Pass your Meta Third-Party Assessment (TPA)
Meta's TPA digs into how you store, protect, and delete Platform Data. Pentest Today produces the pentest, scan evidence, and security policies assessors ask for so you can answer with proof, not promises.
What a Meta TPA review asks for
Meta requires apps and vendors that access Platform Data to complete an annual Third-Party Assessment (formerly the Data Protection Assessment) with an approved assessor.
Scan
Authenticated and external scans across web, API, and cloud surface the issues before an assessor does — de-duped, triaged, and mapped to CVE/CVSS.
Pentest
Approved-target scans become a client-ready pentest report: validated findings, evidence, reproduction steps, remediation, and the retest letter auditors accept.
Policy Generator
Generate the policies and system architecture diagrams the review expects — access control, cryptography, incident response — pre-mapped to controls.
Google VSA
Google's Vendor Security Assessment reviews how suppliers protect Google and user data before and during an engagement.
Microsoft SSPA
Microsoft's Supplier Security and Privacy Assurance (SSPA) program requires suppliers handling Microsoft personal data to attest to the Data Protection Requirements (DPR).
Salesforce Security Review
AppExchange partners must pass Salesforce's Security Review, which includes scanning and penetration testing of the offering before listing.
Lema AI
Lema is an AI-powered third-party risk platform buyers use to assess a vendor's security posture from uploaded evidence and questionnaire answers.
Whistic
Whistic lets vendors publish a Security Profile and respond to customer assessments from a single shared source of evidence.
Vanta
Vanta automates compliance and vendor risk; buyers using Vanta will request evidence of your security controls and tests.
Meta TPA, answered
What is the Meta Third-Party Assessment?
It's Meta's annual review of developers and vendors that handle Platform Data, carried out by Meta-approved assessors against the Platform Terms and Data Protection requirements.
How does Pentest Today help with the TPA?
We generate the security evidence the assessment relies on — a pentest report, scan results, and policies covering access, encryption, retention, and incident response — scoped to the systems that touch Platform Data.
Is the pentest a real test or just a scanner dump?
Both scanning and AI triage are scoped to your approved targets, and every finding is reviewed and signed off by a human before delivery — so the report reflects verified findings, not raw scanner noise.
How fast can I get a report?
Most reports turn around in hours, not weeks. You connect an approved target, we scan and verify, and you export a client-ready report and policy pack.
Get the evidence for your Meta TPA review this week.
Start a scan on an approved target and walk in with the report, policies, and diagrams already done.