· intuitem · News  · 2 min read

CISO Assistant Q2 2026 penetration test report is now available

Staying true to our commitment to transparency and security, we're publishing the latest CISO Assistant penetration test report, conducted by Synacktiv. All findings were reviewed and remediated within hours.

Staying true to our commitment to transparency and security, we're publishing the latest CISO Assistant penetration test report, conducted by Synacktiv. All findings were reviewed and remediated within hours.

To stay consistent with our commitment to transparency and security, we’re pleased to publish the latest CISO Assistant penetration testing report, conducted by Synacktiv.

Many thanks to their team for the quality of their work, their professionalism, and the excellent collaboration throughout the engagement (hi Renaud and team 👋).

All findings were reviewed and remediated within hours of being reported. To make the report easier to consume, we’ve added a summary page highlighting the key information and results.

Acknowledgment

We would like to thank Synacktiv for conducting this penetration test with exceptional rigor and professionalism. Their comprehensive analysis, clear reporting, and valuable recommendations have strengthened the platform’s security posture.

Tested scope

The application was tested in a PRO SaaS deployment while the testers had access to the source code (CISO Assistant is open source) — a white-box engagement that gives the most thorough coverage possible.

Key findings

RefFindingSeverityStatusNotes
V-01Template injection in audit templatesHigh✅ Patched in v3.16.7Added an extra sandboxing mode. Templates are managed only by admins, who control their quality and security. Defense-in-depth in the infrastructure (rootless containers, network policies) prevented lateral movement and kept the tenant admin within their scope.
V-02Error messages information leakLow✅ DismissedThe surfaced information is not sensitive and is intentionally exposed to help with debugging. All sensitive settings (e.g., secrets) follow a write-only pattern.
V-03Subdomain enumeration through certificate transparencyRemark✅ DeprecatedA legacy TLS-management design choice that was deprecated more than a year ago by moving to a wildcard certificate.

The single High-severity finding (V-01) was patched in v3.16.7, with sandboxing reinforced as a defense-in-depth measure on top of the existing admin-only template controls and infrastructure isolation. The remaining items were either intentional behavior (V-02) or already addressed by an earlier design change (V-03).

Why we publish this

Security is not a checkbox — it’s an ongoing practice. Publishing our pentest results, including the findings and how we handled them, is part of how we hold ourselves accountable to the community and to our customers. We believe an open GRC platform should be transparent about its own security posture.

As always, we welcome your feedback and any security findings through our usual channels.

Back to Blog

Related Posts

View All Posts »
What's New in CISO Assistant — Week 37, 2026 (v4.0.2 – v4.0.3)

What's New in CISO Assistant — Week 37, 2026 (v4.0.2 – v4.0.3)

The first two patches after 4.0 are anything but quiet: quick forms turn ad-hoc requests into a real intake channel, every PDF export moves onto one engine, the audit table-mode is rebuilt, workflows gain AI steps, and a focused performance push targets the pages that were slowest to load.

What's New in CISO Assistant — Week 36, 2026 (v3.21.4 – v4.0.1)

What's New in CISO Assistant — Week 36, 2026 (v3.21.4 – v4.0.1)

CISO Assistant reaches 4.0. The headline is a large findings and third-party risk epic — binders, commitments, campaigns, external ratings — landing alongside JIT SSO provisioning, a reworked tasks and evidence module, and a pagination contract that API consumers will want to read before upgrading.

What's New in CISO Assistant — Week 35, 2026 (v3.21.3)

What's New in CISO Assistant — Week 35, 2026 (v3.21.3)

The workflow engine learns to write: an update action with a hard-coded integrity line, date-aware scheduling, and bulk edits that finally emit events. Plus the UNESCO AI Maturity Framework, a feature-flag cache, and a long run of fixes across exports, search, permissions and the framework builder.

What's New in CISO Assistant — Week 34, 2026 (v3.21.1 – v3.21.2)

What's New in CISO Assistant — Week 34, 2026 (v3.21.1 – v3.21.2)

A SCIM account-takeover chain closed, the IAM permission engine rewritten on querysets to lift a hard scaling ceiling, a new aggregated MCP architecture with HTTP transport, and a streamlined approval management interface. Plus manual score overrides, per-template email toggles, and the ISO 27701:2025 outline.