- Authorised web applications and APIs
- Client-owned infrastructure with documented authority
- Teams that can provide a technical owner and remediation path
Permissioned testing against a defined target and window.
Scoped vulnerability assessment and penetration testing for authorised web, API, network and cloud targets, with evidence and retest planning.
The test boundary is part of the deliverable.
A VAPT engagement should make authorisation, targets, testing method, severity treatment, evidence and retesting explicit.
- Authorisation
- The owner, permitted window and safe-testing rules are recorded.
- Targets
- Applications, APIs, hosts, exclusions and third-party dependencies are listed.
- Method
- Automated and manual testing depth is defined for the scope.
- Deliverable
- Findings, evidence, severity, remediation guidance and retest treatment are stated.
Where it fits.
- No testing before written authorisation
- Social engineering and destructive methods are excluded unless expressly approved
- Certification and legal opinion are separate from technical testing
Testing process.
Authorise
Confirm ownership, targets, window, methods, exclusions, contacts and stop conditions.
Assess and validate
Combine appropriate automated discovery with manual validation inside the agreed boundary.
Report and retest
Deliver risk-ranked evidence, remediation guidance and the agreed verification path.
Common questions.
Can ZenoCloud test infrastructure it does not host?
Yes, when the customer owns or controls the target and supplies written testing authorisation.
Does a VAPT report certify compliance?
No. It can support audit and procurement evidence, but certification and legal conclusions remain with the appropriate independent owners.