Security & Vendor Trust Documentation
Doing vendor due diligence? Jump to security documentation ↓
Vendor Security Documentation
Trust Center
Full security documentation lives at trust.integsec.com - Pentest Report, Vulnerability Assessment Report, controls inventory, and framework alignment.
Note: trust.integsec.com is operated by IntegSec, TurboPentest's parent company. The same security program covers both - IntegSec's pentest team builds and tests TurboPentest, and shared security documentation lives in one place.
Compliance frameworks aligned
Our security program maps to CIS Controls 8.1, CMMC, and PCI-DSS. SOC 2 Type II and ISO 27001 audits are on the roadmap.
TurboPentest is pentested by IntegSec
Our parent company runs full pentests against TurboPentest at least quarterly and before every major release. Same elite team that's served IntegSec's clients for years - now testing the product they built. Pentest reports are available on request via the Trust Center.
HIPAA / BAA
Available before any engagement with healthcare customers. No TurboPentest workforce member reviews your data as part of normal operations - automated agents process findings. Talk to our CEO → to start a BAA.
Web hardening
Qualys SSL Labs A+ rating and Security Headers A rating on integsec.com.
Vulnerability disclosure
Found a security issue? Report it through our Bug Bounty Program below or via responsible disclosure on the Trust Center. Standardized contact information is also published at /.well-known/security.txt per RFC 9116.
Trust documents & contacts
- About TurboPentest - legal entity, founder, parent company
- Subprocessors - GDPR Art. 28(2) list with DPAs
- Data Processing Agreement (DPA) - public Article 28 DPA + SCCs (Module Two)
- Legal Library - DPA + Mutual NDA (additional contracts on request)
- For Auditors - attestation, retention, signatory
- Compliance Mapping Document - versioned, public; how findings map to framework controls
- Testing Methodology - PTES + NIST SP 800-115, OWASP Testing Guides, MITRE ATT&CK / ATLAS
Testing follows PTES + NIST SP 800-115, OWASP Testing Guides (WSTG, MASTG, API Security Top 10, LLM Top 10), and MITRE ATT&CK. AI/LLM targets add MITRE ATLAS and the OWASP AI Testing Guide. White-box source-code mode adds OWASP ASVS / MASVS verification levels and the OWASP Code Review Guide. PCI scopes follow the PCI DSS Penetration Testing Guidance. See /methodology/testing for the full breakdown.
Contacts: [email protected] · [email protected] · [email protected] · [email protected]
General procurement: +1 (207) 200-3288
In Scope
- ✓turbopentest.com web application
- ✓API endpoints (turbopentest.com/api)
- ✓Authentication and authorization flows
- ✓Payment and billing logic
- ✓Pentest scheduling and credit management
Out of Scope
- ✗Denial of Service (DoS/DDoS) attacks
- ✗Social engineering or phishing
- ✗Physical security testing
- ✗Third-party services (Stripe, Mailgun, GitHub)
- ✗Pentest infrastructure (Paladin agent)
- ✗Automated pentesting without prior approval
Reward Tiers
Risk Rating Methodology
We use the same methodology to rate findings in our pentests and in our bug bounty program. Severity is based on real-world impact, not theoretical risk.
Critical
CVSS 9.0 - 10.0Full system compromise, mass data breach, or financial loss at scale. Attacker gains unrestricted access or causes organization-wide damage with no or minimal interaction.
- -Remote code execution (RCE) on servers
- -SQL injection with data exfiltration
- -Authentication bypass granting admin access
- -Access to all user data or full database dump
- -Privilege escalation to superadmin
- -Payment or billing manipulation (bypassing charges, stealing credits)
- -Pre-auth SSRF with internal network access
- -Leaked production secrets (API keys, DB credentials)
High
CVSS 7.0 - 8.9Significant data exposure or account compromise for individual users. Attacker compromises specific users or accesses data they should not, but scope is limited.
- -Stored XSS in authenticated areas
- -IDOR exposing sensitive user data (pentest results, billing info)
- -Account takeover via password reset flaws or token leakage
- -CSRF on critical actions (delete account, change email, transfer credits)
- -Privilege escalation from user to admin
- -Accessing other users' pentest reports without authorization
- -SSRF to internal services with limited impact
- -Subdomain takeover on active subdomains
Medium
CVSS 4.0 - 6.9Limited data exposure or partial functionality abuse. Requires user interaction or chaining with other bugs to cause real harm.
- -Reflected XSS requiring user interaction
- -CSRF on non-critical actions (change display name, preferences)
- -Information disclosure (stack traces, internal IPs, software versions)
- -Rate limiting bypass (brute force login, API abuse)
- -Broken access control on low-sensitivity endpoints
- -Email enumeration via login or signup responses
- -Session fixation
- -Missing security headers with demonstrable impact
Low
CVSS 0.1 - 3.9Minimal security risk, mostly theoretical. Hard to exploit in practice, or impact is negligible even if exploited.
- -Self-XSS (only affects the attacker's own session)
- -CSRF on insignificant actions (logout)
- -Verbose error messages without sensitive data
- -Missing security headers without demonstrated impact
- -Clickjacking on non-sensitive pages
- -Open redirect without chaining to a higher impact
- -Cookie without Secure or HttpOnly flag (no demonstrated exploit)
- -Username enumeration via timing attacks
Informational
CVSS 0Best-practice violations with no direct security risk. Good to fix, but not exploitable.
- -Missing X-Content-Type-Options or similar headers
- -SSL/TLS configuration improvements (e.g. supporting TLS 1.1)
- -SPF/DKIM/DMARC misconfigurations without demonstrated spoofing
- -Theoretical attacks with no proof of concept
- -Out-of-scope findings noted for awareness
Rating Principles
- 1.Rate on impact, not effort. A simple IDOR that exposes all user data is Critical, even if it took five minutes to find.
- 2.Require proof of concept. Reporters must demonstrate actual impact, not just theoretical risk.
- 3.Chaining is allowed. Multiple low findings that chain into a high-impact attack should be rated at the combined impact level.
- 4.Context matters. An XSS on a marketing page is lower severity than an XSS in the dashboard where pentest results are displayed.
- 5.Duplicates go to first reporter. Same root cause equals the same report, even if found via different endpoints.
Safe Harbor
Modeled on the HackerOne Gold Standard Safe Harbor
“Good Faith Security Research” means accessing a computer solely for purposes of good-faith testing, investigation, and/or correction of a security flaw or vulnerability, where such activity is carried out in a manner designed to avoid any harm to individuals or the public, and where the information derived from the activity is used primarily to promote the security or safety of the class of devices, machines, or online services to which the accessed computer belongs, or those who use such devices, machines, or online services.
We consider Good Faith Security Research to be authorized activity that is protected from adversarial legal action by us. We waive any relevant restriction in our Terms of Service and Acceptable Use Policy that conflicts with the standard for Good Faith Security Research described here.
For research conducted in compliance with this policy while the program remains active, we commit to the following:
- We will not pursue civil or criminal action, or send notice to law enforcement for Good Faith Security Research, including for bypassing technological measures we use to protect the applications in scope.
- If legal action is initiated by a third party against you for conduct that was consistent with Good Faith Security Research, we will take steps to make it known that your actions were conducted in compliance with this policy.
- We will not recommend that law enforcement investigate or prosecute you for Good Faith Security Research.
This safe harbor applies only to legal claims under the control of TurboPentest (IntegSec LLC) and does not bind independent third parties. It also does not authorize testing on third-party infrastructure not owned by us. If at any point you are uncertain whether your conduct complies with this policy, please contact us at [email protected] before proceeding.
Rules of Engagement
Responsible Disclosure: Give us reasonable time to fix issues before public disclosure.
No Disruption:Do not degrade service availability or access other users' data.
One Account:Test only with accounts you own. Do not access or modify other users' data.
Good Faith: Act in good faith and avoid privacy violations, data destruction, or service interruption.
Duplicates: First valid report for an issue receives the reward. Duplicate reports will be closed.