Skip to content

VAPT Engagement Brief

Document type: Scoped testing mandate for an independent CREST (or equivalent) VAPT provider
Version: 0.2 · Date: 2026-07-14
Owner: Waspada AI engineering

Overview

An independent Vulnerability Assessment and Penetration Test (VAPT) engagement brief is available on request for qualified financial institutions and authorised testing providers.

The full technical pack — including scope, trust boundaries, priority test cases, residual list, and evidence artefacts — is shared under NDA.

Contact: jack@waspada.ai

What the brief covers

  • Grey-box VAPT scoping for the Waspada gateway and adjacent trust boundaries
  • Priority test cases derived from internal adversarial review
  • Evidence pack (architecture docs, load-test reports, RMiT mapping, DPIA)
  • Deliverable expectations (CISO letter, technical report, retest window)
  • Rules of engagement and methodology expectations

Claims we still do not make

  • "BNM-compliant" / "RMiT-certified"
  • That a VAPT brief constitutes a VAPT report or assurance letter
  • Production readiness without VAPT + FI acceptance

Change log

DateChange
2026-07-11v0.1 — initial engagement brief for provider RFP / kickoff
2026-07-14v0.2 — moved full technical brief to NDA-only distribution; public page replaced with summary

Edge tools for citizens. Threat feeds for banks.