Skip to main content

Introduction

Before reaching 50 customers on Unit or within 3 months after the API key handover, you are required to provide the results of a recent and valid penetration test.

Penetration tests will be required annually thereafter. Penetration test providers must be approved by the Unit security team to ensure the quality and scope of the test. Please see more details below.

ItemExplanationGuidance
Penetration Test TypeThere are three primary types of penetration testing: black box, gray box, and white box.

In gray or white box testing, the tester is provided with valid credentials, allowing them to test flows that require authentication. This enables the tester to identify and evaluate potential security vulnerabilities in areas that would otherwise be inaccessible in black box testing.
Unit accepts only Gray box or White box penetration testing.
Penetration Test ScopeIn a penetration test, test/fake accounts are created by the tested party for a penetration tester to use.

The provided test accounts should have access to all the internal and external APIs (especially APIs involving financial related actions).
Penetration tests should cover:
• Network (internal and external)
• Web application
• Mobile applications (if applicable)
• Other APIs (e.g. login, reset password, and other business flows)
Penetration Test ValidityRegularly conducting penetration tests is crucial for detecting any security weaknesses present in the application.• Report must be from the past 12 months
• Annual testing is required
• The full, unmasked report must be shared
Penetration Test ProviderUnit has a list of trusted pre-approved vendors who are already familiar with the required scope. You can engage directly with one of them and share the results at the end of the process.

Alternatively, you may select a different vendor subject to prior approval from Unit's Security team, by sharing the vendor's name, testing scope, and methodology.
Use one of Unit's approved penetration test vendors, or a vendor pre-approved by Unit's Security team.
Penetration Test RemediationIt is important to ensure that any identified vulnerabilities are addressed and that the system or network is adequately secured against potential threats.• All medium and above vulnerabilities must be fixed and retested by the penetration tester
• Unit's security team will review findings and determine if further remediation is required
Initial Penetration Test TimelinesBefore you reach 50 customers on Unit or 3 months after API key handover, you must provide us with the results of a valid penetration test.If gray/white box test completed in last 12 months:
• Satisfactory results → connection-focused test only required
• Unsatisfactory results → full test required before 50 customers

If no gray/white box test in last 12 months:
• Full test required before reaching 50 customers
Ongoing Penetration Testing RequirementsPenetration tests are required to be completed annually while you are live on the Unit platform.Annual testing is required while live on Unit's platform.