Authorised testing
Testing starts only after scope, hosts, dates, rate limits, write permissions and Rules of Engagement are documented.
Kotav Labs delivers authorised security assessments through a controlled engagement model. This page states what we protect, how delivery is governed and where our boundaries are.
They apply from written authorisation through to reviewed evidence and traceable delivery.
Testing starts only after scope, hosts, dates, rate limits, write permissions and Rules of Engagement are documented.
Assessment infrastructure and evidence are hosted in Germany. Subprocessors and any additional processing locations are disclosed per engagement.
Material findings receive specialist review. Deliverables use verified evidence and an audit-suitable report, with PDF and SARIF where applicable.
Tenant-scoped access, explicit roles and server-side authorisation protect customer records and operational actions.
HttpOnly sessions, rotating refresh tokens, TOTP MFA, one-time backup codes and encrypted secrets protect browser accounts.
Assessment jobs, finding changes, retest requests, role changes and sensitive administrative actions produce attributable records.
Argus Sentinel provides passive intelligence and correlation between assessments. Round-the-clock monitoring and incident response sit outside this service, while certification depends on an independent assessment. Retention, subprocessors, testing permissions and deliverables are agreed for each engagement.
A DPA, security FAQ, subprocessor disclosure, sample deliverables and technical answers are available during qualification under appropriate confidentiality terms.
Each item below states its current scope and status. We identify operating safeguards, voluntary commitments, self-assessments and independent certification separately.
Last reviewed 5 September 2026
Kotav Labs submitted its commitment to the nine CREST AI Principles on 5 September 2026. Public listing and the badge remain pending.
CREST principlesKotav Labs submitted all four AI Trustworthy Pledge principles on 5 September 2026. CSA confirmed receipt; public listing and the digital badge remain pending.
CSA pledgeAll 283 CAIQ v4.1 questions are answered for the defined customer-facing service boundary. Registry submission and CSA publication confirmation remain outstanding.
CSA STARAll 320 AI-CAIQ v1.1 questions are answered for Argus model use, Rogue verification and the supporting control plane. Registry submission and CSA confirmation remain outstanding.
STAR for AIScoped current and target profiles structure our internal improvement programme, with evidence reviews tracked against each profile.
NIST CSFAssessment and development practices reference selected OWASP requirements and retain review evidence.
OWASP ASVSOur scoped internal NIS2 programme has complete control, operating-evidence and management-approval records across governance, risk management, incident handling, continuity, supply-chain security, secure development, cryptography, access control and disclosure. These safeguards remain under continuous review. Applicability and any registration or reporting duties remain subject to the competent authority.
EU NIS2 overviewPolicies, risk records, control ownership and operating evidence form an active ISMS programme.
ISO certification guidanceA policy alone does not prove operation. Public claims require a defined scope, an accountable owner, dated evidence and a recorded review.