3 ms·
The page only says that they do external security scans that other companies who do the actual certification recognize as valid scans. They certify no one thems
by teilo 7y ago
The page only says that they do external security scans that other companies who do the actual certification recognize as valid scans. They certify no one themselves.
Further, that has absolutely nothing to do with anyone reporting vulnerabilities through HackerOne. That is not a scan by the definition of PCI-DSS, the SOC2 trust services criteria, or any other security framework you care to name.
Just give it up. You're wrong.