SVC—06 · ASSESSMENT
Cloud penetration testing
We review configuration against the provider's rules and perform only the exploitation authorized in the rules of engagement.
Start scopingTEST BOUNDARY
What sits inside the boundary
ACCESS MODES
Knowledge level is scoped
DELIVERY—LEDGER
Deliverables you can inspect.
Privilege and trust-path analysis
Configuration and exploitation evidence kept separate
Remediation plan aligned to provider constraints
Accounts, services and regions
IAM and Kubernetes complexity
Hybrid links and provider restrictions
Testing must follow each provider's authorization policy
Client-owned and third-party assets are distinguished explicitly
POINT—IN—TIME
Precision includes what we do not claim.
A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.
Method and limitations