Knowledge Article
How often do you perform penetration testing?
Author
cloud_product
SailPoint
SailPoint engages a third-party penetration test firm to test its SaaS services twice a year. The penetration tests are grey and white-box tests in which the pen testers are given product documentation, application user credentials, and, in some cases, source code. Pen testers are provided admin level credentials to the application being tested to mimic vertical movement into the application layer, which also allows configuration and application review. The pen test company has admin access to the application but is encouraged to test the applicable infrastructure while uncredentialled or while authenticated via the application.
SailPoint will share the most recent penetration test executive summary and remediation report with current customers of the SaaS service. To receive a copy of a penetration test report, please email securityassessments@sailpoint.com.