forumNew topic

They asked for a "security test" — what does that actually involve, and what's expected of us?

FFiliz S***Member
Job title
Software developer
Sector
Printing
Organization type
early-stage startup
Joined
Apr 2026
Message
129
#1

We are a 9-person software company developing a cloud-based warehouse and logistics management platform. Last month, we sat down with a major international retail chain and reached the point of signing an annual license agreement worth 520,000 TL. However, their corporate information security department added a clause stating: "Prior to go-live, an independent security testing report must be submitted and all high-risk findings must be resolved."

On the software side, we adhere to standard coding practices, but we've never gone through a formal security testing process before. Once this kicks off, what exactly will the client or their audit team ask from us? Is the test performed on the production server, or do we need to set up a staging environment? Will they review our source code, or just try to breach the system from the outside? I'd really appreciate any guidance from folks who have experience with how this process works and the workload it will demand on our end.

MMerveMember
Job title
Operations manager
Organization type
cooperative
Joined
Mar 2024
Message
118
#2

Email your client's information security team immediately and ask for their accepted standard testing methodology and their test scope template. If you get a test done on your own terms, they might reject the report simply because the format doesn't match.

BBetülExpert
Job title
Management consultant
Joined
Oct 2023
Message
164
Most Helpful#3

Short answer: The security test your client is requesting is a process where an independent expert firm verifies that your software is secure against data breaches, unauthorized access, and system vulnerabilities. The testing team will probe your system for weaknesses both from the outside like an attacker and from within as an authorized user.

When dealing with large enterprise clients, this request is completely standard because they fear data leaks into their internal networks or having their corporate data stolen through your software. Once the process begins, they'll basically need three things from you: an architectural diagram of the system, access credentials for the test environment, and user role definitions.

The test is strictly never conducted on a production server. Testers bombard the system with heavy traffic, inject special characters into the database, and stress-test workflows; these actions can corrupt live data. That's why you need to set up an identical staging environment populated with sanitized test data or properly masked real data.

To prepare, follow these steps: 1) Provision two test accounts for each user role (e.g., warehouse staff, branch manager, system admin) for the testing firm. 2) Whitelist the testing team's IP addresses on your firewalls and security software so they can run deep scans without getting blocked. 3) Plan for a 1-2 week development sprint once the report comes in so your team can patch the findings; after the fixes are deployed, the test firm will rescan and issue a clean report.

BBurcu A***MemberCommunity member
Joined
May 2024
Message
146
#4

Usually they run a "Gray Box" test. They won't ask for source code, but they will want usernames and passwords. The goal is to verify whether a standard warehouse employee can escalate their privileges and access admin-level functions.

RRıdvan B***MemberCommunity member
Joined
May 2023
Message
180
#5

We had a test done for our similarly sized SaaS product last year. It took 5 business days, and they found 1 critical and 3 medium vulnerabilities. Our dev team spent about 25 hours fixing them. Once we handed over the clean report to the client, the contract was signed without a hitch.

ZZeynep K***MemberCommunity member
Joined
Feb 2024
Message
41
#6

The client's contract states that the report must come from an independent firm, but did they specify any requirements like TSE accreditation or specific international certifications? If you overlook this the report might be deemed invalid.

HHalil K***Member
Job title
Clinic manager
Sector
Seafood
Organization type
medium-sized business
Joined
May 2024
Message
208

Doki · Interface design · 2026

#7

Here's what you need to have ready before testing starts: 1) API documentation or Swagger export, 2) Test environment login URLs and credentials, 3) Phone number of the technical lead who has the authority to halt the test in an emergency.

AAhmet G***MemberCommunity member
Joined
Apr 2022
Message
30
#8

when you spin up the test environment make sure to wipe real customer names and phone numbers. load anonymous data into stagging so that stuff doesn't end up as screenshots in the vulnerability report.

BBora Y***ExpertCommunity member
Joined
Oct 2025
Message
127
#9

Welcome to the enterprise onboarding ritual. Next up after the security test is the 80-question third-party risk assessment questionnaire, grab another cup of coffee.

ÖÖzge E***Member
Job title
Sales Manager
Sector
Paper
Organization type
workshop
Joined
Jun 2023
Message
50

Doki · Brand identity · 2023

#10

This approach has a cost, which isn't discussed. People defend habits, not processes. Resistance comes from there.

That's all, sorry if I went on too long.

EEsinMember
Job title
Career counselor
Joined
Jun 2024
Message
94

Doki · Interface design · 2026

#11

Yes, that's exactly how it is with what is a security test. When you try to change everything at once, nothing settles.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

İİbrahim K***MemberCommunity member
Joined
Apr 2023
Message
204
#12

You're right.

AAhmet M***MemberCommunity member
Joined
Jan 2024
Message
27
#13

The cheap-looking path usually ends up costing more later. The harder it is to reverse a decision, the slower you should make it.

This is my opinion I'm not claiming it's absolute truth.

SSelin B***MemberCommunity member
Joined
Jun 2024
Message
33
#14

Saved.

ZZafer B***Member
Job title
Customer service representative
Sector
Insurance
Organization type
chain store
Joined
Nov 2023
Message
34
#15

I agree with this. If permission and scope aren't in writing, don't start that test.

Correct me if I'm wrong.

YYiğit Y***New member
Job title
Sales Manager
Sector
Machinery manufacturing
Organization type
a company within a holding
Joined
Aug 2026
Message
4
#16

My questions are cleared up, thanks.

EErcan T***MemberCommunity member
Joined
Apr 2022
Message
138
#17

i dont think this advice fits everyone. honestly the real issue isnt the number, but what its based on.

good luck with that.

OOrhan K***MemberCommunity member
Joined
May 2023
Message
83
#18

Good call starting this thread.

İİbrahim Y***Expert
Job title
Project manager
Sector
Paper
Organization type
boutique agency
Joined
Jan 2023
Message
120
#19

There's also a measurement aspect to this. Taking notes for two weeks yields better results than a six-month estimate.

If you scold false alarms, nobody will report again. Just leaving this note, it might be useful.

EEmine A***MemberCommunity member
Joined
May 2022
Message
254
#20

This thread is archived.

Reply