Overview
This page summarizes how OpsRabbit identifies, evaluates, remediates and communicates security findings. It separates public customer-safe evidence from detailed reports that may reveal exploitable or sensitive information.
The program combines engineering testing, vulnerability management, targeted AI-security evaluation and independent assessment.
Independent testing
An independent VAPT and remediation cycle was completed in 2026. The customer-facing completion certificate records 8 identified items, 8 resolved and 0 open at retest. Detailed findings, exploit steps and infrastructure information are controlled evidence.
Evidence request
Customers may request available scope statements, testing evidence and questionnaire responses. Independent reports and detailed security artifacts may require confidentiality terms.
Testing program
Testing combines engineering review, configuration validation, dependency and vulnerability scanning, targeted security tests and independent penetration testing. AI-specific testing covers prompt injection, tool authorization, sensitive-data exposure and approval enforcement. Scope and frequency are based on material change, exposure and customer commitments.
Finding management
Findings are recorded with affected component, evidence, risk, owner, corrective action and target date. Risk assessment considers exploitability, access required, data sensitivity, blast radius and operational consequence. Remediation is retested before closure. Accepted risks and compensating controls require documented approval and review dates.
Evidence release
Customer-safe completion certificates and policy summaries may be public. Detailed reports are provided only when justified, under confidentiality protections and with sensitive exploit, credential, architecture and other-customer information redacted. Requests follow the Audit and Assurance Policy.