Appearance
VAPT Engagement Brief
Document type: Scoped testing mandate for an independent CREST (or equivalent) VAPT provider
Version: 0.2 · Date: 2026-07-14
Owner: Waspada AI engineering
Overview
An independent Vulnerability Assessment and Penetration Test (VAPT) engagement brief is available on request for qualified financial institutions and authorised testing providers.
The full technical pack — including scope, trust boundaries, priority test cases, residual list, and evidence artefacts — is shared under NDA.
Contact: jack@waspada.ai
What the brief covers
- Grey-box VAPT scoping for the Waspada gateway and adjacent trust boundaries
- Priority test cases derived from internal adversarial review
- Evidence pack (architecture docs, load-test reports, RMiT mapping, DPIA)
- Deliverable expectations (CISO letter, technical report, retest window)
- Rules of engagement and methodology expectations
Related (public)
- Executive summary — production hardening status and claims boundary
- Integration & Conformance — published contracts, offline verify, conformance simulator
- RMiT mapping — paragraph-cited control table (not a certification)
- Security overview — CISO reading list
Claims we still do not make
- "BNM-compliant" / "RMiT-certified"
- That a VAPT brief constitutes a VAPT report or assurance letter
- Production readiness without VAPT + FI acceptance
Change log
| Date | Change |
|---|---|
| 2026-07-11 | v0.1 — initial engagement brief for provider RFP / kickoff |
| 2026-07-14 | v0.2 — moved full technical brief to NDA-only distribution; public page replaced with summary |