Overview
Ory Network is a multi-tenant platform serving customers worldwide. Security testing that is indistinguishable from a live attack can degrade service for other customers and consume incident response capacity. Penetration testing against Ory Network therefore requires prior written approval, as set out in the Acceptable Use Policy.
Ory supports customers testing their own applications. This policy exists to define how, not whether.
Scope of this policy
This policy governs penetration testing, vulnerability scanning, and security assessment where the traffic reaches Ory Network.
This policy does not govern:
- Load, stress, and performance testing. High-volume traffic intended to measure capacity is covered by the Load Testing Policy, which has separate eligibility, lead time, and duration requirements. If your engagement includes a volumetric component, that component must be requested separately under that policy.
- Vulnerability research against Ory Network itself. Testing intended to find flaws in the Ory platform rather than in your configuration of it runs through the Ory private bug bounty program on HackerOne. Contact [email protected] for access.
- Self-hosted Ory deployments. Testing an Ory Enterprise License or open source deployment you operate requires no approval from Ory.
Authorization required
Penetration testing against Ory Network production or staging environments is only permitted with Ory's prior written approval. Unauthorized testing may result in:
- Temporary blocking of project access
- Suspension of API access from source IPs
- Account suspension for repeated violations
Eligibility
Penetration testing requests are available to customers on all paid subscription plans.
Request timeline
- Submit your request at least 10 business days before your desired test start date.
- Requests with less notice may be denied or rescheduled.
Permitted testing
Within an approved window, you may test:
- Your own project and its configuration
- Your application's integration with Ory, including session handling, redirect URI validation, token storage and lifecycle, logout behavior, and callback handling
- Authentication and authorization flows as exercised by identities you own or control
- Your own authorization logic built on Ory Permissions
Prohibited activities
The following are prohibited during any engagement:
- Testing against identities, projects, or tenants you do not own or have written permission to test
- Denial of service testing, protocol flooding, or resource exhaustion attempts
- Sustained scanning above 5 requests per second against Ory domains
- Social engineering, phishing, vishing, or smishing against Ory personnel or other customers
- Physical testing of Ory or Ory vendor facilities
- Attempts to access, modify, or exfiltrate data belonging to other customers
- Testing that intentionally degrades service availability for other tenants
- Creating incomplete or fraudulent subscriptions to paid plans
Discovery of a cross-tenant issue must stop at proof of concept. Do not pivot further, and report it to [email protected] immediately.
Security control exceptions
Ory does not disable, bypass, or create exceptions in security controls for penetration testing. This includes the web application firewall, bot and abuse detection, malicious path detection, and credential stuffing protections.
Many of these controls are shared across all tenants on Ory Network and cannot be scoped to a single project. An exception would also invalidate the test: an engagement conducted against weakened controls measures a configuration that does not exist in production.
Protective controls that block, throttle, or challenge test traffic are functioning as designed. Ory considers these results, not obstructions, and recommends recording them as such in your report.
Rate limits are separate from security controls. Where an approved test requires it, Ory can raise project rate limits for declared source IPs for the duration of the window. This does not extend to any of the controls above.
Submitting a request
Open a support ticket via the Ory Console or email [email protected] with subject line "Penetration Test Request" and include:
Engagement details:
- Description and business purpose
- Proposed start and end dates, including timezone
- Project name and environment (production/staging)
- Testing firm or internal team conducting the assessment
Technical scope:
- Public routable egress IP addresses or CIDR ranges for all test traffic
- Ory endpoints and flows in scope
- Tooling to be used
- Expected peak request rate
- Whether the engagement includes any volumetric component (see Load Testing Policy)
Contacts:
- Primary contact available during the engagement (name, email, phone, slack)
- Backup contact
- Contact at the testing firm, if applicable
Review process
- Ory reviews the request for completeness and scope
- Ory may request modifications to test parameters
- Upon approval, Ory provides a confirmed window in writing
- Ory tags declared source IPs so test traffic is not triaged as an active attack
- Customer conducts the test within approved parameters
- Customer shares a findings summary with Ory
During the test
- Begin and end within the approved window
- Test only from the declared source IPs
- Honor HTTP 429 responses with exponential backoff, per the Acceptable Use Policy
- Stop immediately if instructed by Ory
- Contact Ory support if issues arise
Findings
- Report any finding that appears to originate in Ory Network rather than in your own configuration to [email protected] within five business days of discovery. Include reproduction steps.
- Do not publish or disclose findings that implicate Ory Network without written consent from Ory. Ory will work with you on coordinated disclosure timelines where appropriate.
- Findings that relate solely to your own configuration or application are yours to handle as you see fit.
Ory's own testing
Ory engages third-party penetration testers against Ory Network and operates a private bug bounty program. Customers requiring platform-level assurance evidence for audit purposes should contact their account team or visit https://trust.ory.com.
Questions
For questions about this policy, contact [email protected] or open a ticket in the Ory Console.