Safety and trust

Autonomous speed needs explicit boundaries.

Pentoma combines AI-assisted testing with human validation, scoped authorization, non-destructive evidence collection, and audit-ready reporting.

Controls

The safety model is part of the product.

These controls explain how Pentoma earns trust: bounded targets, safe validation, human sign-off, and evidence that remains auditable.

Scope control

Assessments run only against verified targets, connected repositories, or registered AI endpoints that are explicitly approved for the engagement.

Non-destructive validation

Pentoma validates exploitability with controlled replay, test accounts, safe payloads, and customer-approved boundaries instead of disruptive production actions.

Human review

AI can discover and draft candidate findings, but customer-facing confirmation requires reviewer validation of scope, impact, severity, and remediation quality.

Cancellation and stop path

Assessments need an operator-visible stop path so scoped testing can be paused or cancelled if customer risk, availability, or scope changes.

Data handling

Credentials, source context, prompts, request evidence, and report artifacts are treated as scoped engagement material and minimized to what the assessment needs.

Auditability

Finding status, false-positive dismissal, remediation state, retest results, and report exports are retained as evidence for engineering and compliance review.

Engagement scope policy

Testing only happens against authorized assets.

Scope is documented, signed, and versioned before any traffic is generated. Discoveries outside that boundary are reported, not pursued.

Authorized targets only

Pentoma never tests assets it has not been authorized to test. Every engagement requires a signed scope statement that lists assets, surfaces, environments, and roles.

Out-of-scope discovery handling

Issues discovered outside the agreed scope are documented separately and are not exploited beyond what is required to confirm they exist.

Versioned scope amendments

Adding or removing a target during an active engagement requires an updated written scope before testing continues on the new surface.

Production-safe testing

Default mode protects availability.

Pentoma is built to validate impact without causing it. Anything that could disrupt production is gated on written approval, environment selection, and customer-controlled stop conditions.

Non-destructive by default

Default mode is non-destructive: no data deletion, no privilege escalation beyond what is needed to confirm an authorization issue, and no denial-of-service testing.

Destructive tests require approval

Destructive testing only happens with explicit written approval and against a designated environment agreed in advance.

Configurable rate and timing

Rate limits and time windows are configured per engagement to match maintenance schedules and on-call coverage.

Pause or stop on request

The customer can pause or stop an active engagement at any time. Operators have a visible stop path during the run.

Authentication and credentials

Test credentials are scoped, encrypted, and short-lived.

Credentials provided for an engagement are treated as sensitive material with a clear lifecycle: encrypted while in use, scoped to the surface being tested, and removed when the engagement closes.

Encrypted at rest, removed at close

Test credentials provided by the customer are stored encrypted at rest and removed at engagement close.

No cross-engagement reuse

Pentoma does not reuse credentials across engagements. Each engagement is provisioned with its own test accounts and secrets.

Scoped to the test surface

Credentials are scoped to the test surface only and are not used to access systems outside the agreed scope.

Evidence and data handling

Evidence stays inside the engagement that produced it.

Findings, captures, and supporting context live in per-engagement storage, are minimized to what the assessment needs, and follow a clear retention and deletion path.

Per-engagement storage

Findings, request/response captures, source paths, and prompt transcripts are stored in scoped per-engagement storage.

Data minimization

Customer data captured incidentally during testing is minimized: redacted before review where possible, and removed when not needed for evidence.

Retention

Standard retention is the duration of the engagement plus the retest window. Longer retention is opt-in by the customer for audit purposes.

Deletion on request

Customers can request deletion of their evidence after delivery. Removal is confirmed in writing.

AI usage transparency

AI accelerates work. Humans confirm findings.

Pentoma is explicit about where AI helps and where it does not decide. Customer material stays out of model training pipelines.

Commercial models for discovery and reasoning

Pentoma uses leading commercial AI models for discovery and reasoning during assessments.

Human sign-off on every finding

AI outputs are never accepted as findings without deterministic replay and human validation sign-off.

No training on customer material

Customer-provided source code, configurations, and credentials are not used to train or fine-tune any third-party model. Provider terms used by Pentoma prohibit training on submitted data.

Audit logs

Lifecycle events are recorded and exportable.

Customer admins should be able to reconstruct what happened during an engagement without filing a request.

What is logged

Pentoma logs scope changes, evidence access, report exports, and engagement lifecycle events.

Customer-visible audit trail

Customer admins can review and export audit log entries for their own engagements.

Insurance and liability

Coverage is in place; specifics travel under NDA.

Insurance is part of how Pentoma takes responsibility for the work. The public commitment is deliberately general; coverage detail is shared with procurement under NDA.

Pentoma maintains commercial insurance appropriate for application security testing. Coverage specifics are shared under NDA during procurement.

Incident escalation

When something is wrong, the customer hears from us first.

Two situations always trigger direct contact with the customer security contact: active exploitation discovered in scope, and any unintended impact caused by testing.

Active exploitation discovered

If Pentoma discovers a critical issue actively being exploited, the customer security contact is paged according to the agreed engagement runbook.

Unintended impact during testing

If an engagement causes unintended impact, Pentoma stops, notifies the customer security contact, and works the incident jointly until resolution.

Disclosure and operations

Clear contact paths reduce risk during testing.

Pentoma should make it easy for customers and researchers to route security issues, scope questions, urgent pause requests, and report corrections.

Security disclosures: security@se.works
Assessment scope questions: use the sales and delivery handoff before testing starts.
Urgent testing pause: contact the assigned engagement owner or support path listed in the assessment kickoff.
Signed webhooks: assessment and finding events should use HMAC verification for customer workflow integrations.
Report corrections: request updates through the remediation/retest window so evidence stays versioned.

For urgent disclosure, email security@se.works.

Include affected surface, reproduction steps, observed impact, and any relevant evidence. Do not test outside approved scope.