Security testing

We penetration test our own applications every month with OWASP ZAP and publish the report in full — findings, evidence and all. Nothing is summarised for you, redacted, or held back for a sales call.

This page is written for security officers, IT security teams and procurement security reviewers. If you need something that is not here, email nici@netfm.org and we will send it.

Latest report

11 August 2026

Scan of core Visitor Express services · OWASP ZAP 2.17.0 (ZAP by Checkmarx)

Read the full report →
0
High
3
Medium
4
Low
10
Informational

No high-risk findings. The three medium findings are missing hardening controls on the public web tier rather than exploitable defects — no Content-Security-Policy header, no Sub-Resource Integrity attributes on third-party scripts, and no anti-CSRF token on the public enquiry form. The low findings are Strict-Transport-Security not set, the Server response header leaking version information, cross-domain JavaScript inclusion and an in-page banner leak. Everything else is informational — technology fingerprinting and cache-control observations.

The scan is unauthenticated and runs against public endpoints only, so no customer data appears anywhere in the report. That is also why we are comfortable publishing it.

Report archive

Each month's report is published here as generated and left up, so you can see the trend rather than a single snapshot we chose to show you. The monthly cycle runs from August 2026; the October 2025 report is the previously published test and is kept for comparison.

Scans of your own deployment

The report above covers our core services. If you are a customer, we will run the same monthly test against your deployment and send you the report directly — so your evidence pack is about your system, not ours.

Once it is set up, the scan and the report are automatic: the same monthly cycle, generated and emailed to your named recipients without anyone having to ask again. No ticket, no chase, no annual scramble when your auditor turns up.

To set it up, email nici@netfm.org.

Requests must come from a verified address

We only accept scan requests, and only send reports, to an email address on your organisation's own domain that we already hold as an authorised security or IT contact for your account.

We will not send a report to a personal address, to a free webmail address, or to anyone we cannot tie back to your account. If the requester is not already on file, we verify through your existing named contact before anything is scanned or sent.

One customer, one report

Each report covers a single customer's deployment. We never include another customer's hosts, findings or data — and no one else's report will ever mention yours.

Reports are sent to a named distribution list that you control. Tell us when someone joins or leaves it and we will change it that day.

Scope and authorisation

We scan the services we host and operate for you. Where a deployment reaches into infrastructure you own — your network, your edge devices, your on-premise hardware — we need written authorisation from you naming the in-scope hosts before we test it.

Scanning is done against production public endpoints, out of hours where you ask for it, and is passive and active web testing only — no denial-of-service testing, no social engineering.

What you get, and when

The full OWASP ZAP report as HTML — the same format as the one published above — with the risk and confidence summaries your questionnaire will ask for. Ask and we will add a short written summary for a board or audit pack.

One-off scans outside the monthly cycle — before a tender, a penetration test review or a contract renewal — are available on the same terms. Just ask.

To get set up, tell us

  • the service or hostname you want covered;
  • the named recipients, at your own domain, who should receive the report;
  • who at your organisation authorises the testing;
  • any window you want us to scan in, or hosts you want excluded.
Email nici@netfm.org →

Reporting a vulnerability

If you believe you have found a vulnerability in one of our applications, email nici@netfm.org with enough detail for us to reproduce it. We will acknowledge you and keep you updated until it is closed out.

Please do not test against a customer's live deployment without their written authorisation and ours — it will be treated as an incident by the customer's own security team, and by us.

The rest of the evidence pack

Filling in a security questionnaire?

Send it over. We hold completed security questionnaires, our data processing agreement, SLA and supplier due-diligence packs, and we would rather answer your standard form than have you build one from this page.

Email nici@netfm.org →