Independent security testing

Your digital inheritance, secured like a vault.
Tested continuously.

Digital Succession Plan custodies inheritances. That makes us a target, so we pay a specialist offensive security firm to attack us before anyone else does — not once a year, but continuously. The firm is Fluid Attacks, which audits large financial institutions such as Bancolombia and Banco General, as well as major airlines like Copa Airlines and Avianca. This page summarises their latest report. The certificate itself is linked at the bottom; nothing here is a claim you have to take on trust.

Tested byFluid Attacks
ServiceAdvanced plan
Under test since
Report issued
100%

of the risk exposure Fluid Attacks identified has been remediated and re-verified.

No open vulnerabilities at any severity.

Independently & continuously tested by Fluid Attacks · as of

No open vulnerabilities

As of , Fluid Attacks's continuous offensive testing has no unresolved findings at any severity. Every issue identified over the engagement has been fixed and re-verified.

How it's scored. Fluid Attacks rates each finding with CVSS 4.0 (0–10 by severity), then rolls the findings into a single risk-exposure score with its own model — each finding weighted by severity (Fluid Attacks's formula, 4(CVSS-4)), so one severe issue outweighs many minor ones. What matters for you is how much of that exposure stays open. For us, none of it.

Open the certificate (PDF)

What this means if you use Digital Succession Plan

Remediated means re-verified

A finding counts as fixed only after Fluid Attacks re-tests it and confirms the weakness is gone — our own word is not enough. Anything still being worked on shows as open; anything we have consciously documented and signed off as not worth changing shows as accepted. A severe finding left open is the combination that would matter to you — so that is the state we lead with above.

It is continuous, not a snapshot

We are under test every day, not audited once and left alone. A new certificate is issued periodically and this page is rebuilt from it — so new findings will appear here over time. That is the process working, not failing; what matters is that each one is fixed and re-verified, which is exactly what these figures track.

An honest caveat. No amount of testing proves software has no vulnerabilities; it proves that a competent adversary looked hard and that what they found was fixed. That is the strongest claim anyone in this industry can truthfully make, and it is the one we are making. The full certificate — every finding, open or closed, and the counts behind these figures — is one click away.

What was tested, and how

The engagement covers 16 source code repositories and 4 running environments — the whole platform, not a sample of it. Fluid Attacks applies every technique below in parallel:

  • SAST

    Static analysis

    Automated reading of our source code, looking for insecure patterns before they ever run.

  • DAST

    Dynamic analysis

    Attacks fired at the running application the way a real attacker would reach it — over the network.

  • SCA

    Dependency analysis

    Every third-party and open-source library we ship is checked against known vulnerabilities.

  • CSPM

    Cloud posture

    The cloud infrastructure and its configuration are audited for exposure — open ports, weak policies, misconfigured storage.

  • PTAAS

    Manual penetration testing

    Human ethical hackers, continuously, doing what tools cannot: chaining small flaws into real attacks.

  • Expert code review

    Security engineers read the code by hand, focused on the logic that guards money and identity.

  • Reverse engineering

    The compiled application is taken apart the way an attacker with a copy of it would.

Against which standard?

This is an attestation of test results, not a pass/fail certification like ISO 27001 or SOC 2 — and we will not describe it as one. Testing is measured against the security requirements curated by Fluid Attacks, which are themselves mapped to the established international standards. Both catalogues are public, so the bar we are held to can be inspected:

Read the certificate

Signed by Carolina Carrasco and Javier Martinez of Fluid Attacks. We publish the results and signature pages; the annex listing our internal repository and environment addresses is withheld, since naming infrastructure publicly helps attackers and proves nothing to you.

  • Carolina CarrascoHead of Service, Fluid Attacks
  • Javier MartinezRed Team Architect, Fluid AttacksOSEP, OSWE, OSCP, OSWP, CEH v9 and Computer Security Specialist
Open the certificate (PDF)Opens in a new tab · issued