OpsRabbit Trust Center

Security Testing and Assurance

Current customer-safe assurance status for OpsRabbit.

PublicVersion 1.0September 2026

Overview

This page summarizes how OpsRabbit identifies, evaluates, remediates and communicates security findings. It separates public customer-safe evidence from detailed reports that may reveal exploitable or sensitive information.

The program combines engineering testing, vulnerability management, targeted AI-security evaluation and independent assessment.

Independent testing

An independent VAPT and remediation cycle was completed in 2026. The customer-facing completion certificate records 8 identified items, 8 resolved and 0 open at retest. Detailed findings, exploit steps and infrastructure information are controlled evidence.

Download VAPT Completion Certificate (PDF)

Evidence request

Customers may request available scope statements, testing evidence and questionnaire responses. Independent reports and detailed security artifacts may require confidentiality terms.

Testing program

Testing combines engineering review, configuration validation, dependency and vulnerability scanning, targeted security tests and independent penetration testing. AI-specific testing covers prompt injection, tool authorization, sensitive-data exposure and approval enforcement. Scope and frequency are based on material change, exposure and customer commitments.

Finding management

Findings are recorded with affected component, evidence, risk, owner, corrective action and target date. Risk assessment considers exploitability, access required, data sensitivity, blast radius and operational consequence. Remediation is retested before closure. Accepted risks and compensating controls require documented approval and review dates.

Evidence release

Customer-safe completion certificates and policy summaries may be public. Detailed reports are provided only when justified, under confidentiality protections and with sensitive exploit, credential, architecture and other-customer information redacted. Requests follow the Audit and Assurance Policy.