Compliance · Audit evidence
Evidence your auditor will accept.
Dunicot operates a certified ISO/IEC 27001 information security management system, certified in the name of Dunicot Private Limited and governing engagements contracted through either entity, Dunicot Private Limited in Pakistan or Dunicot LLC in the United States. The certificate and its scope statement are provided to clients and prospects on request under NDA, together with the current statement of applicability.
Frameworks
ISO 27001 penetration testing and ISMS support
Testing delivered by a consultancy that runs a certified ISMS of its own, with findings written against the Annex A controls your auditor will ask about.
SOC 2SOC 2 penetration testing
The evidence artefact your auditor expects under CC4.1 and CC7.1, produced in the shape they already accept.
PCI DSSPCI DSS penetration testing
Internal, external and segmentation testing under requirement 11.4, documented the way a QSA expects to receive it.
HIPAAHIPAA penetration testing
Technical evidence for the risk analysis and periodic evaluation the Security Rule requires.
GDPR & data protectionGDPR security testing
Article 32 asks for a process for regularly testing technical measures. This is that process, evidenced.
Every engagement includes
Executive summary
One page for the people who approve budget: what was tested, what was found, what it means in business terms.
Technical findings
Each finding with severity, CVSS, affected component, full request and response, reproduction steps and a working proof of concept.
Attack chains
Where findings combine, the chain is written out end to end, from first request to demonstrated impact.
Remediation guidance
A specific fix for your stack and framework, with the corrected pattern, not a link to a generic reference page.
Audit mapping
Findings mapped to SOC 2, ISO 27001, PCI DSS, HIPAA and OWASP ASVS as applicable, so the report drops straight into an audit pack.
Retest and attestation
Every finding retested in a clean session after remediation, with a signed attestation letter for customers and auditors.
Audit date already set?
Engagements are scheduled backwards from your deadline, so findings are remediated and re-verified before the auditor arrives.