Hi Everyone,
Before running any security testing against my own Vercel-hosted application (Pro plan), I want to get absolute clarity on what’s permitted under your penetration testing policy — rather than proceeding on assumptions.
I understand the distinction your KB draws between non-volumetric and volumetric testing, but I’d like specifics rather than the general definition:
- Would a manual Nuclei scan against my own Vercel-hosted URL (e.g.
nuclei -u ``https://target.com) be considered non-volumetric and therefore permitted on Pro without prior notice? - If so, are there specific flags or limits I should apply (e.g. rate-limiting, concurrency, template scope) to stay within non-volumetric bounds — or is there a request volume/rate threshold above which it’s considered volumetric regardless of tooling?
- Is there a frequency limit on how often I can run this manually (e.g. once, daily, ad hoc) if it’s permitted?
- Are there other common tools (e.g. Burp Suite, ffuf, sqlmap, nikto) I should flag for the same clarification, or does the same non-volumetric guidance apply uniformly across tools based on request behavior rather than tool name?
I’d appreciate confirmation in writing, so I have something concrete to reference internally.
Thanks in advance for the clarity.