

611·
19 days agoA penetration test is not an audit and does not provide any such assurance that logs are not retained. The goal of a penetration test is to penetrate via vulnerabilities and misconfigurations, not validate public logging claims about a service
Your belief is wrong. That is not what a penetration test does. They are looking at it from the outside.