Trident’s security experts, accelerated by our agents, take your web apps, APIs, source code and cloud apart once, then walk you through what an attacker could actually do. Scoped on a call, about two weeks of testing, and one retest within 30 days.
Know what’s exploitable, and what to fix first
Ready to show your customer
Ready for your auditor tooSOC 2 · ISO 27001 · HIPAA · PCI DSS
Validated Critical findings reach you within four hours, during testing.
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[06]RETEST STATUS+
Retested 18 February 2026.A status for every finding.
Within 30 days of the report, Trident retested each finding against the remediation evidence and access Acme supplied.
5
Remediated
1
Partially remediated
1
Not remediated
1
Not retested
Finding
Severity
Status
ACME-01
Invoice storage is readable without signing in
Fixed during testing; anonymous requests now return 403.
Critical
Remediated
ACME-02
Invoice download skips the tenant check
The same request now returns 404.
High
Remediated
ACME-03
Member list shows other tenants’ users
The list is now scoped to the caller’s organisation.
High
Remediated
ACME-04
Live payment key in payments-api history
Key rotated; the old key is still in repository history.
High
Partially remediated
ACME-05
Deploy role can write to every bucket
Change scheduled; no evidence supplied yet.
Medium
Not remediated
ACME-06
Session survives a password reset
Sessions are revoked when the password changes.
Medium
Remediated
ACME-07
Sign-in reveals which emails have accounts
No remediation evidence was supplied.
Low
Not retested
ACME-08
No rate limit on password reset requests
Requests are now rate-limited per account.
Low
Remediated
Not retested means no remediation evidence or access was supplied for that finding within the retest window.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
08 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[05]TESTING ATTESTATION+
Testing attestation
Reference
ACME-2026-01
Issued 30 January 2026
To whom it may concern,
Trident performed a penetration test of Acme, Inc. under Statement of Work ACME-2026-01 and the Penetration Testing Services Agreement between the two companies, which set the rules of engagement and authorised the testing.
Authorised scope
Production web application and API: shop.acme.test, api.acme.test, admin.acme.test
Configuration of the production AWS organisation, read-only
Cross-layer attack-path validation
Testing dates
12 January 2026 to 23 January 2026
Completion status
Complete. The final report was issued to Acme on 30 January 2026.
i
It confirms the assessment occurred; it is not a CREST, regulatory or control-framework certification.
Findings and their details are confidential to Acme and are not part of this letter.
For Trident
Engagement lead
30 January 2026
ACME-2026-01
Partner-shareable · ACME-2026-01
07 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[04]REMEDIATION PLAN+
Fix in this order.What an attacker reaches first.
Ranked by severity and by how directly each finding reaches customer data. One shared change, taking the workspace from the session, closes both tenant-isolation findings.
Priority
Finding
Severity
Fix
When
P0
ACME-01
Invoice storage is readable without signing in
Critical
Block public access; signed URLs
Done during testing
P1
ACME-02
Invoice download skips the tenant check
High
Take the workspace from the session
This sprint
P1
ACME-03
Member list shows other tenants’ users
High
Same change as ACME-02
This sprint
P1
ACME-04
Live payment key in payments-api history
High
Rotate the key; purge history
This sprint
P2
ACME-05
Deploy role can write to every bucket
Medium
Scope the role to named buckets
Next sprint
P2
ACME-06
Session survives a password reset
Medium
Revoke sessions on reset
Next sprint
P3
ACME-07
Sign-in reveals which emails have accounts
Low
One response for both cases
Backlog
P3
ACME-08
No rate limit on password reset requests
Low
Rate-limit by account and IP
Backlog
Retest included
One retest within 30 days of this report. Send remediation evidence and access, and each finding gets a written status: remediated, partially remediated, not remediated or not retested.
Walked through with Acme’s engineering leads in a 60-minute readout and remediation-prioritisation session.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
06 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[03]FINDINGS · ACME-02+
Invoice download skipsthe tenant check.
Severity
High
CVSS 3.1
8.1
Layers
Web & API · Source
Affected
GET /api/invoices/:id/pdf
Retest
Remediated
getInvoicePdf looks the invoice up by its ID alone, so any signed-in user can download another workspace’s invoice. Trident reproduced it from a clean session with the second test account.
Reproduced from a clean session · evidence attached
Steps to reproduce
1
Sign in as test account A, in workspace alpha, and copy an invoice ID from Billing.
2
Sign in as test account B, in workspace beta, from a clean session.
3
Request the PDF for account A’s invoice with account B’s session.
Any signed-in user can read other workspaces’ invoices: names, billing addresses and amounts.
Fix
Take the workspace from the session, never from the request, in the shared invoice lookup.
Retest · 18 Feb 2026
Remediated. The same request now returns 404.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
05 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[03]FINDINGS · ACME-01+
Invoice storage is readablewithout signing in.
Severity
Critical
CVSS 3.1
9.1
Layers
Cloud · Web · Source
Reported
Within 4 hours
Status
Remediated
Attack path
acme/payments-api
Invoice keys follow the invoice number.
SOURCE
GET /api/invoices
Invoice numbers appear in every receipt email.
WEB & API
acme-invoices-prod
The bucket policy lets anyone read objects.
CLOUD
Any invoice PDF
fetched by URL, without an account.
IMPACT
Validated across three layers, from a clean session
What we found
The invoice bucket allowed anonymous reads, and its object keys could be derived from invoice numbers that customers receive by email. Joined, the three layers let anyone fetch any customer’s invoice.
Impact
Names, billing addresses and amounts for every Acme customer, with no account and no trace in the app’s logs.
Evidence
Trimmed to the lines that matter
# no credentials, no session
GET acme-invoices-prod / invoices / … / INV-10482.pdf
200 application/pdf · 84 KB
Fix
Block public access on the bucket and serve invoices through short-lived signed URLs, issued only after the API checks the workspace.
Timeline
Reported to Acme within four hours of validation. Confirmed fixed the next day, during testing.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
04 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[02]SCOPE AND METHODOLOGY+
What we tested,and how.
In scope
Rules of engagement: SOW ACME-2026-01
Layer
Targets
Access
Web apps and APIs
shop.acme.test
api.acme.test
admin.acme.test
Black-box, authenticated with two test accounts
Source repositories
acme/payments-api
acme/web
acme/infra
Read-only GitHub access, white-box review
Cloud
AWS organisation acme-prod
3 accounts
Read-only audit role, configuration review
Attack paths
Across all of the above
Cross-layer validation
Out of scope
acme/mobile (mobile testing), staging.acme.test, and third-party services: the payment processor and the email provider.
Method
01
Map
Routes, inputs, roles and cloud identities.
02
Attack
Candidate paths, each tried against the live target.
03
Prove
Replayed from a clean session. Only what reproduces counts.
04
Report
Evidence, impact and the fix for every finding.
Coverage references
NIST SP 800-115
OWASP WSTG v4.2
OWASP ASVS v5.0.0
OWASP API Security Top 10 (2023)
CIS AWS Foundations Benchmark
i
These references guide coverage. They are not a certification.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
03 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[01]EXECUTIVE SUMMARY+
Eight validated findings.One Critical, fixed during testing.
Between 12 and 23 January 2026, Trident tested Acme’s production web application and API, three source repositories and the production AWS organisation. Every finding in this report was validated and comes with reproducible evidence. The Critical finding was reported within four hours of validation and fixed before this report was issued.
Findings by severity
8 validated findings
Critical
1
Fixed during testing
High
3
Medium
2
Low
2
Overall posture
Moderate
Low
High
Acme’s perimeter and cloud baseline are sound. Most of the remaining risk sits in one theme: tenant isolation is enforced in the interface, not in the API. One shared change, taking the workspace from the session, closes both findings in that theme.
Risk themes
01
Tenant isolation lives in the interface, not the API
Two endpoints trust the ID in the request instead of the signed-in workspace.
ACME-02
ACME-03
02
Storage and secrets reachable from outside
A public invoice bucket, and a live payment key in source history.
ACME-01
ACME-04
03
Session lifecycle
Sessions outlive a password reset; sign-in reveals which emails have accounts.
ACME-06
ACME-07
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
Confidential. Prepared for Acme, Inc. under Statement of Work ACME-2026-01 and the Penetration Testing Services Agreement.
[01]WHO IT’S FOR+
One expert check,read three ways.
Run it before a launch, before a big customer deal, after a major change, or simply to know where you stand. The report is written for everyone who reads it.
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[03]FINDINGS · ACME-02+
Invoice download skipsthe tenant check.
Severity
High
CVSS 3.1
8.1
Layers
Web & API · Source
Affected
GET /api/invoices/:id/pdf
Retest
Remediated
getInvoicePdf looks the invoice up by its ID alone, so any signed-in user can download another workspace’s invoice. Trident reproduced it from a clean session with the second test account.
Reproduced from a clean session · evidence attached
Steps to reproduce
1
Sign in as test account A, in workspace alpha, and copy an invoice ID from Billing.
2
Sign in as test account B, in workspace beta, from a clean session.
3
Request the PDF for account A’s invoice with account B’s session.
Any signed-in user can read other workspaces’ invoices: names, billing addresses and amounts.
Fix
Take the workspace from the session, never from the request, in the shared invoice lookup.
Retest · 18 Feb 2026
Remediated. The same request now returns 404.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
05 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[04]REMEDIATION PLAN+
Fix in this order.What an attacker reaches first.
Ranked by severity and by how directly each finding reaches customer data. One shared change, taking the workspace from the session, closes both tenant-isolation findings.
Priority
Finding
Severity
Fix
When
P0
ACME-01
Invoice storage is readable without signing in
Critical
Block public access; signed URLs
Done during testing
P1
ACME-02
Invoice download skips the tenant check
High
Take the workspace from the session
This sprint
P1
ACME-03
Member list shows other tenants’ users
High
Same change as ACME-02
This sprint
P1
ACME-04
Live payment key in payments-api history
High
Rotate the key; purge history
This sprint
P2
ACME-05
Deploy role can write to every bucket
Medium
Scope the role to named buckets
Next sprint
P2
ACME-06
Session survives a password reset
Medium
Revoke sessions on reset
Next sprint
P3
ACME-07
Sign-in reveals which emails have accounts
Low
One response for both cases
Backlog
P3
ACME-08
No rate limit on password reset requests
Low
Rate-limit by account and IP
Backlog
Retest included
One retest within 30 days of this report. Send remediation evidence and access, and each finding gets a written status: remediated, partially remediated, not remediated or not retested.
Walked through with Acme’s engineering leads in a 60-minute readout and remediation-prioritisation session.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
06 / 08
ENGINEERING
Know what to fix first
Every validated finding with the steps to reproduce it and the line that caused it, ranked by what an attacker reaches first, then walked through with your team in a 60-minute readout.
What they get
Findings with evidence
Prioritised remediation plan
60-minute readout
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[01]EXECUTIVE SUMMARY+
Eight validated findings.One Critical, fixed during testing.
Between 12 and 23 January 2026, Trident tested Acme’s production web application and API, three source repositories and the production AWS organisation. Every finding in this report was validated and comes with reproducible evidence. The Critical finding was reported within four hours of validation and fixed before this report was issued.
Findings by severity
8 validated findings
Critical
1
Fixed during testing
High
3
Medium
2
Low
2
Overall posture
Moderate
Low
High
Acme’s perimeter and cloud baseline are sound. Most of the remaining risk sits in one theme: tenant isolation is enforced in the interface, not in the API. One shared change, taking the workspace from the session, closes both findings in that theme.
Risk themes
01
Tenant isolation lives in the interface, not the API
Two endpoints trust the ID in the request instead of the signed-in workspace.
ACME-02
ACME-03
02
Storage and secrets reachable from outside
A public invoice bucket, and a live payment key in source history.
ACME-01
ACME-04
03
Session lifecycle
Sessions outlive a password reset; sign-in reveals which emails have accounts.
ACME-06
ACME-07
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
02 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[05]TESTING ATTESTATION+
Testing attestation
Reference
ACME-2026-01
Issued 30 January 2026
To whom it may concern,
Trident performed a penetration test of Acme, Inc. under Statement of Work ACME-2026-01 and the Penetration Testing Services Agreement between the two companies, which set the rules of engagement and authorised the testing.
Authorised scope
Production web application and API: shop.acme.test, api.acme.test, admin.acme.test
Configuration of the production AWS organisation, read-only
Cross-layer attack-path validation
Testing dates
12 January 2026 to 23 January 2026
Completion status
Complete. The final report was issued to Acme on 30 January 2026.
i
It confirms the assessment occurred; it is not a CREST, regulatory or control-framework certification.
Findings and their details are confidential to Acme and are not part of this letter.
For Trident
Engagement lead
30 January 2026
ACME-2026-01
Partner-shareable · ACME-2026-01
07 / 08
CUSTOMERS
Ready to show your customer
Enterprise buyers ask for your latest pentest during a security review. Send the attestation with the questionnaire, and the executive summary when they want more.
What they get
Testing attestation
Executive summary
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[02]SCOPE AND METHODOLOGY+
What we tested,and how.
In scope
Rules of engagement: SOW ACME-2026-01
Layer
Targets
Access
Web apps and APIs
shop.acme.test
api.acme.test
admin.acme.test
Black-box, authenticated with two test accounts
Source repositories
acme/payments-api
acme/web
acme/infra
Read-only GitHub access, white-box review
Cloud
AWS organisation acme-prod
3 accounts
Read-only audit role, configuration review
Attack paths
Across all of the above
Cross-layer validation
Out of scope
acme/mobile (mobile testing), staging.acme.test, and third-party services: the payment processor and the email provider.
Method
01
Map
Routes, inputs, roles and cloud identities.
02
Attack
Candidate paths, each tried against the live target.
03
Prove
Replayed from a clean session. Only what reproduces counts.
04
Report
Evidence, impact and the fix for every finding.
Coverage references
NIST SP 800-115
OWASP WSTG v4.2
OWASP ASVS v5.0.0
OWASP API Security Top 10 (2023)
CIS AWS Foundations Benchmark
i
These references guide coverage. They are not a certification.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
03 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[06]RETEST STATUS+
Retested 18 February 2026.A status for every finding.
Within 30 days of the report, Trident retested each finding against the remediation evidence and access Acme supplied.
5
Remediated
1
Partially remediated
1
Not remediated
1
Not retested
Finding
Severity
Status
ACME-01
Invoice storage is readable without signing in
Fixed during testing; anonymous requests now return 403.
Critical
Remediated
ACME-02
Invoice download skips the tenant check
The same request now returns 404.
High
Remediated
ACME-03
Member list shows other tenants’ users
The list is now scoped to the caller’s organisation.
High
Remediated
ACME-04
Live payment key in payments-api history
Key rotated; the old key is still in repository history.
High
Partially remediated
ACME-05
Deploy role can write to every bucket
Change scheduled; no evidence supplied yet.
Medium
Not remediated
ACME-06
Session survives a password reset
Sessions are revoked when the password changes.
Medium
Remediated
ACME-07
Sign-in reveals which emails have accounts
No remediation evidence was supplied.
Low
Not retested
ACME-08
No rate limit on password reset requests
Requests are now rate-limited per account.
Low
Remediated
Not retested means no remediation evidence or access was supplied for that finding within the retest window.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
08 / 08
AUDITORS
Ready for your auditor, too
When a framework asks for a recent penetration test, the same report covers it: scope, methodology, testing dates, every finding with evidence, and a written retest status.
SOC 2
ISO 27001
HIPAA
PCI DSS
What they get
Full report
Retest status
iThe attestation confirms the assessment occurred; it is not a certification.
[02]HOW IT RUNS+
Scoped on a call.Reported in writing.
Every engagement runs on a Statement of Work and a Penetration Testing Services Agreement. Together they set the scope, the rules of engagement and the authorisation to test.
Schedule
Before
Week 1
Week 2
Week 3
Up to 30 days after the report
Scoping call
SOW and services agreement signed
Access readiness review
Accounts, contact and scope confirmed
Kickoff
Testing begins
Primary testing window
About two weeks
Validated Critical findings reach you within four hours
Final report and readout
60-minute live session
Remediation retest
One retest, status per finding
01
Access readiness
Signed documents, the scope inventory, an engineering contact and test accounts, confirmed before testing starts.
02
Kickoff
Targets, exclusions, monitoring and how we reach you are agreed. Testing begins.
03
Testing
About two weeks across web and API, source, cloud and attack paths between them.
04
Report and readout
The written report and remediation plan, walked through in a 60-minute live session.
05
Retest
One retest within 30 days of the report, with a written status for every finding.
[03]THE REPORT+
A report you can act on,and share.
Findings your engineers can reproduce, a summary for leadership, and an attestation for the customer who asks. Acme is fictional; the pages are what your report holds.
Confidential. Prepared for Acme, Inc. under Statement of Work ACME-2026-01 and the Penetration Testing Services Agreement.
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[01]EXECUTIVE SUMMARY+
Eight validated findings.One Critical, fixed during testing.
Between 12 and 23 January 2026, Trident tested Acme’s production web application and API, three source repositories and the production AWS organisation. Every finding in this report was validated and comes with reproducible evidence. The Critical finding was reported within four hours of validation and fixed before this report was issued.
Findings by severity
8 validated findings
Critical
1
Fixed during testing
High
3
Medium
2
Low
2
Overall posture
Moderate
Low
High
Acme’s perimeter and cloud baseline are sound. Most of the remaining risk sits in one theme: tenant isolation is enforced in the interface, not in the API. One shared change, taking the workspace from the session, closes both findings in that theme.
Risk themes
01
Tenant isolation lives in the interface, not the API
Two endpoints trust the ID in the request instead of the signed-in workspace.
ACME-02
ACME-03
02
Storage and secrets reachable from outside
A public invoice bucket, and a live payment key in source history.
ACME-01
ACME-04
03
Session lifecycle
Sessions outlive a password reset; sign-in reveals which emails have accounts.
ACME-06
ACME-07
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
02 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[02]SCOPE AND METHODOLOGY+
What we tested,and how.
In scope
Rules of engagement: SOW ACME-2026-01
Layer
Targets
Access
Web apps and APIs
shop.acme.test
api.acme.test
admin.acme.test
Black-box, authenticated with two test accounts
Source repositories
acme/payments-api
acme/web
acme/infra
Read-only GitHub access, white-box review
Cloud
AWS organisation acme-prod
3 accounts
Read-only audit role, configuration review
Attack paths
Across all of the above
Cross-layer validation
Out of scope
acme/mobile (mobile testing), staging.acme.test, and third-party services: the payment processor and the email provider.
Method
01
Map
Routes, inputs, roles and cloud identities.
02
Attack
Candidate paths, each tried against the live target.
03
Prove
Replayed from a clean session. Only what reproduces counts.
04
Report
Evidence, impact and the fix for every finding.
Coverage references
NIST SP 800-115
OWASP WSTG v4.2
OWASP ASVS v5.0.0
OWASP API Security Top 10 (2023)
CIS AWS Foundations Benchmark
i
These references guide coverage. They are not a certification.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
03 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[03]FINDINGS · ACME-01+
Invoice storage is readablewithout signing in.
Severity
Critical
CVSS 3.1
9.1
Layers
Cloud · Web · Source
Reported
Within 4 hours
Status
Remediated
Attack path
acme/payments-api
Invoice keys follow the invoice number.
SOURCE
GET /api/invoices
Invoice numbers appear in every receipt email.
WEB & API
acme-invoices-prod
The bucket policy lets anyone read objects.
CLOUD
Any invoice PDF
fetched by URL, without an account.
IMPACT
Validated across three layers, from a clean session
What we found
The invoice bucket allowed anonymous reads, and its object keys could be derived from invoice numbers that customers receive by email. Joined, the three layers let anyone fetch any customer’s invoice.
Impact
Names, billing addresses and amounts for every Acme customer, with no account and no trace in the app’s logs.
Evidence
Trimmed to the lines that matter
# no credentials, no session
GET acme-invoices-prod / invoices / … / INV-10482.pdf
200 application/pdf · 84 KB
Fix
Block public access on the bucket and serve invoices through short-lived signed URLs, issued only after the API checks the workspace.
Timeline
Reported to Acme within four hours of validation. Confirmed fixed the next day, during testing.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
04 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[03]FINDINGS · ACME-02+
Invoice download skipsthe tenant check.
Severity
High
CVSS 3.1
8.1
Layers
Web & API · Source
Affected
GET /api/invoices/:id/pdf
Retest
Remediated
getInvoicePdf looks the invoice up by its ID alone, so any signed-in user can download another workspace’s invoice. Trident reproduced it from a clean session with the second test account.
Reproduced from a clean session · evidence attached
Steps to reproduce
1
Sign in as test account A, in workspace alpha, and copy an invoice ID from Billing.
2
Sign in as test account B, in workspace beta, from a clean session.
3
Request the PDF for account A’s invoice with account B’s session.
Any signed-in user can read other workspaces’ invoices: names, billing addresses and amounts.
Fix
Take the workspace from the session, never from the request, in the shared invoice lookup.
Retest · 18 Feb 2026
Remediated. The same request now returns 404.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
05 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[04]REMEDIATION PLAN+
Fix in this order.What an attacker reaches first.
Ranked by severity and by how directly each finding reaches customer data. One shared change, taking the workspace from the session, closes both tenant-isolation findings.
Priority
Finding
Severity
Fix
When
P0
ACME-01
Invoice storage is readable without signing in
Critical
Block public access; signed URLs
Done during testing
P1
ACME-02
Invoice download skips the tenant check
High
Take the workspace from the session
This sprint
P1
ACME-03
Member list shows other tenants’ users
High
Same change as ACME-02
This sprint
P1
ACME-04
Live payment key in payments-api history
High
Rotate the key; purge history
This sprint
P2
ACME-05
Deploy role can write to every bucket
Medium
Scope the role to named buckets
Next sprint
P2
ACME-06
Session survives a password reset
Medium
Revoke sessions on reset
Next sprint
P3
ACME-07
Sign-in reveals which emails have accounts
Low
One response for both cases
Backlog
P3
ACME-08
No rate limit on password reset requests
Low
Rate-limit by account and IP
Backlog
Retest included
One retest within 30 days of this report. Send remediation evidence and access, and each finding gets a written status: remediated, partially remediated, not remediated or not retested.
Walked through with Acme’s engineering leads in a 60-minute readout and remediation-prioritisation session.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
06 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[05]TESTING ATTESTATION+
Testing attestation
Reference
ACME-2026-01
Issued 30 January 2026
To whom it may concern,
Trident performed a penetration test of Acme, Inc. under Statement of Work ACME-2026-01 and the Penetration Testing Services Agreement between the two companies, which set the rules of engagement and authorised the testing.
Authorised scope
Production web application and API: shop.acme.test, api.acme.test, admin.acme.test
Configuration of the production AWS organisation, read-only
Cross-layer attack-path validation
Testing dates
12 January 2026 to 23 January 2026
Completion status
Complete. The final report was issued to Acme on 30 January 2026.
i
It confirms the assessment occurred; it is not a CREST, regulatory or control-framework certification.
Findings and their details are confidential to Acme and are not part of this letter.
For Trident
Engagement lead
30 January 2026
ACME-2026-01
Partner-shareable · ACME-2026-01
07 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[06]RETEST STATUS+
Retested 18 February 2026.A status for every finding.
Within 30 days of the report, Trident retested each finding against the remediation evidence and access Acme supplied.
5
Remediated
1
Partially remediated
1
Not remediated
1
Not retested
Finding
Severity
Status
ACME-01
Invoice storage is readable without signing in
Fixed during testing; anonymous requests now return 403.
Critical
Remediated
ACME-02
Invoice download skips the tenant check
The same request now returns 404.
High
Remediated
ACME-03
Member list shows other tenants’ users
The list is now scoped to the caller’s organisation.
High
Remediated
ACME-04
Live payment key in payments-api history
Key rotated; the old key is still in repository history.
High
Partially remediated
ACME-05
Deploy role can write to every bucket
Change scheduled; no evidence supplied yet.
Medium
Not remediated
ACME-06
Session survives a password reset
Sessions are revoked when the password changes.
Medium
Remediated
ACME-07
Sign-in reveals which emails have accounts
No remediation evidence was supplied.
Low
Not retested
ACME-08
No rate limit on password reset requests
Requests are now rate-limited per account.
Low
Remediated
Not retested means no remediation evidence or access was supplied for that finding within the retest window.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
08 / 08
Contents
On this page
For leadership and customers
1What was tested, and whenScope and dates in a paragraph your customer can read.
2Findings by severityEight validated findings; the Critical one fixed during testing.
3Overall postureA plain rating, and the one theme behind most of the risk.
4Risk themesEach tied to the findings behind it, for the engineers reading on.
Acme · Penetration testing reportACME-2026-01
Executive summary02 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[01]EXECUTIVE SUMMARY+
Eight validated findings.One Critical, fixed during testing.
Between 12 and 23 January 2026, Trident tested Acme’s production web application and API, three source repositories and the production AWS organisation. Every finding in this report was validated and comes with reproducible evidence. The Critical finding was reported within four hours of validation and fixed before this report was issued.
Findings by severity
8 validated findings
Critical
1
Fixed during testing
High
3
Medium
2
Low
2
Overall posture
Moderate
Low
High
Acme’s perimeter and cloud baseline are sound. Most of the remaining risk sits in one theme: tenant isolation is enforced in the interface, not in the API. One shared change, taking the workspace from the session, closes both findings in that theme.
Risk themes
01
Tenant isolation lives in the interface, not the API
Two endpoints trust the ID in the request instead of the signed-in workspace.
ACME-02
ACME-03
02
Storage and secrets reachable from outside
A public invoice bucket, and a live payment key in source history.
ACME-01
ACME-04
03
Session lifecycle
Sessions outlive a password reset; sign-in reveals which emails have accounts.
ACME-06
ACME-07
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
Confidential. Prepared for Acme, Inc. under Statement of Work ACME-2026-01 and the Penetration Testing Services Agreement.
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[01]EXECUTIVE SUMMARY+
Eight validated findings.One Critical, fixed during testing.
Between 12 and 23 January 2026, Trident tested Acme’s production web application and API, three source repositories and the production AWS organisation. Every finding in this report was validated and comes with reproducible evidence. The Critical finding was reported within four hours of validation and fixed before this report was issued.
Findings by severity
8 validated findings
Critical
1
Fixed during testing
High
3
Medium
2
Low
2
Overall posture
Moderate
Low
High
Acme’s perimeter and cloud baseline are sound. Most of the remaining risk sits in one theme: tenant isolation is enforced in the interface, not in the API. One shared change, taking the workspace from the session, closes both findings in that theme.
Risk themes
01
Tenant isolation lives in the interface, not the API
Two endpoints trust the ID in the request instead of the signed-in workspace.
ACME-02
ACME-03
02
Storage and secrets reachable from outside
A public invoice bucket, and a live payment key in source history.
ACME-01
ACME-04
03
Session lifecycle
Sessions outlive a password reset; sign-in reveals which emails have accounts.
ACME-06
ACME-07
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
02 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[02]SCOPE AND METHODOLOGY+
What we tested,and how.
In scope
Rules of engagement: SOW ACME-2026-01
Layer
Targets
Access
Web apps and APIs
shop.acme.test
api.acme.test
admin.acme.test
Black-box, authenticated with two test accounts
Source repositories
acme/payments-api
acme/web
acme/infra
Read-only GitHub access, white-box review
Cloud
AWS organisation acme-prod
3 accounts
Read-only audit role, configuration review
Attack paths
Across all of the above
Cross-layer validation
Out of scope
acme/mobile (mobile testing), staging.acme.test, and third-party services: the payment processor and the email provider.
Method
01
Map
Routes, inputs, roles and cloud identities.
02
Attack
Candidate paths, each tried against the live target.
03
Prove
Replayed from a clean session. Only what reproduces counts.
04
Report
Evidence, impact and the fix for every finding.
Coverage references
NIST SP 800-115
OWASP WSTG v4.2
OWASP ASVS v5.0.0
OWASP API Security Top 10 (2023)
CIS AWS Foundations Benchmark
i
These references guide coverage. They are not a certification.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
03 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[03]FINDINGS · ACME-01+
Invoice storage is readablewithout signing in.
Severity
Critical
CVSS 3.1
9.1
Layers
Cloud · Web · Source
Reported
Within 4 hours
Status
Remediated
Attack path
acme/payments-api
Invoice keys follow the invoice number.
SOURCE
GET /api/invoices
Invoice numbers appear in every receipt email.
WEB & API
acme-invoices-prod
The bucket policy lets anyone read objects.
CLOUD
Any invoice PDF
fetched by URL, without an account.
IMPACT
Validated across three layers, from a clean session
What we found
The invoice bucket allowed anonymous reads, and its object keys could be derived from invoice numbers that customers receive by email. Joined, the three layers let anyone fetch any customer’s invoice.
Impact
Names, billing addresses and amounts for every Acme customer, with no account and no trace in the app’s logs.
Evidence
Trimmed to the lines that matter
# no credentials, no session
GET acme-invoices-prod / invoices / … / INV-10482.pdf
200 application/pdf · 84 KB
Fix
Block public access on the bucket and serve invoices through short-lived signed URLs, issued only after the API checks the workspace.
Timeline
Reported to Acme within four hours of validation. Confirmed fixed the next day, during testing.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
04 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[03]FINDINGS · ACME-02+
Invoice download skipsthe tenant check.
Severity
High
CVSS 3.1
8.1
Layers
Web & API · Source
Affected
GET /api/invoices/:id/pdf
Retest
Remediated
getInvoicePdf looks the invoice up by its ID alone, so any signed-in user can download another workspace’s invoice. Trident reproduced it from a clean session with the second test account.
Reproduced from a clean session · evidence attached
Steps to reproduce
1
Sign in as test account A, in workspace alpha, and copy an invoice ID from Billing.
2
Sign in as test account B, in workspace beta, from a clean session.
3
Request the PDF for account A’s invoice with account B’s session.
Any signed-in user can read other workspaces’ invoices: names, billing addresses and amounts.
Fix
Take the workspace from the session, never from the request, in the shared invoice lookup.
Retest · 18 Feb 2026
Remediated. The same request now returns 404.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
05 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[04]REMEDIATION PLAN+
Fix in this order.What an attacker reaches first.
Ranked by severity and by how directly each finding reaches customer data. One shared change, taking the workspace from the session, closes both tenant-isolation findings.
Priority
Finding
Severity
Fix
When
P0
ACME-01
Invoice storage is readable without signing in
Critical
Block public access; signed URLs
Done during testing
P1
ACME-02
Invoice download skips the tenant check
High
Take the workspace from the session
This sprint
P1
ACME-03
Member list shows other tenants’ users
High
Same change as ACME-02
This sprint
P1
ACME-04
Live payment key in payments-api history
High
Rotate the key; purge history
This sprint
P2
ACME-05
Deploy role can write to every bucket
Medium
Scope the role to named buckets
Next sprint
P2
ACME-06
Session survives a password reset
Medium
Revoke sessions on reset
Next sprint
P3
ACME-07
Sign-in reveals which emails have accounts
Low
One response for both cases
Backlog
P3
ACME-08
No rate limit on password reset requests
Low
Rate-limit by account and IP
Backlog
Retest included
One retest within 30 days of this report. Send remediation evidence and access, and each finding gets a written status: remediated, partially remediated, not remediated or not retested.
Walked through with Acme’s engineering leads in a 60-minute readout and remediation-prioritisation session.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
06 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[05]TESTING ATTESTATION+
Testing attestation
Reference
ACME-2026-01
Issued 30 January 2026
To whom it may concern,
Trident performed a penetration test of Acme, Inc. under Statement of Work ACME-2026-01 and the Penetration Testing Services Agreement between the two companies, which set the rules of engagement and authorised the testing.
Authorised scope
Production web application and API: shop.acme.test, api.acme.test, admin.acme.test
Configuration of the production AWS organisation, read-only
Cross-layer attack-path validation
Testing dates
12 January 2026 to 23 January 2026
Completion status
Complete. The final report was issued to Acme on 30 January 2026.
i
It confirms the assessment occurred; it is not a CREST, regulatory or control-framework certification.
Findings and their details are confidential to Acme and are not part of this letter.
For Trident
Engagement lead
30 January 2026
ACME-2026-01
Partner-shareable · ACME-2026-01
07 / 08
Trident
/
Acme · Penetration testing report
ACME-2026-01
Confidential
[06]RETEST STATUS+
Retested 18 February 2026.A status for every finding.
Within 30 days of the report, Trident retested each finding against the remediation evidence and access Acme supplied.
5
Remediated
1
Partially remediated
1
Not remediated
1
Not retested
Finding
Severity
Status
ACME-01
Invoice storage is readable without signing in
Fixed during testing; anonymous requests now return 403.
Critical
Remediated
ACME-02
Invoice download skips the tenant check
The same request now returns 404.
High
Remediated
ACME-03
Member list shows other tenants’ users
The list is now scoped to the caller’s organisation.
High
Remediated
ACME-04
Live payment key in payments-api history
Key rotated; the old key is still in repository history.
High
Partially remediated
ACME-05
Deploy role can write to every bucket
Change scheduled; no evidence supplied yet.
Medium
Not remediated
ACME-06
Session survives a password reset
Sessions are revoked when the password changes.
Medium
Remediated
ACME-07
Sign-in reveals which emails have accounts
No remediation evidence was supplied.
Low
Not retested
ACME-08
No rate limit on password reset requests
Requests are now rate-limited per account.
Low
Remediated
Not retested means no remediation evidence or access was supplied for that finding within the retest window.
Confidential · Prepared for Acme, Inc. under SOW ACME-2026-01
08 / 08
01CoverLeadership, customers
02Executive summaryLeadership, customers
03Scope and methodologySecurity leads
04Finding ACME-01Engineering
05Finding ACME-02Engineering
06Remediation planEngineering
07Testing attestationAuditors, partners
08Retest statusEveryone
[04]WHAT YOU RECEIVE+
What you holdat the end.
The first five are written into the Statement of Work before testing starts. The dashboard keeps all of them in one place.
Penetration testing report
Executive summary, scope and methodology, risk themes, a finding per validated issue with reproducible evidence, and a prioritised remediation plan.
Testing attestation
A partner-shareable letter that confirms the authorised scope, the testing dates and the completion status.
It confirms the assessment occurred; it is not a CREST, regulatory or control-framework certification.
Retest status update
One retest within 30 days of the report. Each finding is marked remediated, partially remediated, not remediated or not retested.
60-minute readout
A live walkthrough of the report and a remediation-prioritisation session with your engineers.
Critical findings within four hours
Validated Critical findings reach you during testing, within four hours. They don’t wait for the report.
Engagement dashboard
Timeline, scope, documents and what we still need from you, in one place in Trident.
[05]WHAT WE TEST+
Four layers,tested as one system.
Web apps and APIs
Black-box, authenticated with the test accounts you supply: routes, inputs, roles and the business logic between them.
Source code
White-box review over read-only GitHub access. Findings point to the file and the line.
Cloud configuration
A read-only role on AWS, Azure, GCP or Kubernetes: exposure across assets, containers, identities and secrets.
Attack paths across layers
A weakness in one layer joined to another, then validated end to end.
aws · acme-prod
deploy-role
api-service
acme-invoices-prod
acme/payments-api · invoices.ts
38
39
40
41
42
43
44
shop.acme.test
/login
/account/invoices
/api/invoices/:id/pdf
/checkout
/api/orgs/:id/members
WEB & API
Black-box
SOURCE
White-box, read-only
CLOUD
Read-only role
Path validated end to end
[06]METHODOLOGY+
The methodologywe follow.
Coverage follows published testing standards, and the report names each one. It is also the first thing an auditor asks.
NIST SP 800-115Technical guide to security testing and assessment
OWASP WSTG v4.2Web Security Testing Guide
OWASP ASVS v5.0.0Application Security Verification Standard
OWASP API Security Top 10 (2023)The most critical API security risks
CIS cloud benchmarksConfiguration baselines for AWS, Azure, GCP and Kubernetes
iThese references guide coverage. They are not a certification.
[07]YOUR ENGAGEMENT+
Every date and document,in one place.
The engagement lives in your Trident dashboard: the timeline, the scope with its exclusions, the paperwork, the report, and what we still need from you.
AAcme
Engagement
Overview
Repositories
Cloud
Documents
Settings
Acme
Testing
Cloud, source-code and web-application penetration test ·
ACME-2026-01
Questions
contact@tridentsecurity.io
Testing window
12 – 23 Jan 2026
Report due
30 Jan 2026
in 13 days
YOUR PENTEST
Timeline
Dates in UTC
Access readiness review
9 Jan
Kickoff, testing begins
12 Jan
Primary testing window
12 – 23 Jan
In progress
Validated Critical findings are reported within four hours.
Final report and readout
30 Jan
Up next
Remediation retest
Within 30 days of the report
Get set up
Ready
Confirm the production domains and subdomains in scope
Confirmed
Grant read-only GitHub access to the three repositories
Confirmed
Grant read-only AWS access and supply the account inventory
Confirmed
Provide at least two test accounts at distinct privilege levels (over Slack, never in this dashboard)
Designate an engineering contact who can answer questions and pause testing
Tell us about blackout periods, fragile services and IP allowlists
Scope
Domains and web apps
The externally reachable production surface we are authorized to test.
shop.acme.test
Black-box; authenticated where accounts are supplied
Confirmed
api.acme.test
Black-box; authenticated where accounts are supplied
Confirmed
admin.acme.test
Black-box; authenticated where accounts are supplied
Confirmed
Source repositories
The repositories named in your Statement of Work. Grant read-only access and we check that every one of them is actually reachable.
acme/payments-api
Read-only repository access
Confirmed
acme/web
Read-only repository access
Confirmed
acme/infra
Read-only repository access
Confirmed
Not in scope
acme/mobileacme/opsacme/design-tools
Cloud environment
AWS organisation acme-prod
Read-only audit role
Confirmed
Documents
Statement of Work ACME-2026-01
The authorised scope, testing coverage, rules of engagement, schedule and fees.
Executed
Penetration Testing Services Agreement
Authorisation to test, confidentiality, data handling, intellectual property and liability.
Executed
Penetration testing report
Executive summary, scope and methodology, risk themes, a finding per validated issue with reproducible evidence, and a prioritised remediation plan.
Not issued yet
Testing attestation
Partner-shareable confirmation of the authorised scope, testing dates and completion status. It confirms the assessment occurred; it is not a CREST, regulatory or control-framework certification.
Not issued yet
Retest status update
Each reported finding marked remediated, partially remediated, not remediated, or not retested.
Not issued yet
Reference standards
NIST SP 800-115OWASP Web Security Testing Guide v4.2OWASP Application Security Verification Standard v5.0.0OWASP API Security Top 10 (2023)CIS Amazon Web Services Foundations Benchmark
These guide coverage and do not constitute a compliance certification.
[08]AFTER THE REPORT+
Start with a pentest.Keep it continuous.
A report is a snapshot of one moment. When you want every release covered, the same platform keeps testing after the retest.
Acme · 2026
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
One-time pentest
January
Test
Report
Retest
Keep it continuous
Every pull request
Reviewed as it opens
Pentests
On your schedule
Cloud
Read-only, always mapped
One-time pentest
When you want to know where you stand.
Scoped on a call with the team that builds Trident
About two weeks of testing across web, source and cloud
Report, testing attestation and a 60-minute readout
Your production web apps and APIs (black-box, authenticated with test accounts you supply), source repositories over read-only GitHub access, your cloud configuration through a read-only role, and the attack paths that join them.
A report with reproducible evidence for every validated finding and a prioritised remediation plan, a 60-minute readout with your engineers, a testing attestation you can share, and one retest within 30 days.
About two weeks of testing from kickoff. The final report and the readout follow about a week later, and the retest happens within 30 days of the report.
Trident’s security experts lead the engagement and Trident’s agents do the heavy lifting. Every finding is reproduced from a clean session before it is reported, and the same team walks you through the report.
The signed Statement of Work and services agreement, the domains, repositories and cloud accounts in scope, read-only GitHub and cloud access, at least two test accounts at different privilege levels, an engineering contact who can pause testing, and any blackout windows.
It sets out scope, methodology, dates and every validated finding with evidence, so it covers a framework’s penetration-testing ask. Whether it meets a specific control is your auditor’s call; the attestation is not a certification.
Validated Critical findings reach you within four hours during testing, so you can start fixing before the report arrives.
Each engagement is scoped on a call and quoted for your apps, repositories and cloud. There are no public prices.
[10]GET STARTED+
Get an expertsecurity check.
Know what is actually exploitable, fixed in order. Scoped on a call, with a report you can share.