# Trust portal: verify a DXCL certificate, sample report, methods

Canonical page: https://dxcl.tech/trust/

Check our work. Then check us. Verify a DXCL certificate, see what our reports look like, and read exactly how we test.

## Verify a certificate

Open https://dxcl.tech/trust/?id=CERTIFICATE-ID in a browser, or type the ID printed on the certificate into the form. IDs look like DCL-XXXX-XXXX-XXXX. The result shows who the certificate was issued to, the scope, the testing window, the issue and expiry dates, the fix check date once done, and whether it is valid, expired or revoked today.

The check runs in the browser. Each record is encrypted with its own certificate ID, so only someone holding the ID can read it, and DXCL never publishes a list of the companies it tests. If a check fails, email info@dxcl.tech with the ID and a person will confirm it.

Sample certificate to try: DCL-DEM0-2026-0001 (issued to the fictional Sample Company Pvt Ltd).

## What a certificate means

It confirms:
- DXCL tested the systems listed in the scope, in the testing window shown.
- Testing combined automated attacks with manual testing of every page and endpoint in scope.
- Every finding was reported to the holder with its impact and a fix.
- When the fix check is complete, the date it was done.
- The date it stops counting as evidence: 3 to 6 months after the report, set per engagement.

It does not claim:
- That the system has no vulnerabilities.
- Anything about systems outside the listed scope, or changes shipped after the testing window.
- To be a CERT-In audit certificate, an ISO 27001 certification or a SOC 2 report. It complements those; it does not replace them.

Lifecycle: issued on the day of the report; fix check recorded; valid for 3 to 6 months; expired or renewed by a full retest with a new ID; revoked if misused or if the scope was misrepresented.

## Sample report

Every engagement ends with a managerial report for leadership, a technical report for engineers, a live walkthrough call with the testers, and an included fix check. Sample: https://dxcl.tech/trust/sample-report/

## How we test

Automated attacks with best-of-market tools, then manual testing of every page and endpoint in scope. Test plans follow public standards:
- Web applications: OWASP Web Security Testing Guide (WSTG) and Application Security Verification Standard (ASVS).
- APIs: OWASP API Security Top 10.
- Mobile apps: OWASP MASVS and MASTG.
- AI and LLM systems: OWASP Top 10 for LLM Applications and MITRE ATLAS.
- Network and cloud: NIST SP 800-115 and PTES.
- IoT devices: OWASP IoT Security Testing Guide (ISTG).

On request, findings are mapped to controls such as ISO/IEC 27001 Annex A, SOC 2, PCI DSS and the reasonable security safeguards required by India's DPDP Act.

## How findings are rated

Each finding gets a CVSS base score and a severity, adjusted for business context, with every adjustment explained in the report.
- Critical: direct path to sensitive data or full control, with little effort or skill.
- High: serious impact that needs some access or a specific condition.
- Medium: real weakness with limited impact, or one that needs chaining with others.
- Low: small risk on its own.
- Informational: no direct risk; a hardening step or good practice.

## Rules of engagement

- Written approval first: testing starts only after the client approves scope, environment and window in writing.
- Certified people: every engagement is run by certified security testers the client meets and talks to directly.
- Your data stays yours: what we see is used only to test and report; findings go to the people the client names.

## Report a vulnerability in DXCL

Email info@dxcl.tech with the affected URL or system, steps to reproduce and how to reach you. Please do not access, change or keep data that is not yours, run denial-of-service, spam or social engineering tests, or share the issue publicly before it is fixed. Machine-readable contact: https://dxcl.tech/.well-known/security.txt
