For Auditors
Verifying TurboPentest Evidence
If you're auditing a customer who cited TurboPentest as a third-party penetration testing vendor, this page is for you. It documents what evidence customers receive, what each artifact contains, how to verify the signatory, and how to reach us with audit-specific questions.
Direct line for auditors: [email protected] · Phone: +1 (207) 200-3288
What evidence customers receive
Pentest report
Full PDF report with proof-of-concept exploits, CVSS v3.1 scores, screenshots, remediation guidance, and tool output. One report per pentest.
Attestation letter
Single-page PDF, signed by the IntegSec CEO, suitable for sharing with auditors, customers, and prospects without disclosing finding detail.
Compliance mapping document
Public, versioned. Shows how findings map to SOC 2 TSC, ISO 27001 Annex A, PCI DSS v4.0 Req 11.4.x, and HIPAA. Always links to the same canonical URL. /compliance/methodology →
Pentest methodology (PTES, OWASP Testing Guides, MITRE ATT&CK) is documented separately at /how-it-works (or /methodology/testing for the deep dive).
Attestation letter - what's in it
Every attestation letter contains the following elements. If a customer hands you an attestation that is missing any of these, contact us directly to verify authenticity.
- ✓Date of testing (start date and completion date)
- ✓Scope (target application URL and tested attack surface)
- ✓Pentest methodology reference - PTES + NIST SP 800-115 (overall workflow), OWASP Testing Guides (WSTG, MASTG, API Security Top 10, LLM Top 10, OWASP AI Testing Guide for AI/LLM scopes), MITRE ATT&CK (plus MITRE ATLAS for AI/LLM scopes), OWASP ASVS / MASVS and OWASP Code Review Guide when source code is provided, PCI DSS Penetration Testing Guidance for PCI scopes
- ✓Compliance mapping reference - link to the public, versioned compliance mapping document at /compliance/methodology
- ✓Tools used (industry-standard security tools + Paladin AI agents)
- ✓Findings summary by severity (Critical / High / Medium / Low / Informational counts)
- ✓Compliance framework mapping (PCI DSS v4.0.1, SOC 2 TSC 2017/2022 PoF, ISO 27001:2022, HIPAA, NIST 800-115, OWASP WSTG)
- ✓Signatory and qualifications (Michel Chamberland - CISSP, OSCP, OSCE, CEH, GIAC, CCSK)
- ✓SHA-256 hash of the underlying findings report (for integrity verification)
- ✓Verification URL + QR code (auditor can confirm the report has not been altered post-issue)
Compliance framework mapping
The same pentest evidence supports the following framework requirements. The attestation letter cites all of them by name.
| Framework | Requirement | Note |
|---|---|---|
| PCI DSS v4.0.1 | Requirement 11.4.x | External and internal penetration testing (v4.0.1 June 2024 errata; v3.2.1 11.3.x maps to v4.0 11.4.x). |
| SOC 2 (TSC 2017 w/ 2022 PoF) | Trust Services Criteria CC6.1 + CC6.6, CC7.1 | Direct evidence: logical access (CC6.1), network access boundaries (CC6.6), vulnerability detection (CC7.1). Supports CC4.1 (Monitoring activities) when the testing cadence is documented separately by the customer. |
| ISO 27001:2022 | Annex A controls A.8.8, A.8.29 | A.8.8 (Management of technical vulnerabilities) and A.8.29 (Security testing in development and acceptance). |
| HIPAA Security Rule | § 164.308(a)(8) | Technical evaluation of security controls. |
| NIST SP 800-115 | Technical Guide to Information Security Testing and Assessment | Methodology aligns with the Planning → Discovery → Attack → Reporting four-phase model. |
| OWASP WSTG | Web Security Testing Guide v4.2 | Web app testing checklist coverage. |
Signatory verification
Every TurboPentest attestation letter is signed by Michel Chamberland, CEO of IntegSec. Credentials:
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security at IBM X-Force Red and Trustwave SpiderLabs.
Verify on LinkedIn: linkedin.com/in/michelchamberland
Each attestation also carries a SHA-256 hash of the report - auditors can independently compute the report's hash and compare it to the hash recorded on the attestation letter and at the verification URL to confirm the report has not been altered since issue. The QR code on the attestation links directly to the verification URL.
Independence position
Honest disclosure: TurboPentest is operated by IntegSec, which also pentests TurboPentest itself quarterly. The TurboPentest product is independently developed by the same offensive security team that performs the quarterly pentests.
We disclose this relationship explicitly so auditors can apply appropriate independence judgment. For audits where strict third-party-tester independence is required, customers can supplement the TurboPentest engagement with a managed IntegSec engagement led by a different lead tester, or with a third-party firm entirely.
Sub-processors
Full subprocessor list (data touched, hosting region, link to each DPA): /subprocessors →
For security teams running 100+ targets
Customers running fleet-wide pentest cadences (security teams with 100+ targets, weekly regression coverage, data-sovereignty requirements) often move to Enterprise - a dedicated TurboPentest instance deployed into the customer's own cloud account. TurboPentest engineering operates the instance; the customer pays their cloud and Anthropic infrastructure directly. From an audit-evidence perspective, Enterprise produces the same attestation letters and compliance mapping as per-target pentests - only the deployment topology changes.
Auditors verifying Enterprise-tier evidence: the signatory and methodology fields on the attestation letter are unchanged. The only Enterprise-specific note is that the pentest ran on a dedicated instance inside the customer's cloud environment, which is documented in the engagement scope file.
Retention policy
Pentest reports are retained for the active customer subscription period. After cancellation, customer data (including reports) is retained for 90 days for legal and audit purposes, then deleted.
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Direct line for auditors
Send questions about specific customer evidence, attestation authenticity, our testing methodology, or our compliance mapping to [email protected] or call +1 (207) 200-3288. Auditor inquiries are triaged within 1 business day.
Need a Data Processing Agreement on file? Our public DPA is at /dpa - counter-signed copies available on request. The procurement legal library publishes DPA and Mutual NDA at /legal; additional contracts (MSA, Subscription Agreement, custom paper, on-premises deployment) are available on request via [email protected].