Penetration tests are in the interest of the client to assess the security of their data when processed by service providers. However, without prior notification and coordination with us, we cannot distinguish a pentest from a real attack on our services. In such cases, we will actively respond, which may have both technical and legal consequences.
To avoid such misunderstandings, we require the following information in advance:
Timing
- Date of the pentest
- Duration of the pentest
Scope
- Scope of the pentest
- Affected Hornetsecurity services
- Number of tests to be conducted
Technical Details
- Type of planned tests
- Possible impact on our production systems (e.g., "destructive tests," DoS, DDoS)
- IP address or IP range from which the test will be conducted
Please send this information to support@hornetsecurity.com. We will then review the approval and get back to you. A prerequisite for approval is also that the test results are provided to us after the pentest.