Does Chargebee support Vulnerability Assessment and Penetration Testing (VAPT)?
Problem Statement
You want to know whether Chargebee supports Vulnerability Assessment and Penetration Testing (VAPT) and how often security testing is performed.
Related Scenarios
- Does Chargebee support VAPT security?
- How often does Chargebee perform vulnerability scanning and patching?
Solution
Chargebee is committed to ensuring the confidentiality, integrity, and availability of the sensitive and confidential data of the customers it collects, stores, or transfers.
Vulnerability Assessment and Penetration Testing (VAPT) describes a broad range of security assessments designed to identify and help address cybersecurity exposures across an organization's IT estate. The evolving tools, tactics, and procedures used by cybercriminals to breach networks mean that it's essential to test your organization's cybersecurity regularly. VAPT helps protect your organization by providing visibility of security weaknesses and guidance to address them.
Types of scans
- Internal VAPT (App & API)
- External VAPT (App & API)
- DAST (App & API)
Chargebee performs the VAPT assessment on a quarterly basis.
Chargebee periodically checks and applies patches for third-party software and services. As vulnerabilities are discovered, fixes are applied. Periodic vulnerability scanning is performed using the services of an authorized QSA.
In addition, Chargebee has an in-house security team that performs vulnerability scans on a monthly basis.
Each API endpoint is manually tested against vulnerabilities, which includes the following modules:
- BOLA (Broken Object Level Authorization)
- Broken User Authentication
- Excessive Data Exposure
- Lack of resources & rate limiting
- Broken Function Level Authorization (BFLA)
- Mass Assignment
- Security Misconfiguration
- Injection
- Improper Asset Management
- Insufficient Logging & Monitoring
Below are the major test cases validated when any module in the Chargebee product undergoes a security assessment:
- Authentication
- Authorization
- Encryption
- Information Leakage
- Injection Attacks
- Insecure Server Configuration
- Session Management
- Request Header based attacks
- Others
Additional Information
For more information, see Vulnerability Scanning & Patching.
Related Articles
Was this article helpful?