Pentest

Internal pentest

Rocket.Chat does not currently have a calendar for penetration tests performed by internal security engineers. However, penetration tests are performed when the security team deems it necessary for new features, critical infrastructure and/or functionalities.

External pentest

External pentesting is performed by an independent company. Each pentest is based on a specific engagement description, which outlines the test procedures and scope of the testing. External pentesting must produce a report with identified vulnerabilities in a shareable format to customers and other stakeholders. All vulnerabilities identified in the pentest must be mitigated before the report is shared with external stakeholders.

Last external pentests

  • Electron application, performed by Dyonsec - Dec 2022

  • Rocket.Chat application, performed by Pride Security - Jan 2023

  • Rocket.Chat application, performed by Pride Security - Jun 2024

In order to see the pentest results a NDA must be signed. Please contact your sales specialist or our support team to know more about it.