Penetration Testing and Security Assurance
Purpose
This page describes how DefectDojo, Inc. validates the security of the DefectDojo platform, how test results are shared, and the rules that apply to security testing performed by customers.
Independent Penetration Testing
DefectDojo engages an independent third party to perform penetration testing of the DefectDojo platform. This testing is reperformed at least once per year, and findings are triaged and remediated in accordance with our Vulnerability Management Policy.
The most recent penetration test report is available to customers and prospective customers under a non-disclosure agreement. To request the report, contact your account team or email hello@defectdojo.com.
Customer Penetration Testing
Direct penetration testing of DefectDojo production environments is not permitted. This restriction protects the availability and integrity of the service for all customers.
Customers with a requirement to perform their own penetration testing may contact us to discuss testing against a non-production environment. These arrangements are considered on a case-by-case basis and require prior written agreement covering scope, timing, and rules of engagement.
This page applies to environments operated by DefectDojo, Inc. Customers who self-host DefectDojo within their own infrastructure may test their own deployments at their discretion.
Security Testing in Development
Every pull request is put through automated security scanning and testing before it is merged. Production environments are also scanned for vulnerabilities on an ongoing basis as described in our Vulnerability Management Policy.
Certifications
DefectDojo maintains a SOC 2 Type 2 attestation. The report is available under a non-disclosure agreement on request.
Relevant Documents
- Vulnerability Management Policy
- Change Management Policy
- Information Security Policy