TesseraCyber
← Back to Tessera Cyber

Tessera Cyber

External Assessment Methodology

A trading name of Pepaco Group LLC.

Purpose

This document describes how Tessera Cyber performs its external security assessment: what is checked, how findings are classified, what is explicitly out of scope, and the limitations of the assessment. It is provided so brokers and clients know exactly what the assessment does and does not cover before authorizing one.

What is assessed

All checks are performed against the single authorized domain, using only information that is already publicly observable from outside the target's network. No authentication, exploitation, or internal access is used at any point.

  • HTTP security headers (e.g. HSTS, Content-Security-Policy, X-Frame-Options, and related response headers)
  • TLS / certificate health, including expiry, self-signed/CA validation, protocol version, and cipher suite strength
  • Email spoofing protection: SPF and DMARC records; DKIM only where a selector or a signed sample email is available
  • Publicly accessible sensitive-file and backup-file patterns (e.g. exposed configuration or backup files at predictable paths)
  • Detectable client-side JavaScript libraries cross-referenced against known vulnerabilities (via the public OSV.dev database)
  • CORS (Cross-Origin Resource Sharing) misconfiguration
  • Technology / CMS fingerprinting (e.g. identifying publicly disclosed platform or generator information)
  • Public-source subdomain discovery (via Certificate Transparency logs, e.g. crt.sh) — discovered hostnames are listed only, never individually scanned or probed

What is explicitly out of scope

The following are never performed, regardless of client or broker request:

  • No exploitation, injection, or attack payload testing of any kind
  • No credential brute-forcing or authentication bypass attempts
  • No port scanning for the purpose of live exploitation
  • No access to internal systems, networks, or infrastructure
  • No assessment of internal controls (e.g. MFA enforcement, EDR deployment, backup testing, patch management, incident response readiness, privileged access management, or security awareness training) — these require internal access this assessment does not have
  • No document or evidence upload, transfer, or retention of any kind

Finding classification

Severity: Critical/High — well-established, direct security or fraud impact. Medium — increases risk but requires additional conditions, or context we can't observe externally. Low — hygiene/best-practice gaps with limited standalone impact. Informational — observations for awareness only.

Status: Detected — the condition was directly observed. Not Detected — the check ran and found nothing. Inconclusive — the check couldn't be completed reliably. Not Assessed — outside the scope defined in this methodology.

Severity ratings reflect general technical risk patterns only. They are not a substitute for underwriting judgment, and are not represented as equivalent to an insurer's own risk assessment.

Authorization

No assessment begins without documented authorization from the domain owner, established through one of: a DNS TXT record published by the client, confirmation from an approved administrative email address on the domain, or written authorization supplied by the client through the broker.

Rescan

One rescan is included per assessment. It re-runs the same external checks and confirms only externally detectable changes — it does not verify remediation at the infrastructure/configuration level beyond what's externally observable, and does not confirm internal-control remediation.

Data sources and third-party services

OSV.dev is queried with the name and version of a detected front-end library only. crt.sh is used only to discover already-public subdomain records via Certificate Transparency logs. Neither service receives any client-identifying information beyond what is already public.

Limitations

  • This is a point-in-time snapshot; a domain's external posture can change at any time after delivery
  • Only what is externally, passively or non-intrusively observable is covered — internal systems and controls are never assessed
  • Findings reflect commonly recognized technical risk patterns, not a guarantee of exploitability, business impact, or insurability
  • This is not a penetration test, security certification, or compliance audit of any kind

Questions? Email ciso@tesseracyber.com

Tessera Cyber is a trading name of Pepaco Group LLC.