Digital Succession Plan custodies inheritances. That makes us a target, so we pay a specialist offensive security firm to attack us before anyone else does — not once a year, but continuously. This page summarises their latest report. The certificate itself is linked at the bottom; nothing here is a claim you have to take on trust.
0Critical or high severity findings left openAll 30 high-severity findings ever reported were fixed and re-verified. No critical one was ever found.
100%Of the reported risk exposure remediatedFluid Attacks scores each finding by severity and sums it — 11,289 points across the whole engagement.
279/293Vulnerabilities fixed and re-verified14 remain, all of them low severity — see the table below.
The results in full
Reproduced verbatim from the certificate, scored with CVSS 4.0. A finding is remediated only after Fluid Attacks re-tests the fix and confirms the weakness is gone — our own word is not enough.
Severity (CVSS 4.0)
Reported
Remediated
Accepted
Open
Remediation rate
Critical9 – 10
0
0
0
0
—
High7 – 8.9
30
30
0
0
100%
Medium4 – 6.9
112
112
0
0
100%
Low0.1 – 3.9
151
137
5
9
90.7%
Total
293
279
5
9
—
What this means if you use Digital Succession Plan
Nothing serious is left open
Critical and high severity findings are the ones that matter to you: the kind that could let an attacker take over an account, reach funds, or read another person's data. 30 high-severity issues were found over the engagement and 30 were fixed and re-verified. None is open. No critical issue was ever reported.
What remains is low severity
14 low-severity findings are still on the books — 9 being worked on and 5 formally accepted. Low severity means an attacker could not use them on their own to reach your assets; they are hardening gaps rather than doors. An accepted finding is one we have consciously decided not to change, documented and signed off, because the fix would cost more than the risk it removes.
Weighted by severity, the risk is closed
Fluid Attacks converts every finding into a risk-exposure score that grows steeply with severity, so one high-severity issue outweighs many low ones. Our engagement totalled 11,289 points, of which 100% is remediated. That figure is rounded: the remaining low-severity findings are what is left, and they are worth a fraction of a point each.
It is continuous, not a snapshot
We are under test every day, not audited once and left alone. The numbers above are the state of the engagement as of ; a new certificate is issued periodically and this page is rebuilt from it. That also means new findings will appear here in the future — that is the process working, not failing.
An honest caveat. No amount of testing proves software has no vulnerabilities; it proves that a competent adversary looked hard and that what they found was fixed. That is the strongest claim anyone in this industry can truthfully make, and it is the one we are making.
What was tested, and how
The engagement covers 16 source code repositories and 2 running environments — the whole platform, not a sample of it. Fluid Attacks applies every technique below in parallel:
SAST
Static analysis
Automated reading of our source code, looking for insecure patterns before they ever run.
DAST
Dynamic analysis
Attacks fired at the running application the way a real attacker would reach it — over the network.
SCA
Dependency analysis
Every third-party and open-source library we ship is checked against known vulnerabilities.
CSPM
Cloud posture
The cloud infrastructure and its configuration are audited for exposure — open ports, weak policies, misconfigured storage.
PTAAS
Manual penetration testing
Human ethical hackers, continuously, doing what tools cannot: chaining small flaws into real attacks.
Expert code review
Security engineers read the code by hand, focused on the logic that guards money and identity.
Reverse engineering
The compiled application is taken apart the way an attacker with a copy of it would.
Against which standard?
This is an attestation of test results, not a pass/fail certification like ISO 27001 or SOC 2 — and we will not describe it as one. Testing is measured against the security requirements curated by Fluid Attacks, which are themselves mapped to the established international standards. Both catalogues are public, so the bar we are held to can be inspected:
Signed by Carolina Carrasco and Javier Martinez of Fluid Attacks. We publish the results and signature pages; the annex listing our internal repository and environment addresses is withheld, since naming infrastructure publicly helps attackers and proves nothing to you.
Carolina CarrascoHead of Service, Fluid Attacks
Javier MartinezRed Team Architect, Fluid AttacksOSEP, OSWE, OSCP, OSWP, CEH v9 and Computer Security Specialist