Continuing our series of posts on Enterprise Infrastructure capabilities, featured in a dedicated tab within the Blueprint dashboard, this post explores the Vulnerability Testing.
Vulnerability Testing Policy for Applications on Pega Cloud defines authorized security testing procedures that allow you to identify and remediate security weaknesses in your custom applications while protecting the platform integrity and other tenants.
What it Means:
- Vulnerability testing is authorized security assessment of your own applications running on Pega Cloud to proactively detect and fix security issues before attackers exploit them.
- Pega Cloud permits security testing within defined parameters—internal application testing is encouraged, but testing that impacts shared infrastructure, automated denial-of-service attacks, or affects other tenants is strictly prohibited.
- Your own app testing → allowed (with proper notification)
- Platform or shared infrastructure testing → prohibited
What It Does
Enables security testing in a controlled, compliant framework:
- Authorizes vulnerability scanning of your application code and configuration
- Permits penetration testing of your application logic and workflows
- Allows security assessment of custom APIs and integrations
- Protects Pega Cloud infrastructure from harmful testing activities
- Ensures testing does not disrupt other customer environments or services
How It Works
Vulnerability testing follows a structured, approved process:
- Request Authorization: Submit a testing request to Pega Support specifying scope, timing, and testing methods
- Approval Process: Pega Cloud team reviews the request to confirm testing is limited to your application only
- Scheduled Testing: Coordinate testing window to minimize business impact and avoid critical operations
- Scoped Testing: Conduct testing only on your environments and applications; do not target infrastructure
- Documentation & Reporting: Document findings and share results with Pega Cloud team if infrastructure impacts occur
Best Practices
- Submit testing requests in advance (at least 2 weeks prior) to allow Pega review and approval
- Clearly define the scope of testing (specific URLs, endpoints, IP ranges, applications)
- Avoid automated DoS or load tests that could trigger platform alerts or impact service availability
- Use non-production environments whenever possible to test security findings
- Document all discovered vulnerabilities and track remediation efforts internally
- Notify Pega Security immediately if you discover vulnerabilities in platform infrastructure
Technical Documentation: Vulnerability testing policy for applications on Pega Cloud