Skip to content

Commit 055355a

Browse files
authored
Fix formatting
1 parent 80ccf9d commit 055355a

File tree

1 file changed

+13
-9
lines changed

1 file changed

+13
-9
lines changed

docs/about-hypernode/security-policies/penetration-testing-policy.md

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
---
22
myst:
33
html_meta:
4-
description: Hypernode's policy for customers that wish to run a pentest on their website
4+
description: Hypernode's policy for customers that wish to run a pentest on their
5+
website
56
title: Penetration Testing Policy | Security | Hypernode
67
---
78

@@ -14,25 +15,28 @@ This policy is for customers that wish to perform an external penetration test o
1415
At Hypernode, we support responsible security testing practices that help customers improve the safety and resilience of their hosted application, and our platform. Customers may conduct penetration tests on their own hosting environments under the following conditions and guidelines.
1516

1617
## Scope of Testing
18+
1719
Penetration testing is only permitted on the customer's *own* hosting space. Testing must not extend to, or affect, any other part of the platform or infrastructure managed by either Hypernode, or other Hypernode customers..
1820

1921
## Requirements
22+
2023
Penetration testing is allowed under the following conditions:
2124

22-
* All pentests must be performed by a reputable, experienced, party.
23-
* You will [inform us](https://www.hypernode.com/en/support/) at least 72 hours ahead of time, and let us know the time, source IP(s) and target of the pentest.
24-
* If the pentest causes, or discovers, any server side issues, you will share the full report of the pentest with us afterwards. You will keep these findings confidential, untill we've had the opportunity to assess and address the issue.
25+
- All pentests must be performed by a reputable, experienced, party.
26+
- You will [inform us](https://www.hypernode.com/en/support/) at least 72 hours ahead of time, and let us know the time, source IP(s) and target of the pentest.
27+
- If the pentest causes, or discovers, any server side issues, you will share the full report of the pentest with us afterwards. You will keep these findings confidential, untill we've had the opportunity to assess and address the issue.
2528

2629
We do not allow pentests that:
27-
* Rely on Social Engineering.
28-
* Perform Brute Force testing.
29-
* Test (D)DoS protection or -resilience.
30-
* Test Physical Security of Datacenters, Offices, etc.
31-
* May cause permanent damage to hardware or equipment.
30+
- Rely on Social Engineering.
31+
- Perform Brute Force testing.
32+
- Test (D)DoS protection or -resilience.
33+
- Test Physical Security of Datacenters, Offices, etc.
34+
- May cause permanent damage to hardware or equipment.
3235

3336
You may wish to add the source IP's of the pentest to the [Hypernode WAF allowlist](./../../best-practices/firewall/ftp-waf-database-allowlist.md), to prevent our automated systems from affecting the test.
3437

3538
## Security Waivers
39+
3640
Hypernode explicitly gives its customers permission to test their own Hypernode hosting environment. If your penetration testing partner still requires a signed waiver, please [contact us](https://www.hypernode.com/en/support/).
3741

3842
# Hypernode's Own Pentest Policy

0 commit comments

Comments
 (0)