Everything on this page sits inside the scope of our certification to ISO/IEC 27001:2022 by Technical Standards Institute, valid to September 2027. Penetration testing, vulnerability management, protective monitoring and incident management are all named controls within that scope.
Independent penetration testing
We commission a full-scope penetration test of B-SAFE and its supporting infrastructure at least once a year, from an independent, CREST-registered provider. We take no part in the testing itself.
The most recent full-scope test was completed within the last 12 months. Its scope covered:
- the external and internal network;
- the web application and API — authentication, session management, authorisation, injection, business logic, and the isolation between one customer's instance and another's;
- configuration and TLS review; and
- authenticated testing from each role level.
The methodology combines black-box, grey-box and white-box testing, with OWASP Top 10 and OWASP ASVS coverage. The exact date of the most recent test, and the identity of the provider, are given to customers on request.
Access-restriction testing
We test access restrictions at least every six months — more frequently than the annual full-scope test. The separation and access control within management interfaces is subject to independent penetration testing.
Continuous vulnerability scanning
Scanning software routinely checks our compute instances (hosts) and our containers against the National Vulnerability Database (NVD), Open Vulnerability and Assessment Language (OVAL) and Center for Internet Security (CIS) sources. It checks for unnecessary exposed services, missing patches and insecure configurations. This runs continuously rather than as a periodic campaign, alongside red-team penetration testing and our vulnerability management arrangements.
Every release is scanned before it ships. All code, however authored, is peer-reviewed (four eyes) and passes static application security testing, software composition analysis, secrets scanning and security regression testing before release. All changes are requested through our formal change request process and require authorisation from senior IT management.
Protective monitoring
We use real-time monitoring across the cloud, execution and backup log levels, including collection of user activity logs such as access logs. Our resolution targets apply to what that monitoring detects: our target is to resolve the most serious compromises within 12 hours and others within approximately 72 hours.
How we handle findings
Findings from a penetration test, a scan or our own monitoring are classified by severity and given a named owner. Remediation is verified by retest: a finding is closed when a retest shows it closed, not when a change is deployed. Remediation and its verification sit within our published vulnerability management arrangements.
Findings are risk-rated and remediated to documented timescales by severity, with progress and ageing reported to customers; the timescales are set out in the service documentation available to customers. Separately, our published patching commitment applies to operating system, database and application updates: critical updates are released not later than one working day.
What we tell customers
- The report. Customers may obtain the penetration test report under NDA, on request.
- A summary of each annual test is issued to customers: scope, methodology, tester, findings by severity, and the remediation plan.
- Early notice of serious findings. Any finding rated Critical or High that affects the service is notified to affected customers ahead of the formal report.
- Open findings and their ageing are reported in the service reporting cycle.
- Incidents. Incidents impacting customers are communicated on an ad-hoc basis if and when they occur. If a major incident occurs, information about the incident is sent by email — or another contact route the customer specifies — to the customer, and to the corresponding authority when applicable (the ICO). All discovered incidents, including minor ones, are registered, and incidents are automatically escalated to a fortnightly director meeting for review.
Testing the service yourself
Customers may commission their own penetration test of their own environment, by prior arrangement with us. A customer's IT managed service provider may do this on the customer's behalf. We agree the scope and timing with you before testing begins; ask us at gc@bondap.com.
Reporting a vulnerability to us
If you are not a customer and you believe you have found a security vulnerability in B-SAFE, tell us at security@bondap.com. Please include enough detail for us to reproduce the issue.
Reports are registered and handled under the incident management process described above. While testing, please do not access, alter or delete data belonging to other people, and do not degrade the service for its users. We will not pursue legal action against researchers who act in good faith within this scope.
Questions about anything on this page: gc@bondap.com
© BONDAP LTD. This document is the property of Bondap and is published for information only. It may not be copied, reproduced, adapted, distributed or used for any purpose without our prior written consent.