Managed cloud services, private networking, encrypted storage, audit logging and operational monitoring.
Pensure Trust Centre
Security you can examine, not just accept.
Pensure combines its own application, access and engagement controls with independently assessed AWS and Google Cloud infrastructure.
Current as at 26 August 2026
AWS and Google Cloud maintain independently audited ISO/IEC 27001 certifications for their in-scope services.
Relevant AWS and Google Cloud services are covered by independent SOC reports and ongoing audit programmes.
Cloud-provider controls are inherited where applicable. Pensure remains accountable for its applications, access and data handling.
Our assurance position
Pensure handles sensitive information as part of authorised penetration testing. Our security model combines controls operated by Pensure with controls inherited from independently assessed cloud infrastructure.
Core platform workloads use Amazon Web Services (AWS). Selected managed services, including AI-enabled services where required, may use Google Cloud. The relevant cloud services are operated within the providers' independently audited control environments.
AWS is certified to ISO/IEC 27001:2022 and maintains SOC 1, SOC 2 and SOC 3 reports for in-scope services. Google Cloud's ISMS is independently certified to ISO/IEC 27001, and its core services are covered by regularly issued SOC 2 Type II reports.
These certifications and attestations apply to the providers and their in-scope services. They do not mean Pensure itself is certified to ISO/IEC 27001 or has completed its own SOC 2 examination. Pensure uses the providers' assessed controls as part of a shared-responsibility model and remains accountable for the controls it operates.
What Pensure inherits from its cloud providers
Depending on the service used, Pensure inherits independently assessed controls covering areas such as:
- physical data-centre security;
- underlying compute, storage and network infrastructure;
- environmental safeguards and hardware lifecycle management;
- resilience of managed cloud services;
- provider identity, change-management and operational processes; and
- encryption capabilities for managed services.
AWS describes this boundary through its shared responsibility model. Google Cloud describes the same principle through its shared responsibility and shared fate guidance.
Controls operated by Pensure
Pensure remains responsible for the security of its applications, identities, access policies, engagement data, testing workflows and reporting. The platform uses a defence-in-depth architecture that includes:
- private network boundaries for platform and data services;
- role-based access and separate application, execution and operational responsibilities;
- encrypted secrets management rather than credentials stored in source code;
- KMS-backed encryption for private report, evidence and artefact storage;
- public-access blocks and restrictive storage policies;
- encrypted application, infrastructure and audit logs;
- cloud audit trails for management activity;
- service-health monitoring and operational alerting; and
- controlled report release and time-limited customer access.
Controls are selected and operated according to the service, environment and sensitivity of the information involved.
Data and evidence handling
Penetration-testing information is treated as sensitive. Depending on the agreed scope, an engagement may contain:
- targets and application or API information;
- agreed access arrangements for authenticated testing;
- vulnerability evidence, screenshots and request-response evidence;
- reports and remediation information.
Connections to Pensure services use TLS/HTTPS. Stored reports, evidence and operational records use cloud-provider encryption controls, including AWS KMS-backed encryption where applicable.
Pensure's public scoping flow does not collect passwords, API keys, access tokens, session cookies or other authentication secrets. If authenticated testing is selected, Pensure coordinates an appropriate secure access method after the target, scope and authority have been reviewed.
Access to customer information is limited to authorised people and services with an operational need. Customer reports are not made available merely because a file has been created; release is a separate controlled step.
Authorised and controlled testing
Pensure requires authority for the exact target and acceptance of the applicable engagement terms before testing begins. Scope, safeguards, exclusions, schedule, access method and customer contacts are confirmed before execution.
Testing is designed to exercise realistic attack paths within controlled conditions. SafeGuard remains active throughout the engagement, operational intensity is agreed with the customer and material operating constraints can be recorded before testing.
AI-enabled services and human access
Pensure uses AI-led workflows to support penetration testing. Core Plus adds human validation of material findings and human report quality assurance. Qualified personnel may access relevant engagement information when required to validate findings, assess exploitability, remove false positives, review evidence, finalise reporting or support remediation and retesting.
Where a managed AI service is used, Pensure applies the provider's enterprise service terms and security controls relevant to that service. Specific data-location, retention or customer-configured assurance requirements should be confirmed during scope review.
Retention and deletion
Pensure retains engagement and business records only for as long as reasonably required to deliver the service, support remediation, meet contractual or legal obligations, secure the platform and resolve disputes. The applicable agreement or statement of work may set additional requirements.
Customers with specific retention, deletion, residency or supplier-assurance requirements should raise them during scope review so they can be confirmed before testing begins.
Security enquiries
Security concerns and assurance requests are handled directly by Pensure. If you believe you have identified a security issue affecting Pensure, please include enough detail for us to investigate, but do not send credentials or sensitive customer evidence by ordinary email.
For security and assurance enquiries:
- Contact: Pensure Pty Ltd (ABN 87 688 512 334)
- Email: josh@pensure.ai
- Address: 30-03, 201 Elizabeth Street, Sydney NSW 2000, Australia
Assurance enquiries
Need evidence for a customer or supplier review?
Contact Pensure to discuss your security questionnaire, data-handling requirements or the cloud-provider assurance material relevant to your review.
Contact Pensure