Back to the main pageIndependent security testing

Attacked continuously,
by design.

Digital Succession Plan custodies inheritances. That makes us a target, so we pay a specialist offensive security firm to attack us before anyone else does — not once a year, but continuously. This page summarises their latest report. The certificate itself is linked at the bottom; nothing here is a claim you have to take on trust.

Tested byFluid Attacks
ServiceContinuous Hacking · Advanced plan
Under test since
Report issued
0Critical or high severity findings left openAll 30 high-severity findings ever reported were fixed and re-verified. No critical one was ever found.
100%Of the reported risk exposure remediatedFluid Attacks scores each finding by severity and sums it — 11,289 points across the whole engagement.
279/293Vulnerabilities fixed and re-verified14 remain, all of them low severity — see the table below.

The results in full

Reproduced verbatim from the certificate, scored with CVSS 4.0. A finding is remediated only after Fluid Attacks re-tests the fix and confirms the weakness is gone — our own word is not enough.

Severity (CVSS 4.0)ReportedRemediatedAcceptedOpenRemediation rate
Critical9100000
High78.9303000100%
Medium46.911211200100%
Low0.13.91511375990.7%
Total29327959

What this means if you use Digital Succession Plan

Nothing serious is left open

Critical and high severity findings are the ones that matter to you: the kind that could let an attacker take over an account, reach funds, or read another person's data. 30 high-severity issues were found over the engagement and 30 were fixed and re-verified. None is open. No critical issue was ever reported.

What remains is low severity

14 low-severity findings are still on the books — 9 being worked on and 5 formally accepted. Low severity means an attacker could not use them on their own to reach your assets; they are hardening gaps rather than doors. An accepted finding is one we have consciously decided not to change, documented and signed off, because the fix would cost more than the risk it removes.

Weighted by severity, the risk is closed

Fluid Attacks converts every finding into a risk-exposure score that grows steeply with severity, so one high-severity issue outweighs many low ones. Our engagement totalled 11,289 points, of which 100% is remediated. That figure is rounded: the remaining low-severity findings are what is left, and they are worth a fraction of a point each.

It is continuous, not a snapshot

We are under test every day, not audited once and left alone. The numbers above are the state of the engagement as of ; a new certificate is issued periodically and this page is rebuilt from it. That also means new findings will appear here in the future — that is the process working, not failing.

An honest caveat. No amount of testing proves software has no vulnerabilities; it proves that a competent adversary looked hard and that what they found was fixed. That is the strongest claim anyone in this industry can truthfully make, and it is the one we are making.

What was tested, and how

The engagement covers 16 source code repositories and 2 running environments — the whole platform, not a sample of it. Fluid Attacks applies every technique below in parallel:

  • SAST

    Static analysis

    Automated reading of our source code, looking for insecure patterns before they ever run.

  • DAST

    Dynamic analysis

    Attacks fired at the running application the way a real attacker would reach it — over the network.

  • SCA

    Dependency analysis

    Every third-party and open-source library we ship is checked against known vulnerabilities.

  • CSPM

    Cloud posture

    The cloud infrastructure and its configuration are audited for exposure — open ports, weak policies, misconfigured storage.

  • PTAAS

    Manual penetration testing

    Human ethical hackers, continuously, doing what tools cannot: chaining small flaws into real attacks.

  • Expert code review

    Security engineers read the code by hand, focused on the logic that guards money and identity.

  • Reverse engineering

    The compiled application is taken apart the way an attacker with a copy of it would.

Against which standard?

This is an attestation of test results, not a pass/fail certification like ISO 27001 or SOC 2 — and we will not describe it as one. Testing is measured against the security requirements curated by Fluid Attacks, which are themselves mapped to the established international standards. Both catalogues are public, so the bar we are held to can be inspected:

Read the certificate

Signed by Carolina Carrasco and Javier Martinez of Fluid Attacks. We publish the results and signature pages; the annex listing our internal repository and environment addresses is withheld, since naming infrastructure publicly helps attackers and proves nothing to you.

  • Carolina CarrascoHead of Service, Fluid Attacks
  • Javier MartinezRed Team Architect, Fluid AttacksOSEP, OSWE, OSCP, OSWP, CEH v9 and Computer Security Specialist
Open the certificate (PDF)Opens in a new tab · issued