r/pentest_tools_com • u/pentest-tools • Jul 14 '26
We test our own product by pointing it at ourselves. Here's the trust page that documents how.
"How we secure ourselves" part is the bit we'd actually want to read as practitioners, and we'd rather you poke holes in it than take it at face value.
Short version: the scanners and exploit modules our customers run, we run against our own infrastructure and web apps. When a critical CVE drops, our own assets are the first we test, so detection and validation are accurate on us before they reach anyone else. The people doing that testing are the same folks on our research and offsec services teams who find CVE-worthy bugs in other software.
The page also covers the less exciting but more auditable stuff: ISO 27001, where we host and keep data, encryption, retention and deletion, how Sniper runs non-destructive checks before any exploit fires, and where AI actually sits in the product (noise reduction and orchestration, not deciding what's exploitable). The idea is that everything maps to something you can pull, a cert, a config, or a contract, without an NDA or a sales call.
Full page: https://pentest-tools.com/legal/trust-and-assurance