· intuitem · News  · 2 min read

CISO Assistant Q2 2026 penetration test report is now available

Staying true to our commitment to transparency and security, we're publishing the latest CISO Assistant penetration test report, conducted by Synacktiv. All findings were reviewed and remediated within hours.

Staying true to our commitment to transparency and security, we're publishing the latest CISO Assistant penetration test report, conducted by Synacktiv. All findings were reviewed and remediated within hours.

To stay consistent with our commitment to transparency and security, we’re pleased to publish the latest CISO Assistant penetration testing report, conducted by Synacktiv.

Many thanks to their team for the quality of their work, their professionalism, and the excellent collaboration throughout the engagement (hi Renaud and team 👋).

All findings were reviewed and remediated within hours of being reported. To make the report easier to consume, we’ve added a summary page highlighting the key information and results.

Acknowledgment

We would like to thank Synacktiv for conducting this penetration test with exceptional rigor and professionalism. Their comprehensive analysis, clear reporting, and valuable recommendations have strengthened the platform’s security posture.

Tested scope

The application was tested in a PRO SaaS deployment while the testers had access to the source code (CISO Assistant is open source) — a white-box engagement that gives the most thorough coverage possible.

Key findings

RefFindingSeverityStatusNotes
V-01Template injection in audit templatesHigh✅ Patched in v3.16.7Added an extra sandboxing mode. Templates are managed only by admins, who control their quality and security. Defense-in-depth in the infrastructure (rootless containers, network policies) prevented lateral movement and kept the tenant admin within their scope.
V-02Error messages information leakLow✅ DismissedThe surfaced information is not sensitive and is intentionally exposed to help with debugging. All sensitive settings (e.g., secrets) follow a write-only pattern.
V-03Subdomain enumeration through certificate transparencyRemark✅ DeprecatedA legacy TLS-management design choice that was deprecated more than a year ago by moving to a wildcard certificate.

The single High-severity finding (V-01) was patched in v3.16.7, with sandboxing reinforced as a defense-in-depth measure on top of the existing admin-only template controls and infrastructure isolation. The remaining items were either intentional behavior (V-02) or already addressed by an earlier design change (V-03).

Why we publish this

Security is not a checkbox — it’s an ongoing practice. Publishing our pentest results, including the findings and how we handled them, is part of how we hold ourselves accountable to the community and to our customers. We believe an open GRC platform should be transparent about its own security posture.

As always, we welcome your feedback and any security findings through our usual channels.

Back to Blog

Related Posts

View All Posts »
What's New in CISO Assistant — Week 42, 2026 (v4.1.0)

What's New in CISO Assistant — Week 42, 2026 (v4.1.0)

v4.1.0 brings a large rework of the EBIOS RM module (study framing, RO/TO radar, standard and advanced likelihood methods on kill-chain steps), arithmetic in workflows with a CEL compute action, MCP write tools for a full risk review, a delegated user-creator role, entity-assessment exports, the BSI C5:2026 framework, German email templates, and a breaking change to the current-user API.

What's New in CISO Assistant — Week 41, 2026 (v4.0.8 – v4.0.9)

What's New in CISO Assistant — Week 41, 2026 (v4.0.8 – v4.0.9)

v4.0.8 and v4.0.9 let you set a custom score scale on an audit without cloning its framework, bring the SCF 2026.3 framework and a proper ASD Essential Eight (November 2023) model, make every linked-object tab on applied controls able to link existing objects, load long autocomplete lists in batches, and fix a seat-count regression that made readers count as editors.

What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

v4.0.7 brings an in-app notification centre, a risk trajectory view that plays a risk assessment forward in time, X-rays that cover governance and operations and point at active controls with no evidence behind them, per-user module visibility, Mermaid diagrams in documents and PDFs, and workflows that can draft and review documents.

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

v4.0.5 lands a mapping table beside the graph, relation graphs on detail pages, a command palette that can now search and create, workflow steps that record measurements and file scan results — and a Power BI connector release that anyone who upgraded to 4.0 needs to install. v4.0.6 follows with an evidence-upload fix worth taking straight away.