and Enterprise and MSP 7 years. Security-relevant actions are recorded in a tamper-evident audit log retained for 365 days. Exported reports, signed authorisation records and legal documents are kept and are never removed by the retention process, and findings can be placed on legal hold when a matter requires it. Plan windows are listed on pricing.
Where is customer data stored?
The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia. Specific data-residency arrangements are available to Enterprise customers on request, so you can align hosting with your own obligations. Our sub-processor list is published in the Trust Centre and currently names Stripe for payment processing and billing; our processor commitments are summarised on the DPA page.
How is my data protected in transit and at rest?
Customer data is encrypted at rest, and all traffic is protected with TLS in transit. Every customer runs in an isolated Kubernetes namespace with its own dedicated database, so there is no shared tenant data store. Role-based access control limits what each user can do, multi-factor authentication is available on every account and required for administrators, and credentials and signing keys are held in a dedicated secrets vault and injected at runtime, never committed to source.
Is my scan data sent to third-party AI providers?
Not by default. PentestOps AI is self-hosted by default, running on infrastructure Extranet Systems operates, so scan data is not sent to third-party large language model providers. External providers can be enabled per tenant at your discretion if you prefer them. The design and the trade-offs are covered on AI penetration testing.
How do I report a security vulnerability in PentestOps?
We welcome reports from security researchers. Contact us privately using the security address published in the Trust Centre or the machine-readable security.txt file, and give us the chance to investigate and remediate before any public disclosure. We aim to acknowledge reports within 5 business days. Please do not access, modify or delete data that is not your own while testing.