Saltar al contenido principal
Pen testing · política pública

Penetration testing policy

Cadencia anual + post-cambio mayor · scope OWASP Top 10 + API + infra · vendor externo certificado (OSCP/CREST/CEH) · disclosure responsable · re-test obligatorio · findings públicos resumidos. Política pública para transparencia + procurement Enterprise.

Scope · 6 áreas

ÁreaCoverageFrecuencia
Web application · landing + adminOWASP Top 10 2021 · authn/authz · injection · XSS · CSRF · IDOR · SSRF · business logic flawsAnual + post-cambio mayor (refactor 30%+ código admin · nueva feature high-risk)
WhatsApp webhook · process-message pipelineWebhook signature validation · idempotency · rate limiting · prompt injection · output guardrails bypass attemptsAnual + post-cambio process-message.ts
API endpoints públicosAuthentication bypass · rate limit bypass · enumeration · IDOR · mass assignment · CORS misconfigurationAnual
Infrastructure · Cloudflare + Supabase + UpstashConfig review (Cloudflare WAF rules · Supabase RLS policies · Upstash auth tokens) · secret leakage scanSemestral (Q2/Q4)
Mobile · NO actual (futuro)Cuando app patient/clinic admin móvil ship · OWASP MASVS L1+L2Pre-launch + anual
Social engineering · NO actualPhishing campaign founder/staff · vishing pretexting · physical access (oficina N/A)Cuando team ≥5 personas · planned post-tracción primeros 5 clientes

Vendor criteria · 6 requisitos

Certificación vendor
OSCP · CREST · CEH · OSEP equivalent · 5+ años experiencia healthcare/fintech
Insurance + bonding
Cyber liability ≥1M EUR · errors & omissions · indemnification clause contractual
Methodology transparente
PTES · OSSTMM · OWASP WSTG · NIST SP 800-115 · adapted per scope
Reporting estándar
Executive summary · technical findings con CVSS 3.1 · remediation guidance · evidence reproducible · re-test certification
Data handling
EU jurisdicción · DPA mutuo · zero retention findings post-engagement · encrypted communications + storage · NDA contractual
Disclosure policy
Responsible disclosure · embargo 90d max · CVE assignment si aplica · no público disclosure sin client approval

Timeline standardized · 8 hitos

Independiente del vendor seleccionado · todo pen test sigue mismo flow para predictibilidad + comparison year-over-year metrics.

  1. M-30d · Scoping call vendor · define scope written · environment access · accounts test · contract + SOW + DPA signed
  2. M0 · Kickoff · vendor begins testing · daily sync calls · slack channel dedicated · monitoring our side (no obstrucción)
  3. M+7-14d · Active testing concluido · vendor preparing report · findings categorized CVSS Critical/High/Medium/Low
  4. M+21d · Draft report delivered · client review (founder + technical advisor) · clarification calls · evidence verification
  5. M+30d · Final report · CRITICAL fixes immediate (≤48h) · HIGH fixes ≤1 week · MEDIUM ≤30d · LOW ≤90d
  6. M+60d · Retesting CRITICAL + HIGH fixes · vendor verification fix correctly applied · re-test certification issued
  7. M+90d · Public summary published · `/security` page updated · /trust page metrics updated · post-mortem internal
  8. M+365d · Next annual pen test scheduled · scope updated based on infra changes año · vendor evaluation (same vs rotate)

Findings history · transparente

FechaScopeCritical/HighMedium/LowVendorRemediation
2026-04-10Web app + API · 18 endpoints0 Critical · 1 High3 Medium · 5 LowInternal automated only (Snyk · OWASP ZAP · npm audit)100% findings remediated 30d · public summary `/security`
2026-02-15Infrastructure review · Cloudflare + Supabase + Upstash0 Critical · 0 High2 Medium · 4 LowInternal review founder + ChatGPT auditorAll remediated 14d · Cloudflare WAF rules tightened · Supabase RLS audit passed
TBD post-CIF Q3 2026Full external pen testPlannedPlannedExternal certified vendor (TBD · scope: web + API + WhatsApp pipeline)Budget allocated post-tracción primeros 5 clientes pagando
Honest disclosure · pre-revenue stage

External pen test full <6 meses NO realizado todavía. Razón: pre-revenue · budget allocated post-CIF + primeros 5 clientes pagando (Q3 2026 estimated). Mitigation actual: automated tooling continuo (Snyk · OWASP ZAP · npm audit · Sentry) + internal review (founder + ChatGPT auditor adversarial bundle weekly).

Esta transparencia es deliberada: muchos competidores afirman SOC2/ISO sin pen tests externos reales. Nuestra política pública compromete external pen test pre-procurement Enterprise · NO cuando alguien pregunta.

¿Tu security team necesita pen test reports?

Cuando first external pen test esté completado (Q3 2026 planned) · executive summary + redacted technical report disponibles bajo NDA Enterprise. Útil security review pre-procurement.