I think our security auditor love us. We ask for audit several months ahead (it looks like it's not an habit, the general case is more "we need it for yesterday").
And they have access to the whole code (which is open source), and to a lab with all access on everything.
The qualification call was 3'30" :)
[#]pentest #cybersecurity
=> More informations about this toot | More toots from fanf42@treehouse.systems
@fanf42 are you still using Lift?
=> More informations about this toot | More toots from dpp@mastodon.social
@dpp Yes. For now w| didn't audited part with lift, only some targeted aspects like internal communication protocol or authentication
=> More informations about this toot | More toots from fanf42@treehouse.systems This content has been proxied by September (3851b).Proxy Information
text/gemini