Authorised testing
Testing starts only after scope, hosts, dates, rate limits, write permissions and Rules of Engagement are documented.
Kotav Labs delivers authorised security assessments through a controlled engagement model. This page states what we protect, how delivery is governed and where our boundaries are.
Testing starts only after scope, hosts, dates, rate limits, write permissions and Rules of Engagement are documented.
Assessment infrastructure and evidence are hosted in Germany. Subprocessors and any additional processing locations are disclosed per engagement.
Material findings receive specialist review. Deliverables use verified evidence and an audit-suitable report, with PDF and SARIF where applicable.
Tenant-scoped access, explicit roles and server-side authorisation protect customer records and operational actions.
HttpOnly sessions, rotating refresh tokens, TOTP MFA, one-time backup codes and encrypted secrets protect browser accounts.
Assessment jobs, finding changes, retest requests, role changes and sensitive administrative actions produce attributable records.
Kotav does not present Argus Sentinel as 24/7 monitoring or incident response, and does not guarantee certification. Retention, subprocessors, testing permissions and deliverables are agreed for each engagement.
A DPA, security FAQ, subprocessor disclosure, sample deliverables and technical answers are available during qualification under appropriate confidentiality terms.