Data protection & assessment security
Penny is designed so that ordering, authorisation, assessment execution and report delivery remain controlled steps.
Scope control
The public website does not directly trigger the scanner. Point-IT validates the customer, domain and public IP scope before execution.
European infrastructure
The website, mail environment and Penny infrastructure are hosted on servers in Germany.
Access control
Administrative and assessment systems are restricted to authorised accounts and separated from the public website.
Data minimisation
Point-IT aims to collect and retain only information needed for service delivery, evidence, security and legal obligations.
Human review
Generated reports are reviewed before delivery to reduce obvious false positives, inconsistencies and misleading automated output.
No absolute security claim
Penny is an external assessment service, not a penetration-test guarantee, certification or assurance that every weakness will be found.
