How often are penetration tests conducted?
amaise conducts annual external penetration tests by independent third-party firms. These tests are part of the ISO 27001 and SOC 2 certification cycles.
In addition to the annual external tests, the security program includes:
Quarterly internal security audits — review of architecture, access controls, and configurations
Continuous external and internal scans — periodic application and infrastructure scans via the compliance platform
Automated vulnerability scans — with every build in the CI/CD pipeline (static code analysis, dependency checks, secret scanning)
Threat detection — continuous monitoring by cloud-native security services
Penetration test reports — including full findings, not just management summaries — are available to customers under NDA upon request.
