Where a pentest is required for compliance is there a documented policy for the third-party pentesters?
This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.
Enter your email to get $200 in credit for your first 60 days with DigitalOcean.
New accounts only. By submitting your email you agree to our Privacy Policy.
Heya,
You can find some information in our TOS.
Generally this type of testing is ok as long as it’s not detrimental to service in terms of negatively affecting others on the platform / your hypervisor. Our Security team at that point will take action on that Droplet or if the pattern repeats the account.
This would include reasons like, but is not limited to: large bandwidth usage, CPU resource usage, etc. originating from or sending to a Droplet.
Our Security Operations team would always try to be transparent with communication if the above scenarios ever did occur. You would get a ticket asking for more details on what you were doing + to stop the negative effects. If you could spread the penetration tests across several Droplets in various regions, that may help to reduce the load for one hypervisor in particular.
You can read our Terms of Service here to ensure no other issues from your use-case will alert our Security Operations team: https://www.digitalocean.com/legal/terms-of-service-agreement/
If you have any other questions or need clarification on anything, just write back in and let us know! :)
Hey @sethcoral,
There isn’t any compliance documention as far as I’m aware as you are the owner of the Droplet. Having said that, if there is any heavy traffic to the Droplet, it’s possible DigitalOcean’s systems indicate this as some-kind of an attack towards your Droplet and prevent it.
In that regard, I’ll recommend contacting DigitalOcean’s support just to give a heads up about the upcoming pentest.