Frameworks · OWASP ASVS 4.0.3

Requirements, verified.

The Application Security Verification Standard defines verification requirements across chapters V1–V14, at three assurance levels — L1, L2, L3. Pentr verifies the requirements a penetration test can exercise and seals a real request/response proof for each one. Not a scanner's maybe — a captured, signed proof per requirement.

Chapters
V1–V14
Assurance levels
L1 · L2 · L3
Cadence
Per release + quarterly
Evidence retention
12 months
Chapters covered

Verification requirements — tested and sealed.

Each row is an ASVS chapter, the phase in the agent that exercises it, and the request/response artifacts the locker holds.

ID
Chapter
Phase
Artifacts
V14
Configuration
Headers, TLS, and exposed admin or backup surfaces.
02 · intelligence
9 sealed
V1
Architecture, design & threat modeling
Abuse cases derived from the mapped attack surface.
03 · threat modeling
5 sealed
V2
Authentication
Credential handling, lockout, and bypass paths.
04 · vuln analysis
11 sealed
V3
Session management
Token entropy, fixation, and CSRF handling.
04 · vuln analysis
6 sealed
V4
Access control
IDOR, privilege escalation, path traversal — proven live.
05 · exploitation
8 sealed
V5
Validation, sanitization & encoding
Injection, XSS, SSRF exercised against live routes.
05 · exploitation
14 sealed
V13
API and web service
REST/GraphQL auth, rate-limit, and mass-assignment.
05 · exploitation
10 sealed
V11
Business logic
Workflow abuse and state-machine violations.
06 · post-exploit
5 sealed
Phase → chapter mapping

Where each phase earns its evidence.

01 · Pre-engagement

Target & level

Agrees the routes in scope and the ASVS level to verify.

L1–L3
02 · Intelligence

Surface mapping

Fingerprints the stack, entry points, and configuration.

V14
03 · Threat modeling

Architecture

Derives abuse cases from the mapped attack surface.

V1
04 · Vuln analysis

Authn / session

Authentication and session weaknesses as req/resp.

V2V3
05 · Exploitation

Access & injection

Access control, injection, SSRF, and API abuse, proven.

V4V5V13
06 · Post-exploitation

Business logic

Workflow abuse and state-machine violations chained.

V11
07 · Reporting

Locker seal

sha-256 chain signed at seal time. Verifier-ready.

V7

Run your first ASVS verification.

Point Pentr at a set of routes and pick a level. The agent verifies the requirements it can exercise across V1–V14 and seals a request/response proof for every one it confirms.