Annual external penetration test — booking + parts surfaces
Two-week grey-box engagement focused on the public booking, quote and parts surfaces plus the workshop staff console. No critical or high findings remained at re-test. Two medium-severity SSRF candidates were confirmed mitigated by the workshop's egress allowlist. Three low-severity informational items were filed for next sprint.