Verified ownership
Prove you control a target’s domain by DNS TXT record, file upload, or HTML meta tag — the same pattern as common webmaster tools. Verification is scoped to your account and cannot be claimed by another.
Trust Center
Everything procurement asks for — compliance program, data handling, sub-processors, disclosure — published up front, before you ask.
Pentrova actively probes the systems you point it at, so we enforce proof of ownership before a scan can run. You verify control of a target’s domain first; only verified domains can be scanned. This is a hard product control, not a checkbox. The full terms — your ownership warranty, permitted scope, and indemnity — are published in the Terms of Service and the Acceptable Use Policy.
Prove you control a target’s domain by DNS TXT record, file upload, or HTML meta tag — the same pattern as common webmaster tools. Verification is scoped to your account and cannot be claimed by another.
Scans run only against verified domains. A request to scan an unverified target is rejected before any traffic is sent. This is separate from our safety blocklist for internal and reserved network ranges.
Pentrova records which account verified which domain, by what method, and when each scan ran against which target — so the authorisation behind a scan can be evidenced if a target owner ever raises a question.
This section covers Pentrova’s own posture as your vendor. For the report-output feature — every customer engagement ships a compliance-mapped report with findings tagged to PCI DSS, ISO 27001, HIPAA, and GDPR controls — see /solutions/compliance.
Pentrova is built against the ISO/IEC 27001:2022 control set and processes customer data as a GDPR data processor. Independent audits run on the schedule below; we will not claim a certification we do not yet hold. The Data Processing Addendum is published with the product, at app.pentrova.ai/legal/dpa, so the copy you read is the copy that binds.
Not yet certified · program in build
Pentrova is a new company building its security program against ISO/IEC 27001:2022. We are not yet certified and do not claim to be. Once a registrar engagement is signed, the audit timeline and certification status will be published on this page.
Day-one design
Pentrova acts as a data processor under GDPR. Our DPA carries the Article 28 processing particulars, the cross-border transfer mechanism, and our breach-notification obligations. Every sub-processor is named individually, with its location and the data it receives, on the sub-processor list.
Pentrova is designed so customer data stays inside an encrypted boundary and is never exposed without an explicit run or export action. The safeguards, the retention windows, and the region are stated in the DPA and the platform privacy policy — published, not negotiated per engagement.
Encrypted at rest across the database, shared filesystem, cache, and object storage, and encrypted in transit. Credentials captured during authenticated pentests carry a further application-layer encryption. The DPA states the full detail, including the one internal hop that is not encrypted — we would rather qualify that than overstate it.
Set by the platform privacy policy and the DPA, not by an order form. Backups are kept for a short fixed period stated in the policy. The authorisation record for each pentest is retained even after an account closes, because it is the evidence that the testing was authorised.
Customers can request deletion of workspace data at any time, and deletion propagates through primary storage and backups on the timeline in the DPA. One documented exception: authorisation records survive, because they evidence that the scanning was authorised.
Every Pentrova engagement runs against the same catalogs documented below. Coverage grows with the platform, not with the engagement clock.
Covers SQLi-to-file-read, LFI-to-RCE, SSRF-to-cloud-metadata, SSTI-to-RCE, XXE-to-SSRF, and every other business-impact path we have reproduced in a sandbox. Inventory and chain detail is available to evaluators under NDA via the product console; product context lives at /product/platform#attack-chains.
Six capability families: passive, injection, access control, business logic, protocol, and post-exploitation. Every agent is individually versioned and audited in the release log; the product console exposes the full catalog to evaluators under NDA. Public family descriptions live at /product/platform#agents.
DOM XSS coverage spans HTML-writing, script-evaluating, URL, and attribute sinks, plus the framework-specific sinks in React, Angular, and Vue applications. Findings ship with the source, the sink, and a reproducible URL. Detail at /product/platform#dom-xss-taint.
Researchers who report vulnerabilities in Pentrova infrastructure, the product surface, or the marketing site are welcome. Please use the contact and PGP key below, and review the machine-readable policy before reporting.
Common security and compliance questions from procurement and security teams during the evaluation process.
Next step
Book a guided walkthrough and get answers to your remaining security questions from our engineering team.