Objective
Commission an independent, authenticated penetration test of the CaseBender application, APIs, integrations, and supported on-premise deployment. The engagement must produce an evidence-backed report, remediation verification, and a retest letter suitable for customer due diligence.In Scope
- Web application and REST/tRPC APIs
- Administrative, analyst, read-only, and deliberately cross-tenant test identities
- Organization and team boundaries, RBAC, object-level authorization, and invitation flows
- Authentication, MFA, sessions, password reset, SSO, and account recovery
- Case, alert, observable, evidence, task, workflow, playbook, and reporting operations
- File upload, archive, document, image, JSON, XML, CSV, and other parser paths
- Outbound integrations, webhook callbacks, HTTP actions, URL enrichment, and SSRF controls
- Secrets, connector credentials, license keys, logs, exports, and error responses
- Audit-event integrity, attribution, ordering, deletion resistance, and privileged changes
- Docker Compose and Kubernetes deployment defaults, service exposure, container privileges, and secrets handling
- Published container images, SBOMs, provenance attestations, and signature verification
Required Test Cases
- Attempt horizontal and vertical privilege escalation across every identifier-bearing API.
- Validate tenant isolation with paired organizations and intentionally overlapping object names.
- Test mass assignment, unsafe filtering, pagination abuse, race conditions, and replay.
- Exercise stored, reflected, and DOM XSS plus SQL/NoSQL/command/template injection.
- Test SSRF with redirects, DNS rebinding, IPv4/IPv6 variants, metadata endpoints, and alternate URL encodings.
- Fuzz uploads and parsers for traversal, decompression bombs, polyglots, XXE, and malicious filenames.
- Validate CSRF, CORS, cookie attributes, session rotation, logout invalidation, and token lifetime.
- Attempt audit suppression, tampering, log injection, and actions without attributable identity.
- Review default network boundaries, non-root execution, writable paths, capabilities, and exposed management services.
- Confirm no credentials or customer data appear in client bundles, images, logs, crash output, or build attestations.
Rules of Engagement
- Use a dedicated production-like environment with synthetic data only.
- Provide written authorization, source IPs, test window, emergency contacts, and stop conditions.
- Permit authenticated testing and safe proof-of-concept exploitation; prohibit destructive persistence and denial-of-service unless separately approved.
- Record tool versions, timestamps, affected release digest, test identities, and complete reproduction steps.
- Notify the CaseBender security contact immediately for Critical findings or evidence of cross-tenant access.
Deliverables and Acceptance
- Executive and technical reports with CVSS, business impact, evidence, and remediation guidance
- Coverage matrix mapping every in-scope area to tests performed and outcomes
- Explicit limitations and untested areas
- CaseBender triage response with owner and SLA for every finding
- Independent retest of all Critical and High findings
- Signed retest letter identifying the tested release and remaining accepted risks