Before running an assessment, review these security requirements. They reduce the risk of data exposure, unintended actions, unreliable results, and unauthorized access.
#Use a non-production environment
Run Tahr against a staging, test, preproduction, or other dedicated non-production environment.
#Use dedicated test accounts and data
Use dedicated test identities with only the permissions required for the assessment. Use disposable test data that can be changed or removed without affecting active users.
Do not use:
- Personal employee accounts.
- Real customer accounts or data.
- Production administrator accounts.
- Accounts shared with active users or concurrent assessments.
For authorization testing, provide separate users across the relevant roles, tenants, workspaces, or ownership boundaries.
#Keep secrets out of free-text fields
Never enter passwords, API keys, access tokens, client secrets, recovery codes, TOTP secrets, private customer data, or other sensitive information in free-text fields.
Use the dedicated credential, authentication, header, repository, or integration fields provided by Tahr.
This applies to application context, testing instructions, authentication guidance, comments, findings, tickets, and Assistant questions.
#Verify the target and scope
Before launching an assessment, confirm that every configured target belongs to the intended application and environment.
Review:
- URLs and domains.
- API definitions.
- Repository and branch.
- Authentication settings.
- Test identities.
- Uploaded files.
- Custom headers.
- Assessment type and scope.
Incorrect or outdated inputs may cause Tahr to test the wrong target or produce incomplete or misleading results.
#Limit third-party access
Repository, OAuth, ticketing, CI/CD, and integration credentials must use the least privileges required.
Restrict connections to the intended repositories, projects, teams, and applications. Remove unused connections and rotate credentials when they are no longer required or may have been exposed.
Before enabling ticket creation or external workflows, verify the selected destination to prevent assessment data from being sent to the wrong project or organization.