SLA scope

Last updated: Oct 1, 2026


The scope sets the limits of the security tests. A clear scope is very important for a clear service-level agreement (SLA).

For the Fluid Attacks solution, four primary criteria set the scope:

  • Parity: The active repositories and matching environments that you register on the Fluid Attacks platform. For more information, read "Methodology".
  • Health Check: When you request a Health Check, the Fluid Attacks pentesters analyze the development from before the start of the Advanced plan.
  • Supported technologies: If Fluid Attacks supports the technologies of the development.
  • Ownership: If Fluid Attacks has the consent of the owner of the application to analyze it.

Parity

The analysis of environment and code parity below defines the scope of Fluid Attacks. Thus it also defines what can be a false negative (FN) and what is added value.

Parity in and out of scope scenarios by Fluid Attacks

Examples

The simplified examples below show how to identify each scenario.

Complete match

You wrote a small Python script, calculator.py, with only five functions (add, subtract, multiply, divide, and modulo). Fluid Attacks examines the environment that you gave, for example a dedicated microservice container, and finds this:

  • The environment has only those five functions.
  • It has no more scripts, libraries, or utilities.

The environment and your code are the same, with nothing more and nothing less. This is a complete match.

Fully contained

You deploy your calculator.py, with its five functions, on a large ML platform environment. The environment also has data manipulation libraries, unrelated scripts, and frameworks for logs. This is true of the environment:

  • It contains all of your calculator.py.
  • It also has many other scripts and libraries that are not related to your code.

All your code is there, but the environment also has "extras." This is a fully contained scenario.

Partial match

The environment that you gave has only the add and subtract functions of your calculator.py. The other three (multiply, divide, and modulo) are missing. This is true of your environment:

  • It has part of the code.
  • It does not contain all five functions.

Because only some of the functions are there, this is a partial match.

Complete mismatch

The environment that you gave is only a service that processes text. It has none of the functions, structure, or code segments of your calculator.py.

None of the functionality of your code is there. This is a complete mismatch.

No environment

You give only your calculator.py code. There is no container, no platform, and no hosted environment for the code to run in.

There is no environment at all. This is a no environment scenario.

Health Check

A Health Check applies SCR, PTaaS, and RE to the code written before you got the Advanced plan. The organization decides if it wants a Health Check. It is a decision based on risk. Without a Health Check, the organization can miss vulnerabilities in the code from before the subscription. If the Health Check does not include all the repositories of the group, the accuracy SLA does not apply.

The analysis below combines parity and Health Check. It defines the scope of Fluid Attacks more accurately than the parity analysis alone (the analysis above). Thus it also defines what can be a false negative (FN) and what is added value.

With a Health Check

Health Check in and out of scope scenarios by Fluid Attacks

To identify the scenarios, take the scenarios of the parity analysis and add the Health Check. That is, the Fluid Attacks pentesters analyzed all the code from before your subscription to the Advanced plan.

Without a Health Check

No Health Check in and out of scope scenarios by Fluid Attacks

To identify the scenarios, take the scenarios of the parity analysis again, with no Health Check in each of them. That is, the Fluid Attacks pentesters did not analyze the code from before your subscription to the Advanced plan.

Supported technologies

The scope of the tests includes only the technologies that Fluid Attacks officially supports. Thus, a vulnerability that someone other than Fluid Attacks finds in an unsupported stack is not a false negative. The "Support information" section shows the supported technologies.

Ownership

Fluid Attacks does not analyze an application without explicit authorization from the owner of the application. Thus, a vulnerability found in software that Fluid Attacks has no consent to test, for example third-party software, is not a false negative.

On this page