Introduction
Before reaching 50 customers on Unit or within 3 months after the API key handover, you are required to provide the results of a recent and valid penetration test.
Penetration tests will be required annually thereafter. Penetration test providers must be approved by the Unit security team to ensure the quality and scope of the test. Please see more details below.
Item | Explanation | Guidance |
---|---|---|
Penetration test type | There are three primary types of penetration testing: black box, gray box, and white box. In gray or white box testing, the tester is provided with valid credentials, allowing them to test flows that require authentication. This enables the tester to identify and evaluate potential security vulnerabilities in areas that would otherwise be inaccessible in black box testing. |
|
Penetration Test Scope | In a penetration test, test/fake accounts are created by the tested party for a penetration tester to use. The provided test accounts should have access to all the internal and external APIs (especially APIs involving financial related actions) | Penetration tests should cover:
|
Penetration Testing Validity | Regularly conducting penetration tests is crucial for detecting any security weaknesses present in the application. |
|
Penetration Test Provider | We have created a list of trusted service providers to simplify the process of conducting a penetration test for our clients. Those vendors are already familiar with the scope of the required test, so you can directly engage with one of them, and share the pentest results with Unit at the end of the process. Alternatively, you can select a different vendor for the test. Choosing a different vendor will require approval from Unit’s Security team that can be received after sharing the vendor’s name, the testing scope, and the testing methodology. |
|
Penetration Test Remediations | It is important to ensure that any identified vulnerabilities are addressed and that the system or network is adequately secured against potential threats. |
|
Initial Penetration Test Timelines | Before you reach 50 customers on Unit or 3 months after API key handover, you must provide us with the results of a valid penetration test. | If you have conducted a gray or white box pen test in the last 12 months:
|
Ongoing Penetration Testing Requirements | Penetration tests are required to be completed annually while you are live on the Unit platform. | Penetration tests are required to be completed annually while you are live on the Unit platform. |