We engage an external offensive security firm twice a year for a full-scope penetration test against our production environment.
In between, we run continuous internal red-team exercises against a staging environment that mirrors production. Findings flow into the same security bug queue as any other vulnerability.
We share executive summaries of pentest results with customers under NDA. The remediation tracking is shared with customers who request it.
