Skip to content
PentestBX — Security is a continuous process
Legal

Security Architecture & Deployment Overview

Technical summary of security, deployment methods, and data management

1. Introduction

This document explains the security architecture, deployment methods, and data management processes of the PentestBX application in a technical yet understandable way. Its purpose is to demonstrate to our customers the reliability of the application, the strength of its data isolation, and its compliance with industry standards.

2. Reliability & validity

Scanning engine standards

  • Vulnerability rules aligned with CVE and OWASP databases are used.
  • The scanning engine operates on the appliance with the same methodology, and the results are fully repeatable.

Data integrity

  • All scan logs are signed with SHA-256.
  • Data is encrypted with AES-2048, whether stored in the cloud or on the appliance.

Reporting

  • Data is normalised to generate comparable reports across different scans.
  • Reports guarantee the validity and reliability of the results.

3. Penetration tests and access

Testing process

  • At least once a year, penetration tests are conducted by independent cybersecurity firms at both the network and application layers.
  • The tests simulate real attacker behaviours.

Access and reporting

  • Reports are restricted to our authorised security team and, if requested, designated customer representatives.
  • Customers receive summary reports showing that vulnerabilities are resolved; sensitive details are kept internal.

4. Deployment methods

We offer our customers two deployment options.

A. Cloud deployment
Customer data is stored in separate and isolated databases. Data transmission is encrypted using TLS 1.3 and data at rest is protected with AES-2048 encryption. Role-Based Access Control is enforced, and all accesses and actions are logged.
B. On-premise appliance
The appliance operates in a virtual environment within the customer's network. It connects to the cloud only via VPN and has no direct internet access. Data is stored encrypted and isolated on the appliance, with access control and audit logging enforced.

Both methods apply encryption, access controls, and network isolation by default.

5. Server locations and commitments

Our cloud servers are hosted in ISO 27001 and SOC 2 certified data centres in Türkiye and Europe. We commit to:

  • Secure and redundant storage of data.
  • Authorised user access only.
  • Strict application and database isolation.
  • Highest level of privacy protection.
  • Network and host-level segmentation.
  • Logs and scan results stored with integrity guarantees.

6. Summary & assurance

  • Industry-standard vulnerability scanning and data handling.
  • Security ensured through encryption, RBAC, audit logging, and network isolation.
  • Continuous security maintained via independent penetration tests and regular updates.
  • Flexible and secure customer data control through cloud or on-premise deployment options.