Start here

Security Notices

Review the environment, account, secret, scope, and integration safeguards required before running a Tahr assessment.

Last updated August 2, 2026
On this page

Before running an assessment, review these security requirements. They reduce the risk of data exposure, unintended actions, unreliable results, and unauthorized access.

#Use a non-production environment

Run Tahr against a staging, test, preproduction, or other dedicated non-production environment.

#Use dedicated test accounts and data

Use dedicated test identities with only the permissions required for the assessment. Use disposable test data that can be changed or removed without affecting active users.

Do not use:

  • Personal employee accounts.
  • Real customer accounts or data.
  • Production administrator accounts.
  • Accounts shared with active users or concurrent assessments.

For authorization testing, provide separate users across the relevant roles, tenants, workspaces, or ownership boundaries.

#Keep secrets out of free-text fields

Never enter passwords, API keys, access tokens, client secrets, recovery codes, TOTP secrets, private customer data, or other sensitive information in free-text fields.

Use the dedicated credential, authentication, header, repository, or integration fields provided by Tahr.

This applies to application context, testing instructions, authentication guidance, comments, findings, tickets, and Assistant questions.

#Verify the target and scope

Before launching an assessment, confirm that every configured target belongs to the intended application and environment.

Review:

  • URLs and domains.
  • API definitions.
  • Repository and branch.
  • Authentication settings.
  • Test identities.
  • Uploaded files.
  • Custom headers.
  • Assessment type and scope.

Incorrect or outdated inputs may cause Tahr to test the wrong target or produce incomplete or misleading results.

#Limit third-party access

Repository, OAuth, ticketing, CI/CD, and integration credentials must use the least privileges required.

Restrict connections to the intended repositories, projects, teams, and applications. Remove unused connections and rotate credentials when they are no longer required or may have been exposed.

Before enabling ticket creation or external workflows, verify the selected destination to prevent assessment data from being sent to the wrong project or organization.

Image preview