SLA scope
Last updated: Oct 1, 2026
The scope sets the limits of the security tests. A clear scope is very important for a clear service-level agreement (SLA).
For the Fluid Attacks solution, four primary criteria set the scope:
- Parity: The active repositories and matching environments that you register on the Fluid Attacks platform. For more information, read "Methodology".
- Health Check: When you request a Health Check, the Fluid Attacks pentesters analyze the development from before the start of the Advanced plan.
- Supported technologies: If Fluid Attacks supports the technologies of the development.
- Ownership: If Fluid Attacks has the consent of the owner of the application to analyze it.
For the accuracy SLA of Fluid Attacks to apply, more criteria must be true.
Parity
The analysis of environment and code parity below defines the scope of Fluid Attacks. Thus it also defines what can be a false negative (FN) and what is added value.

Examples
The simplified examples below show how to identify each scenario.
Complete match
You wrote a small Python script, calculator.py,
with only five functions
(add, subtract, multiply, divide, and modulo).
Fluid Attacks examines the environment that you gave,
for example a dedicated microservice container,
and finds this:
- The environment has only those five functions.
- It has no more scripts, libraries, or utilities.
The environment and your code are the same, with nothing more and nothing less. This is a complete match.
Fully contained
You deploy your calculator.py, with its five functions, on a large ML platform environment. The environment also has data manipulation libraries, unrelated scripts, and frameworks for logs. This is true of the environment:
- It contains all of your calculator.py.
- It also has many other scripts and libraries that are not related to your code.
All your code is there, but the environment also has "extras." This is a fully contained scenario.
Partial match
The environment that you gave has only the add and subtract functions
of your calculator.py.
The other three (multiply, divide, and modulo) are missing.
This is true of your environment:
- It has part of the code.
- It does not contain all five functions.
Because only some of the functions are there, this is a partial match.
Complete mismatch
The environment that you gave is only a service that processes text. It has none of the functions, structure, or code segments of your calculator.py.
None of the functionality of your code is there. This is a complete mismatch.
No environment
You give only your calculator.py code. There is no container, no platform, and no hosted environment for the code to run in.
There is no environment at all. This is a no environment scenario.
Health Check
A Health Check applies SCR, PTaaS, and RE to the code written before you got the Advanced plan. The organization decides if it wants a Health Check. It is a decision based on risk. Without a Health Check, the organization can miss vulnerabilities in the code from before the subscription. If the Health Check does not include all the repositories of the group, the accuracy SLA does not apply.
The analysis below combines parity and Health Check. It defines the scope of Fluid Attacks more accurately than the parity analysis alone (the analysis above). Thus it also defines what can be a false negative (FN) and what is added value.
With a Health Check

To identify the scenarios, take the scenarios of the parity analysis and add the Health Check. That is, the Fluid Attacks pentesters analyzed all the code from before your subscription to the Advanced plan.
Without a Health Check

To identify the scenarios, take the scenarios of the parity analysis again, with no Health Check in each of them. That is, the Fluid Attacks pentesters did not analyze the code from before your subscription to the Advanced plan.
Supported technologies
The scope of the tests includes only the technologies that Fluid Attacks officially supports. Thus, a vulnerability that someone other than Fluid Attacks finds in an unsupported stack is not a false negative. The "Support information" section shows the supported technologies.
On managed dependencies: The Fluid Attacks SCA finds vulnerabilities only
in third-party libraries that standard manifest files declare, for example
package.json, requirements.txt, and pom.xml. The scope of the tests
excludes libraries or dependencies that someone copied directly into the
source code of the repository, with no declaration. For full traceability and
detection of known vulnerabilities, you must manage all dependencies through
the manifests of their package managers.
Ownership
Fluid Attacks does not analyze an application without explicit authorization from the owner of the application. Thus, a vulnerability found in software that Fluid Attacks has no consent to test, for example third-party software, is not a false negative.
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' pentesting team, complete this contact form.