MCMMCM DocsEngineering (Internal)
User StoriesMCM-57 — Legal & Compliance Readiness for Customer Deployment
v1.2 is unreleased — see v1.1 for the current stable release.

MCM-66 — Customer Audit & Penetration Testing Rights

Controlled audit and pen-test rights a customer's security team can exercise before deployment.

MCM-66 — Customer Audit & Penetration Testing Rights

← Back to Legal & Compliance Readiness overview

As Compliance & Security Lead,
I want to define and offer customer audit and penetration-testing rights under controlled terms,
so that a prospective customer's security team can independently verify MCM's claims before granting cross-account access, without an uncontrolled test disrupting shared infrastructure or other tenants.

Acceptance Criteria

  • The contract defines audit rights: scope (e.g., pre-deployment, or annual thereafter), required notice period, and what MCM will produce in lieu of a full customer-run audit where reasonable — e.g., the latest SOC 2 report, SBOM, and penetration test summary.
  • Customer-initiated penetration testing is permitted under a documented rules-of-engagement: scope limited to the customer's own tenant, exclusions for shared multi-tenant infrastructure, required advance notice, and a defined test window.
  • MCM's own third-party penetration test is conducted at least annually, and a redacted summary is available to share with customers as an alternative to a customer-run test.
  • Any finding from a customer-permitted pen test is triaged through the same vulnerability management process and severity SLA as MCM's own findings (see MCM-64).
  • Audit and pen-test rights, and their limits, are reviewed by Legal Counsel before being offered, so they are never granted ad hoc by Sales.

Technical Design

A customer-run test is really a request to exercise the platform's tenant-isolation guarantee under controlled conditions, scoped to that customer's own tenant boundary — the same isolation the platform must already enforce for other reasons. Findings from a permitted test are routed into the standard vulnerability process rather than a separate parallel one, so they get the same severity SLA as anything found internally.

On this page