GoRefer Trust Center
Penetration Testing
Updated September 2026
About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.
GoRefer uses code review, automated checks and security testing to assess risk. Independent penetration testing is a goal of our security program. Before relying on any claim of independent testing, ask us for the scope, completion date, assessor and report.
Testing Cadence
Updated September 2026
Independent Assessment Target
Full-scope web application and API penetration test
Goal: a qualified independent assessor
Policy target: annually and after major architectural changes
Results include executive summary + technical findings + remediation guidance
Continuous Scanning
Automated code-quality checks run in our build pipeline
Dependency audits for our Rust and JavaScript code run in the same pipeline
Results and scope for each release: details on request
Some checks are advisory and do not block a release
Feature-Level Testing
Policy target: review high-risk features before release
Policy target: check prompt-injection tests for major AI changes
Policy target: check payment-flow tests when the Stripe integration changes
Policy target: check sign-in and OAuth tests when authentication changes
Target Assessment Scope
Updated September 2026
| Test Area | Scope | Methodology |
|---|---|---|
| Web Application | Full GoRefer portal (frontend + API) | OWASP Top 10 + ASVS L2 |
| Authentication & Session | Login, MFA, JWT, refresh token lifecycle | Manual + automated |
| API Endpoints | All REST endpoints — authorization, injection, data exposure | Burp Suite + manual |
| Access Control | RBAC enforcement, isolation between firms, privilege escalation | Manual testing |
| AI / Gio Features | Prompt injection, data leakage via AI responses | Manual + red team |
| Infrastructure | AWS configuration, S3 bucket exposure, network segmentation | Cloud security review |
Remediation Process
Updated September 2026
Remediation policy targets
The policy target is to triage Critical and High findings immediately and remediate within 72 hours, Medium findings within two weeks, and Low findings in a planned sprint. Ask us for the remediation and retest records of a specific assessment.
Critical / High Priority
Immediate triage and incident response activation
72-hour remediation target
Executive notification if customer data is at risk
Re-test with pentest firm before clearing
Medium / Low Priority
Tracked in security backlog with owner and due date
Medium: 2 weeks; Low: next sprint
All findings documented in internal remediation register
Annual pentest re-tests previously-closed findings
Access Pentest Results
Updated September 2026
Enterprise customers and security-conscious prospects can request information about available penetration-test summaries and reports. Availability and any NDA requirement are confirmed during review. Request access through the Trust Portal and select "Penetration Test Report" from the document list.
Request available assessment reports