Factory Pentest · Roadmap

We break into ourselves
before anyone else can

Factory Pentest is our continuous, in-house penetration testing program. It runs against every surface we ship (the CRM app, the Commerce Admin API, the storefront API, and all 21 live storefronts), and it hands you a signed, tamper-evident report you can actually trust. Because it's our own front door too.

On a mission to be the startup with the best SOC 2 posture that doesn't have a SOC 2 report yet. Working on that part too.

Eating our own dog food

Most security pages ask for your trust. This one hands you the receipts.

Most vendors run one annual pentest, staple the summary to a sales deck, and hope nobody asks what changed in the other 51 weeks. Factory Labs runs the same production platform we sell: same tenant, same deploys, same code path a real buyer hits. So the cheapest way for us to keep customers safe is to keep ourselves safe, continuously, and to make the proof independently verifiable instead of asking anyone to take our word for it.

Continuous coverage · latest run 623 / 624 clean
0

probes every run

missing-auth, injection, mass-assign, isolation

0

routes covered

enumerated from a live inventory, not guessed

0

live storefronts

every revenue-generating chain

0

probes clean

1 low advisory · 0 high · 0 medium

What's covered

Every surface we ship, under the same probe

Four surfaces, one pipeline. Each is exercised for the same class of defect, from the authenticated CRM app down to every buyer storefront.

Factory CRM app

The authenticated platform surface: session auth, tenant isolation, role-based access, and the API routes behind them.

Commerce Admin API

Operator endpoints for catalogs, price schedules, buyers, and promotions. Staff-session-gated, checked for cross-tenant reach.

Storefront API

Buyer-facing cart, catalog, and checkout routes behind the __store cookie / PAT bearer, CSRF, and per-tenant rate limits.

All 21 storefronts

Every revenue-generating chain storefront on the sandbox mirror, probed at the site level for the same class of defects.

What we map, and how

Every finding, in the reviewer's own vocabulary

Coverage is enumerated from a live route inventory, not a hand-waved "we test everything." Pick a framework to see exactly which categories the probe exercises, what it checks for each, and the real pass counts from the latest run.

The classic web application risks. The probe actively exercises the five categories below across all 197 routes and 21 storefronts.

A01

Broken Access Control

Clean

Missing-auth on every route, plus tenant-isolation and admin cross-tenant reach.

191
probes pass
A03

Injection

Clean

SQL-injection and malformed-payload probes on query and body inputs.

68
probes pass
A04

Insecure Design

Clean

Mass-assignment probes and business-flow abuse, including the checkout parity gate.

68
probes pass
A05

Security Misconfiguration

1 low

Security headers, clickjacking, CORS, verbose errors, and diagnostic-endpoint exposure.

1 low: a preview-only diagnostics endpoint (redis-bench) is reachable behind Vercel Deployment Protection. It 404s in production via the environment gate.

294
probes pass
A07

Identification & Authentication Failures

Clean

Authentication enforcement and session / PAT handling on protected routes.

2
probes pass

Not exercised by this run: A02 Cryptographic Failures, A06 Vulnerable & Outdated Components, A08 Software & Data Integrity Failures, A09 Security Logging & Monitoring Failures, and A10 Server-Side Request Forgery are tracked outside this automated probe (TLS config, dependency scanning, and the logging pipeline) and reported in the Trust Center controls catalog.

How Factory Pentest is wired

From live surface to tamper-evident proof

The same pipeline runs on every deploy. Nothing is hand-collected, and nothing about a finished run can be quietly edited after the fact.

probeEvery route is hit unauthenticated and authenticated, safely.classifyEach result is tagged to an OWASP category and a severity.sealThe run is appended to the ledger and time-stamped on-chain.SURFACESCRMCommerce Admin APIStorefront API20+ storefrontsPROBE ENGINEMissing-authInjection / SQLiMass-assignmentTenant isolationEnumeration / rateCLASSIFYOWASP Top 10 (2021)API Top 10 (2023)Severity + fingerprintEVIDENCE CHAINHash-chained ledgerRFC 3161 anchorSigned PDF report
Probe requests
Classified findings
Sealed evidence

The mechanics

How the probe actually runs

  1. 01

    Enumerate the surface

    A generated route inventory lists every endpoint and its expected auth model. New routes show up automatically, so you can't forget to test what you just shipped.

  2. 02

    Probe, safely

    Unauthenticated and authenticated requests exercise missing-auth, injection, mass-assignment, tenant-isolation and enumeration checks. A parity gate blocks any mutation that could touch a real order.

  3. 03

    Classify & score

    Each result becomes a pass or a finding, tagged to its OWASP category and severity, and de-duplicated by fingerprint so the same issue doesn't spam the ledger.

  4. 04

    Seal the evidence

    The run is appended to a hash-chained ledger whose head is stamped by independent RFC 3161 authorities. Tampering with an old entry breaks the chain, visibly.

The deliverable

An authenticated, high-gloss report, and a way to prove it's real

Qualified buyers get the full report through the Trust Center: a Factory Labs-styled PDF with OWASP scorecards, per-surface coverage, dispositions, and residual risk. No screenshot of a spreadsheet, no "trust me."

A PDF is easy to doctor, though. So the roadmap is simple: hash the exact bytes of the report, anchor that hash on-chain alongside the evidence ledger, and publish a verifier. Drop the PDF you were handed into our verify page and we recompute the hash and check it against the chain: genuine, or tampered. No login required to check.

  • Hash-chained evidence ledger, anchored to two independent RFC 3161 authoritiesShipped
  • Authenticated PDF delivery through the Trust CenterShipped
  • Embed the report's SHA-256 in the ledger and stamp it on-chainNext
  • Public verify-by-upload: recompute the hash and confirm it against the chainRoadmap

Verify a reportRoadmap

Upload the PDF

Anyone who receives a report drops the file into the verifier.

We hash the bytes

A SHA-256 is computed client-side and compared, never stored.

Check the chain

The hash is matched against the on-chain, TSA-anchored ledger entry.

Genuine or tampered

A clear verdict, including which run the report belongs to and when it was sealed.

The honest roadmap

Best SOC 2 posture, no SOC 2 report (yet)

We're a startup, and we're not going to pretend an auditor has signed anything they haven't. What we can do is build the evidence a SOC 2 auditor would want to see (continuous testing, tamper-evident logs, independent time-stamping) and let you inspect it today. Here's exactly where each piece stands.

ShippedContinuous pentest of CRM, Commerce Admin, storefront API, and all 21 storefronts
ShippedFindings mapped to OWASP Top 10 (2021) + OWASP API Security Top 10 (2023)
ShippedEvidence chain anchored to RFC 3161 time-stamping authorities
NextReport hash embedded in the ledger and stamped on-chain
RoadmapPublic verify-by-upload endpoint
RoadmapSOC 2 Type II audit with a named CPA firm

From the founders

Why we built our own pentest instead of buying one

There is a whole market that will sell you tens of thousands of dollars of "security" that is mostly readily-available tooling with a logo on top: two scans a year, a PDF, an invoice. That is the nature of legacy SaaS, charging a premium for something you could just run yourself. In most cases you are not really paying for the security. You are paying for the logo on your trust page and the right to call it "independent."

So we didn't buy it. We built something we actually use every day. The same probe runs on every deploy, the results are ours to read, and the proof is verifiable instead of asking anyone to take our word for it. If it is good enough to keep us safe continuously, it is good enough to show you.

Turns out the cheapest way to afford great security was to stop renting it.

The Factory Labs founders

Ready to put ERP truth in front of every rep?

We onboard a limited number of teams each month for hands-on setup, migration support, and ERP connector configuration.