# Penetration test scope (Phase 3) **Status:** Scope pack for an independent tester **Date:** 2026-08-12 **In-repo evidence folder:** `security-reports/` (attach PDF/HTML outputs here; do not commit secrets) ## In scope - Public marketing site, Carplace booking, company dashboard, admin console - API ` /api/v1/* `, `/health`, `/ready`, `/metrics` (metrics should not expose PII) - Auth: employee, renter, admin (incl. 2FA), company API keys - Multi-tenant isolation (IDOR across companies) - Payments / webhooks (signature bypass attempts) - File upload / private media paths - Session cookies, CSRF on cookie mutations, redirect/open-redirect ## Out of scope (unless separately contracted) - Physical / social engineering - Third-party Clerk/payment provider infrastructure itself - DoS that risks shared staging cost blowups (use agreed soak limits) ## Priority assertions to verify 1. No password hashes, TOTP secrets, raw invite/reset/review tokens in API JSON (**S11 closed in code**) 2. Cross-tenant resource access returns 404 without leakage 3. Webhook endpoints reject unsigned/forged payloads 4. Admin money-moving actions require fresh 2FA where designed 5. Container/Docker orchestration remains disabled (ADR-001) ## Exit for Phase 3 - [ ] Independent report attached under `security-reports/` - [ ] All Critical/High findings fixed or formally accepted with owner + date - [ ] Retest of fixed Critical/High completed ## Suggested tooling (tester choice) OWASP ZAP / Burp, authenticated scripted checks mirroring `cross-tenant-isolation.test.ts`, dependency SCA already in CI.