We break into ourselves
before anyone else can
Factory Pentest is our continuous, in-house penetration testing program. It runs against every surface we ship (the CRM app, the Commerce Admin API, the storefront API, and all 21 live storefronts), and it hands you a signed, tamper-evident report you can actually trust. Because it's our own front door too.
On a mission to be the startup with the best SOC 2 posture that doesn't have a SOC 2 report yet. Working on that part too.
Eating our own dog food
Most security pages ask for your trust. This one hands you the receipts.
Most vendors run one annual pentest, staple the summary to a sales deck, and hope nobody asks what changed in the other 51 weeks. Factory Labs runs the same production platform we sell: same tenant, same deploys, same code path a real buyer hits. So the cheapest way for us to keep customers safe is to keep ourselves safe, continuously, and to make the proof independently verifiable instead of asking anyone to take our word for it.
probes every run
missing-auth, injection, mass-assign, isolation
routes covered
enumerated from a live inventory, not guessed
live storefronts
every revenue-generating chain
probes clean
1 low advisory · 0 high · 0 medium
What's covered
Every surface we ship, under the same probe
Four surfaces, one pipeline. Each is exercised for the same class of defect, from the authenticated CRM app down to every buyer storefront.
Factory CRM app
The authenticated platform surface: session auth, tenant isolation, role-based access, and the API routes behind them.
Commerce Admin API
Operator endpoints for catalogs, price schedules, buyers, and promotions. Staff-session-gated, checked for cross-tenant reach.
Storefront API
Buyer-facing cart, catalog, and checkout routes behind the __store cookie / PAT bearer, CSRF, and per-tenant rate limits.
All 21 storefronts
Every revenue-generating chain storefront on the sandbox mirror, probed at the site level for the same class of defects.
What we map, and how
Every finding, in the reviewer's own vocabulary
Coverage is enumerated from a live route inventory, not a hand-waved "we test everything." Pick a framework to see exactly which categories the probe exercises, what it checks for each, and the real pass counts from the latest run.
The classic web application risks. The probe actively exercises the five categories below across all 197 routes and 21 storefronts.
Broken Access Control
Missing-auth on every route, plus tenant-isolation and admin cross-tenant reach.
Injection
SQL-injection and malformed-payload probes on query and body inputs.
Insecure Design
Mass-assignment probes and business-flow abuse, including the checkout parity gate.
Security Misconfiguration
Security headers, clickjacking, CORS, verbose errors, and diagnostic-endpoint exposure.
1 low: a preview-only diagnostics endpoint (redis-bench) is reachable behind Vercel Deployment Protection. It 404s in production via the environment gate.
Identification & Authentication Failures
Authentication enforcement and session / PAT handling on protected routes.
Not exercised by this run: A02 Cryptographic Failures, A06 Vulnerable & Outdated Components, A08 Software & Data Integrity Failures, A09 Security Logging & Monitoring Failures, and A10 Server-Side Request Forgery are tracked outside this automated probe (TLS config, dependency scanning, and the logging pipeline) and reported in the Trust Center controls catalog.
How Factory Pentest is wired
From live surface to tamper-evident proof
The same pipeline runs on every deploy. Nothing is hand-collected, and nothing about a finished run can be quietly edited after the fact.
The mechanics
How the probe actually runs
- 01
Enumerate the surface
A generated route inventory lists every endpoint and its expected auth model. New routes show up automatically, so you can't forget to test what you just shipped.
- 02
Probe, safely
Unauthenticated and authenticated requests exercise missing-auth, injection, mass-assignment, tenant-isolation and enumeration checks. A parity gate blocks any mutation that could touch a real order.
- 03
Classify & score
Each result becomes a pass or a finding, tagged to its OWASP category and severity, and de-duplicated by fingerprint so the same issue doesn't spam the ledger.
- 04
Seal the evidence
The run is appended to a hash-chained ledger whose head is stamped by independent RFC 3161 authorities. Tampering with an old entry breaks the chain, visibly.
The deliverable
An authenticated, high-gloss report, and a way to prove it's real
Qualified buyers get the full report through the Trust Center: a Factory Labs-styled PDF with OWASP scorecards, per-surface coverage, dispositions, and residual risk. No screenshot of a spreadsheet, no "trust me."
A PDF is easy to doctor, though. So the roadmap is simple: hash the exact bytes of the report, anchor that hash on-chain alongside the evidence ledger, and publish a verifier. Drop the PDF you were handed into our verify page and we recompute the hash and check it against the chain: genuine, or tampered. No login required to check.
- Hash-chained evidence ledger, anchored to two independent RFC 3161 authoritiesShipped
- Authenticated PDF delivery through the Trust CenterShipped
- Embed the report's SHA-256 in the ledger and stamp it on-chainNext
- Public verify-by-upload: recompute the hash and confirm it against the chainRoadmap
Verify a reportRoadmap
Upload the PDF
Anyone who receives a report drops the file into the verifier.
We hash the bytes
A SHA-256 is computed client-side and compared, never stored.
Check the chain
The hash is matched against the on-chain, TSA-anchored ledger entry.
Genuine or tampered
A clear verdict, including which run the report belongs to and when it was sealed.
The honest roadmap
Best SOC 2 posture, no SOC 2 report (yet)
We're a startup, and we're not going to pretend an auditor has signed anything they haven't. What we can do is build the evidence a SOC 2 auditor would want to see (continuous testing, tamper-evident logs, independent time-stamping) and let you inspect it today. Here's exactly where each piece stands.
From the founders
Why we built our own pentest instead of buying one
There is a whole market that will sell you tens of thousands of dollars of "security" that is mostly readily-available tooling with a logo on top: two scans a year, a PDF, an invoice. That is the nature of legacy SaaS, charging a premium for something you could just run yourself. In most cases you are not really paying for the security. You are paying for the logo on your trust page and the right to call it "independent."
So we didn't buy it. We built something we actually use every day. The same probe runs on every deploy, the results are ours to read, and the proof is verifiable instead of asking anyone to take our word for it. If it is good enough to keep us safe continuously, it is good enough to show you.
Turns out the cheapest way to afford great security was to stop renting it.
The Factory Labs founders
Ready to put ERP truth in front of every rep?
We onboard a limited number of teams each month for hands-on setup, migration support, and ERP connector configuration.