> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/reports-and-audits/penetration-test-summary.md).

# Penetration test summary

The security testing activities carried out on the AIsuru platform.

Memori runs penetration tests on the AIsuru platform to identify vulnerabilities before malicious actors can exploit them. Tests are run on Memori's own initiative and after major feature releases.

### What is tested

Testing covers the main attack vectors relevant to a SaaS/PaaS platform:

* **Application security:** OWASP Top 10 tests, injection, broken access control, security misconfiguration, XSS, CSRF
* **API security:** verification of the REST endpoints exposed by the main components of the platform, authentication and authorization, rate limiting
* **Session management:** analysis of authentication mechanisms (magic link, JWT tokens, session tokens)
* **Asset security:** verification of cloud storage controls and access to uploaded files
* **MCP Gateway:** analysis of the surface exposed by the gateway for integrations with external systems
* **Multi-tenancy isolation:** checks that one tenant cannot access another tenant's data

### How to access the results

Full penetration test reports are confidential documents. They are available as an Executive Summary (a summary of the main findings, without exploitable technical details) for:

* Customers with an active PaaS contract
* Enterprise and Private Cloud customers
* Partners with a signed NDA

To request the Executive Summary, write to <privacy@memori.ai> stating your company name and the delivery model in use.

> Full reports with technical details of the identified vulnerabilities are not shared externally, as they could provide exploitable information to malicious actors. This is standard practice in the information security industry.

<h4 align="center"><a href="mailto:privacy@memori.ai" class="button primary" data-icon="envelope">Request Summary</a></h4>
