Question

Is there a published policy for penetration testing my droplets

Where a pentest is required for compliance is there a documented policy for the third-party pentesters?


Submit an answer


This textbox defaults to using Markdown to format your answer.

You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!

Sign In or Sign Up to Answer

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

alexdo
Site Moderator
Site Moderator badge
July 6, 2023

Heya,

You can find some information in our TOS.

Generally this type of testing is ok as long as it’s not detrimental to service in terms of negatively affecting others on the platform / your hypervisor. Our Security team at that point will take action on that Droplet or if the pattern repeats the account.

This would include reasons like, but is not limited to: large bandwidth usage, CPU resource usage, etc. originating from or sending to a Droplet.

Our Security Operations team would always try to be transparent with communication if the above scenarios ever did occur. You would get a ticket asking for more details on what you were doing + to stop the negative effects. If you could spread the penetration tests across several Droplets in various regions, that may help to reduce the load for one hypervisor in particular.

You can read our Terms of Service here to ensure no other issues from your use-case will alert our Security Operations team: https://www.digitalocean.com/legal/terms-of-service-agreement/

If you have any other questions or need clarification on anything, just write back in and let us know! :)

KFSys
Site Moderator
Site Moderator badge
July 5, 2023

Hey @sethcoral,

There isn’t any compliance documention as far as I’m aware as you are the owner of the Droplet. Having said that, if there is any heavy traffic to the Droplet, it’s possible DigitalOcean’s systems indicate this as some-kind of an attack towards your Droplet and prevent it.

In that regard, I’ll recommend contacting DigitalOcean’s support just to give a heads up about the upcoming pentest.

Try DigitalOcean for free

Click below to sign up and get $200 of credit to try our products over 60 days!

Sign up

Get our biweekly newsletter

Sign up for Infrastructure as a Newsletter.

Hollie's Hub for Good

Working on improving health and education, reducing inequality, and spurring economic growth? We'd like to help.

Become a contributor

Get paid to write technical tutorials and select a tech-focused charity to receive a matching donation.

Welcome to the developer cloud

DigitalOcean makes it simple to launch in the cloud and scale up as you grow — whether you're running one virtual machine or ten thousand.

Learn more
DigitalOcean Cloud Control Panel