What the buyer is really asking
Which kinds of testing do you actually run: static analysis, dynamic scanning, dependency scanning, third-party penetration tests? Name the tools and how often each runs. Be plain about anything you do not do yet.
Other ways buyers ask it
Every one of these wants the same answer:
- “What application security testing do you perform?”
- “Do you perform SAST and DAST?”
- “Do you conduct penetration tests?”
- “Can you share your latest pen test report?”
Evidence to have ready
- Scanner configuration in CI
- The most recent penetration test summary, if one exists
- Remediation records for findings
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.