Penetration tested against a production-equivalent deployment
Realm9 undergoes independent penetration testing against an isolated deployment that reflects the architecture, controls, and configuration patterns used for customer environments.
Testing that reflects the deployed service
Each assessment is conducted against a production-equivalent Realm9 deployment provisioned using the same Infrastructure-as-Code, architecture, network controls, identity configuration patterns, and security controls used for customer environments.
Testing takes place in a dedicated, isolated cloud environment. This avoids impact to customer systems while preserving the deployment model used for private customer installations.
Assessment scope
The review reaches beyond the application layer to cover the controls and operating model that support Realm9 deployments.
Application and APIs
The Realm9 application, service interfaces, and the controls that protect data in transit.
Identity and access
Authentication flows, access-control boundaries, and the identity patterns used in customer environments.
Platform and infrastructure
Cloud infrastructure, network controls, Kubernetes, and the IaC-driven deployment model.
Operational controls
The security processes and operating controls that support the deployed service over time.
A recognised testing framework
The assessment is conducted in accordance with a recognised stack of industry frameworks, selected to examine the application, infrastructure, identity, and operational security controls together.
| Framework | How it informs the assessment |
|---|---|
| OWASP | Application security testing guidance |
| NIST SP 800-115 | Technical security testing methodology |
| MITRE ATT&CK | Adversary tactics and techniques |
| CIS Benchmarks | Secure configuration baselines |
| NCSC Cloud Security Principles | Cloud security assurance principles |
No Critical or High severity findings in the latest assessment
Detailed reports are available to customers, prospective customers, and auditors under NDA. Contact our team to request the latest penetration-testing summary.
Discuss your assurance requirements
We can share the latest penetration-testing summary and supporting security documentation with qualified customers and auditors under NDA.