> For the complete documentation index, see [llms.txt](https://docs.softwaresecured.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.softwaresecured.com/pentesting-with-software-secured/glossary-less-than-wip-greater-than.md).

# Glossary \<WIP>

### Executive Summary

A document that includes a summary of the report that can be shared with external customers and shareholders as proof of completion for the pentest.&#x20;

For more information, see [Viewing and downloading reports and executive summaries](/reports-and-certificates/viewing-and-downloading-reports-and-executive-summaries.md).&#x20;

***

### Component

A category to assign to specified findings during a pentest.&#x20;

For more information, see [Project components](/planning/kickoff-call/project-components.md).&#x20;

***

### Finding

A vulnerability discovered by <code class="expression">space.vars.company\_name</code> during a pentest. Each finding has its own unique identifier in the pentest report.&#x20;

***

### Intercepting Proxy

A tool that allows testers to intercept, inspect, modify, and send HTTP requests to a server in order to test for different vulnerabilities.&#x20;

***

### Pentest Director

The primary tester who will conduct your pentest. This tester will also be your main point of contact during the test if you have any questions. Other testers might be involved in your test depending on the scope, timeframe, and complexity.&#x20;

***

### Penetration Test

An authorized test that simulates real-world attacks on a product to determine the state of its security and compliance. Often abbreviated as *pentest*.

* For a more detailed definition, see [Penetration Testing | SANS Institute](https://www.sans.org/security-resources/glossary-of-terms/penetration-testing).&#x20;
* For <code class="expression">space.vars.company\_name</code>'s testing methodologies, see [Testing methodologies \<WIP>](/methodologies/testing-methodologies-less-than-wip-greater-than.md).&#x20;

***

### Production Environment

The live environment for a product that can be accessed externally by clients. Production environments are tested during network and infrastructure tests; production can be tested during other types of tests as well, but those tests have higher risks for outages and data deletion.&#x20;

For more information, see [Preparing your environment for the testing team](/planning/preparing-your-environment-for-the-testing-team.md).&#x20;

***

### Report

The results of the pentest that includes detailed information about <code class="expression">space.vars.company\_name</code>'s findings.&#x20;

For more information, see [Viewing and downloading reports and executive summaries](/reports-and-certificates/viewing-and-downloading-reports-and-executive-summaries.md).&#x20;

***

### Retest/retesting

A service where <code class="expression">space.vars.company\_name</code> retests vulnerabilities that we previously reported to see if you remediated them successfully.&#x20;

For more information, see [Retesting your vulnerabilities](/after-testing/retesting-your-vulnerabilities.md).&#x20;

***

### SLA

Service Level Agreement

For more information, see [Service Level Agreements (SLAs)](/findings/service-level-agreements-slas.md).&#x20;

***

### Staging/test environment

A non-production environment for a product that can only be accessed internally. These environments are typically where development is tested. In general, <code class="expression">space.vars.company\_name</code> tests these non-production environments to minimize risk for outages and data deletion on the production environment.&#x20;

For more information, see [Preparing your environment for the testing team](/planning/preparing-your-environment-for-the-testing-team.md).&#x20;

***

### Vulnerability

A flaw or weakness in a system or product that can be exploited by attackers. Sometimes used interchangeably with finding or issue.&#x20;
