Your findings never
leave your walls.
Penetration test findings are among the most sensitive documents an organization owns. This page answers the questions security and procurement teams ask us, starting with the most important one: what can leave your network.
What can leave.
Precisely.
Neuron does not claim that a connected server makes no network traffic at all. It makes a stronger claim: none of the traffic it can make carries the contents of your engagements. Every outbound capability ships switched off, and each one asks an administrator for confirmation before it connects.
Neuron collects no usage analytics, telemetry or crash reports, and validates its license on the server with no heartbeat.
| Connection | When | What it carries | Air-gapped |
|---|---|---|---|
| Engagement data | Never | Findings, evidence, credentials, client details, AI prompts and output stay in your database. | Never |
| License activation | Once, when an administrator activates online | License serial and a hardware fingerprint | One file carried out by hand |
| Update check | Only when an administrator runs one | Current version and platform | Does not happen |
| Software and model downloads | When an administrator starts one | Nothing is uploaded; the file comes in | Carried in on media |
| Public security feeds | Only if an administrator enables them | A request for public vulnerability and technique data | Left off |
| Your own integrations | If you configure them | Traffic to systems you operate: email, SSO, ServiceNow | Flagged while Offline Mode is on |
AI with an owner.
Always a person.
Neuron AI is an optional module, licensed and deployed separately from Core. Our Responsible AI Policy sets out where it runs, what data it touches, who reviews its output and who is responsible for what.
On-premises inference
Models run on your hardware. Prompts and completions never leave your trust boundary, and there is no hosted AI provider or fallback behind Neuron.
Vendor-supplied, signed models
Models come from PenTest.WS through the signed update channel. Customers do not load arbitrary models, and a model without the official marker is refused.
Human approval is structural
AI output lands in the same fields and the same QA workflow as human writing. Nothing it drafts reaches a client without reviewer approval.
No training on your data
We do not collect, transmit or train on prompts or completions, and the product has no facility to do so. The AI module emits no telemetry.
Known limits, stated
Models can be wrong, generic or out of date. The policy names those failure modes and makes the operator the author of record.
Clear responsibilities
A vendor and customer responsibility matrix covers models, hardware, review, access and defect handling.
Built like the people
who will test it.
Our customers break into systems for a living. These are the controls they find when they look.
SSO, MFA and no auto-provisioning
SAML 2.0 with signed assertions or OIDC with PKCE. MFA with backup codes. An administrator creates every account before its first sign-in.
A superadmin that stays out of the work
The superadmin signs in with a local password only, cannot use SSO, cannot reach day-to-day work and cannot manage API tokens.
Nobody approves their own work
Reviewer and approver must be different people, and a submitter can never be forwarded back as their own reviewer.
Your key, on your server
Sensitive fields are encrypted at rest with AES-256-GCM under a key held on your server. Components talk over TLS, verified by pinning or your internal CA.
A DMZ service with nothing to steal
The Delivery Portal holds no database and no encryption keys. Unreleased findings return not found, and lockouts never confirm that an address exists.
Re-checked on every request
IP allowlists are enforced on every page load, data endpoints are rate limited to 60 requests a minute per IP, and session cookies are HMAC-signed.
Signed releases
Every download ships with a SHA256SUMS file and a signature against the Neuron release key. The AI host installs only signed builds.
Who did what, and when
Admin, portal and AI activity logs, attributed track changes, per-field provenance on findings, and per-round retest audit trails.
Unsafe setups are called out
Neuron warns when Core listens on plain HTTP on a reachable address, and refuses to start if the clock jumps backwards or the database was upgraded by a newer version.
Documented,
not improvised.
- Policies
- Information Security Policy, Information Security Standards, Enterprise Risk Management, Asset Management, Acceptable Use, Human Resource Security, Cloud Security, Encryption Key Management Standard, Incident Response Plan, Business Continuity and Disaster Recovery, and AI Governance.
- Approach
- Informed by ISO/IEC 27001 and 27002 and the NIST Cybersecurity Framework. This describes our approach, not a certification.
- Your data
- Out of scope by design. Neuron runs on your infrastructure, and we hold none of your engagement data.
- On request
- The Neuron Technical Whitepaper, our policy set, completed security questionnaires and an IPv6 capability attestation for PenTest.WS Pro, shared during procurement. Ask our team.
Found something?
Tell us first.
Report suspected vulnerabilities in PenTest.WS products or websites to [email protected]. Include enough detail for us to reproduce the issue.
We will acknowledge your report, keep you updated while we investigate, and credit you if you would like. Please give us a reasonable time to fix the issue before disclosing it publicly, and do not access, change or delete data that is not yours.
We will not pursue legal action against research carried out in good faith under this policy.
Our contact details are also published in security.txt.
Questions we
get asked.
Do you have sub-processors for our engagement data?
No. Neuron runs on your infrastructure and engagement data never reaches us, so no third party processes it on our behalf.
Can we verify that nothing leaves?
Yes. Put the server behind a firewall that denies outbound traffic and watch the logs. Neuron keeps working, including its AI, and there is nothing for it to send.
Which certifications do you hold?
None. Neuron runs inside your boundary and we never hold your data, so the controls that matter sit in the product and in your environment. Our security policies are informed by ISO/IEC 27001 and 27002 and the NIST Cybersecurity Framework, and they are available during procurement.
What happens to our deployment if something happens to PenTest.WS?
Neuron validates its license locally and needs no connection to us to keep running for the license term, and your data is already in your own database. There is no hosted service to switch off.
How do you handle security defects in Neuron?
Report them to [email protected]. We investigate, fix and ship the fix as a signed release, and customers apply it through their normal update path, including air-gapped installs.
Can you fill in our security questionnaire?
Yes. We have completed standard questionnaires, including the Shared Assessments SIG Lite, and can answer yours during procurement.
Questions from your security team?
We are happy to walk your security and procurement teams through deployment, data handling and our controls.