Audit Deliverables
- Written authorization, scope boundaries, and a safe test-environment plan before testing
- Threat model and crown-jewels map
- Attack-surface map across routes, APIs, SDKs, webhooks, admin, deployment, and payments
- Role, tenant-isolation, session, rate-limit, and revenue-leakage checks within the agreed scope
- Prioritized findings with evidence, impact, and fix guidance
- Readiness score, fix tickets, and a retest plan
Testing is limited to the systems and environments authorized in writing. No destructive production tests or third-party targets are included by default.