How We Work About Services CPS 234 Compliance Results FAQ Blog
Book a Scoping Call →
EdTech · ST4S Pen Testing

Your EdTech product needs a pen test for ST4S. We've done this before.

We helped Scriibi meet their ST4S pen test requirement with a well-documented, OWASP-compliant assessment including retest. Hands-on testing by certified ethical hackers - not automated scanners.

OWASP
Top 10 coverage - what ST4S requires
2–4wks
Including retest cycle
EV10
Critical ST4S requirement met
Penetration Testing

What is the ST4S pen test requirement (EV10)? EV10 is a Critical-importance evidence requirement in the ST4S (Safer Technologies 4 Schools) Full Assessment. Every EdTech supplier selling to Australian schools must submit a qualified external penetration test performed by a certified ethical hacker using OWASP methodology. Automated scanners, AI-powered testing, and vulnerability scanners are explicitly rejected. The report must include detailed findings with reproduction steps, risk ratings, and remediation guidance. Critical and high findings must be remediated and retested before submission.

The ST4S Requirement

What Does ST4S Require for Your Pen Test?

ST4S (Safer Technologies 4 Schools) requires every EdTech supplier selling to Australian schools to submit a qualified external penetration test. This is EV10 - rated Critical. Getting it wrong means you can't sell to schools.

⚠️
Automated scanners are explicitly rejected

ST4S does not accept automated scans, AI-powered pen testing, or vulnerability scanners. The test must be a hands-on exercise by a certified ethical hacker.

📋
Must follow OWASP methodology

Testing must cover the OWASP Top 10 with a documented methodology description, detailed findings, and screenshots or logs for each test.

🔒
Tester must be independent and certified

The pen tester must be fully independent from your development team and hold recognised certifications - OSCP, CEH, GPEN, CREST, CompTIA PenTest+, or eCPPT.

🔄
Critical and high findings must be remediated and retested

A report alone isn't enough. ST4S requires critical and high findings to be fixed, and fixes must be verified through a retest cycle.

What We Deliver

What Does an ST4S-Compliant Pen Test Include?

An ST4S-compliant pen test includes OWASP Top 10 coverage, detailed findings with reproduction steps, risk ratings, remediation guidance, and a retest cycle - all delivered by certified testers independent from your team. Every deliverable is mapped directly to what ST4S assessors look for.

Coverage

OWASP Top 10 Testing

Full OWASP Top 10 coverage as required by ST4S. Manual testing across injection, broken authentication, access control, security misconfiguration, and more.

Evidence

Detailed Report with Reproduction Steps

Every finding includes detailed descriptions, screenshots, reproduction steps, and logs. Written so ST4S assessors - and your dev team - can understand exactly what was found and how.

Prioritisation

Risk Ratings and Remediation Guidance

Findings rated by severity with practical remediation guidance your developers can action immediately. No vague recommendations - clear steps to fix each issue.

Verification

Retest Cycle Included

After you remediate critical and high findings, we retest to confirm fixes are effective. The retest report becomes part of your ST4S evidence pack. Included in the engagement - no extra cost.

Credentials

CREST & OSCP-Certified Testers

All testing performed by certified ethical hackers holding OSCP, CEH, CREST, and GPEN credentials. ST4S accepts all of these certifications.

Independence

Fully Independent from Your Team

ST4S requires the pen tester to be independent from your development team. Logic Weave has no relationship with your codebase or infrastructure - complete separation of duties.

Proof Point

Who Has Passed an ST4S Pen Test with Logic Weave?

Scriibi, an Australian EdTech company, engaged Logic Weave for their ST4S pen test. Here's what their CEO said about the experience.

"Engaged Logic Weave for a penetration test. They delivered well-documented findings with clear reproduction steps and practical remediation guidance. The retest cycle was delivered on time, and the lead tester was open and constructive in discussions. Professional, thorough, and fair throughout. Highly recommended."
David Nicolaides CEO, Scriibi
How It Works

How Does the ST4S Pen Test Process Work?

The ST4S pen test process typically takes 2–4 weeks from scoping call to signed-off retest report. Here are the five steps.

  1. 1. Scoping call
    We review your EdTech application, discuss ST4S EV10 requirements, and define the pen test scope - target systems, testing windows, and deliverables.
  2. 2. OWASP-compliant testing
    Certified ethical hackers (OSCP, CEH, CREST) perform hands-on manual testing covering the OWASP Top 10. No automated scanners - ST4S explicitly rejects them.
  3. 3. Detailed report
    You receive a report with detailed descriptions, screenshots, reproduction steps, risk ratings, and practical remediation guidance - structured for ST4S assessors.
  4. 4. Remediation support
    Your development team fixes critical and high findings using our guidance. We're available for questions throughout the remediation period.
  5. 5. Retest and sign-off
    We retest all remediated findings to confirm fixes are effective. The retest report becomes part of your ST4S evidence pack. Included in the engagement - no extra cost.
Beyond the Pen Test

What Comes After Your ST4S Pen Test?

The pen test gets you through ST4S. After passing, many EdTech companies strengthen their security posture with ongoing assessments, ISO 27001 certification, or fractional CISO services as they scale into new markets.

Ongoing Vulnerability Management

Regular assessments as your product evolves. New features mean new attack surface - stay ahead of it with scheduled testing rather than one-off engagements.

Learn more →

ISO 27001 Certification

Some school departments and state education bodies prefer ISO-certified suppliers. We deliver full ISO 27001 readiness in 16 weeks - even from scratch.

Learn more →

Fractional CISO

Security leadership without a full-time hire. Ideal for EdTech companies scaling into enterprise education, government, or international markets where security governance is expected.

Learn more →

Secure Cloud Infrastructure

AWS environment secured in 4 weeks. IAM policies, encryption, logging, and monitoring configured to meet both ST4S expectations and broader compliance frameworks.

Learn more →
Common Questions

ST4S Pen Testing - Frequently Asked Questions

Can I use an automated scanner for my ST4S pen test?
No. ST4S explicitly rejects automated scans, AI-powered pen testing, and vulnerability scanners. A pen test must be a hands-on exercise by a certified ethical hacker following OWASP methodology. Logic Weave delivers manual-first testing - automated tools are used for discovery only, with every finding validated through manual exploitation.
What certifications does my pen tester need?
ST4S accepts: OSCP, CEH, GPEN, CREST, CompTIA PenTest+, eCPPT, and similar. Logic Weave's testers hold these credentials. We can provide certification evidence as part of the engagement documentation.
What does the pen test report need to contain?
Detailed descriptions of each test, screenshots and logs, OWASP Top 10 coverage, methodology description, risk ratings, and remediation guidance. Our reports are structured to satisfy ST4S assessors - with an executive summary and technical findings that match exactly what they look for.
What if critical findings are discovered?
We provide practical remediation guidance and a retest cycle to confirm fixes. ST4S requires critical and high findings to be remediated. The retest is included in the engagement cost - no additional charges.
How long does the ST4S pen test process take?
Typically 2–4 weeks depending on application complexity, including the retest cycle. We provide a firm timeline before work starts so you can plan your ST4S submission accordingly.
What is the difference between a pen test and a vulnerability scan for ST4S?
A vulnerability scan runs automated tools to identify known weaknesses - ST4S explicitly rejects this as evidence for EV10. A penetration test is a hands-on exercise where a certified ethical hacker manually attempts to exploit vulnerabilities, tests business logic, and chains findings. Only a manual pen test following OWASP methodology satisfies the ST4S requirement.
How much does an ST4S pen test cost?
Cost depends on the complexity of your EdTech application - number of user roles, API endpoints, integrations, and testing scope. We provide a fixed-price quote after the scoping call so there are no surprises. The retest cycle is included at no extra cost. Book a scoping call for a quote.

Ready to meet your ST4S
pen test requirement?

Book a free scoping call. We'll walk you through what ST4S requires for EV10 and scope an engagement that gets you through it.

Book a Pen Test Scoping Call →

No obligation · Melbourne-based · Australia-wide