Skip to content

GoRefer Trust Center

Penetration Testing

Updated September 2026

About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.

GoRefer uses code review, automated checks and security testing to assess risk. Independent penetration testing is a goal of our security program. Before relying on any claim of independent testing, ask us for the scope, completion date, assessor and report.

Assessment Program
OWASP Methodology
Report Requests

Testing Cadence

Updated September 2026

Independent Assessment Target

  • Full-scope web application and API penetration test

  • Goal: a qualified independent assessor

  • Policy target: annually and after major architectural changes

  • Results include executive summary + technical findings + remediation guidance

Continuous Scanning

  • Automated code-quality checks run in our build pipeline

  • Dependency audits for our Rust and JavaScript code run in the same pipeline

  • Results and scope for each release: details on request

  • Some checks are advisory and do not block a release

Feature-Level Testing

  • Policy target: review high-risk features before release

  • Policy target: check prompt-injection tests for major AI changes

  • Policy target: check payment-flow tests when the Stripe integration changes

  • Policy target: check sign-in and OAuth tests when authentication changes

Target Assessment Scope

Updated September 2026

Test AreaScopeMethodology
Web ApplicationFull GoRefer portal (frontend + API)OWASP Top 10 + ASVS L2
Authentication & SessionLogin, MFA, JWT, refresh token lifecycleManual + automated
API EndpointsAll REST endpoints — authorization, injection, data exposureBurp Suite + manual
Access ControlRBAC enforcement, isolation between firms, privilege escalationManual testing
AI / Gio FeaturesPrompt injection, data leakage via AI responsesManual + red team
InfrastructureAWS configuration, S3 bucket exposure, network segmentationCloud security review

Remediation Process

Updated September 2026

Remediation policy targets

The policy target is to triage Critical and High findings immediately and remediate within 72 hours, Medium findings within two weeks, and Low findings in a planned sprint. Ask us for the remediation and retest records of a specific assessment.

Critical / High Priority

  • Immediate triage and incident response activation

  • 72-hour remediation target

  • Executive notification if customer data is at risk

  • Re-test with pentest firm before clearing

Medium / Low Priority

  • Tracked in security backlog with owner and due date

  • Medium: 2 weeks; Low: next sprint

  • All findings documented in internal remediation register

  • Annual pentest re-tests previously-closed findings

Access Pentest Results

Updated September 2026

Enterprise customers and security-conscious prospects can request information about available penetration-test summaries and reports. Availability and any NDA requirement are confirmed during review. Request access through the Trust Portal and select "Penetration Test Report" from the document list.

Request available assessment reports