- Job title
- Software developer
- Sector
- Printing
- Organization type
- early-stage startup
- Joined
- Apr 2026
- Message
- 129
We are a 9-person software company developing a cloud-based warehouse and logistics management platform. Last month, we sat down with a major international retail chain and reached the point of signing an annual license agreement worth 520,000 TL. However, their corporate information security department added a clause stating: "Prior to go-live, an independent security testing report must be submitted and all high-risk findings must be resolved."
On the software side, we adhere to standard coding practices, but we've never gone through a formal security testing process before. Once this kicks off, what exactly will the client or their audit team ask from us? Is the test performed on the production server, or do we need to set up a staging environment? Will they review our source code, or just try to breach the system from the outside? I'd really appreciate any guidance from folks who have experience with how this process works and the workload it will demand on our end.