> ## Documentation Index
> Fetch the complete documentation index at: https://docs.casebender.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Independent Penetration Test Scope

> Rules of engagement and minimum coverage for an independent authenticated CaseBender security assessment.

## Objective

Commission an independent, authenticated penetration test of the CaseBender application, APIs, integrations, and supported on-premise deployment. The engagement must produce an evidence-backed report, remediation verification, and a retest letter suitable for customer due diligence.

## In Scope

* Web application and REST/tRPC APIs
* Administrative, analyst, read-only, and deliberately cross-tenant test identities
* Organization and team boundaries, RBAC, object-level authorization, and invitation flows
* Authentication, MFA, sessions, password reset, SSO, and account recovery
* Case, alert, observable, evidence, task, workflow, playbook, and reporting operations
* File upload, archive, document, image, JSON, XML, CSV, and other parser paths
* Outbound integrations, webhook callbacks, HTTP actions, URL enrichment, and SSRF controls
* Secrets, connector credentials, license keys, logs, exports, and error responses
* Audit-event integrity, attribution, ordering, deletion resistance, and privileged changes
* Docker Compose and Kubernetes deployment defaults, service exposure, container privileges, and secrets handling
* Published container images, SBOMs, provenance attestations, and signature verification

## Required Test Cases

1. Attempt horizontal and vertical privilege escalation across every identifier-bearing API.
2. Validate tenant isolation with paired organizations and intentionally overlapping object names.
3. Test mass assignment, unsafe filtering, pagination abuse, race conditions, and replay.
4. Exercise stored, reflected, and DOM XSS plus SQL/NoSQL/command/template injection.
5. Test SSRF with redirects, DNS rebinding, IPv4/IPv6 variants, metadata endpoints, and alternate URL encodings.
6. Fuzz uploads and parsers for traversal, decompression bombs, polyglots, XXE, and malicious filenames.
7. Validate CSRF, CORS, cookie attributes, session rotation, logout invalidation, and token lifetime.
8. Attempt audit suppression, tampering, log injection, and actions without attributable identity.
9. Review default network boundaries, non-root execution, writable paths, capabilities, and exposed management services.
10. Confirm no credentials or customer data appear in client bundles, images, logs, crash output, or build attestations.

## Rules of Engagement

* Use a dedicated production-like environment with synthetic data only.
* Provide written authorization, source IPs, test window, emergency contacts, and stop conditions.
* Permit authenticated testing and safe proof-of-concept exploitation; prohibit destructive persistence and denial-of-service unless separately approved.
* Record tool versions, timestamps, affected release digest, test identities, and complete reproduction steps.
* Notify the CaseBender security contact immediately for Critical findings or evidence of cross-tenant access.

## Deliverables and Acceptance

* Executive and technical reports with CVSS, business impact, evidence, and remediation guidance
* Coverage matrix mapping every in-scope area to tests performed and outcomes
* Explicit limitations and untested areas
* CaseBender triage response with owner and SLA for every finding
* Independent retest of all Critical and High findings
* Signed retest letter identifying the tested release and remaining accepted risks

The engagement is complete only after the retest artifacts are stored in the security evidence register and customer-facing claims are updated to match the verified result.
