<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
    <url>
        <loc>https://nullstrikesecurity.com/</loc>
        <lastmod>2026-05-23</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog</loc>
        <lastmod>2026-05-23</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/case_studies</loc>
        <lastmod>2026-05-23</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/newsletter</loc>
        <lastmod>2026-05-23</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/privacy</loc>
        <lastmod>2026-03-22</lastmod>
    </url>

    <!-- Blog posts — newest first -->
    <url>
        <loc>https://nullstrikesecurity.com/blog/palantir-ma-s2-security-standard</loc>
        <lastmod>2026-05-19</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/vanta-drata-penetration-testing-requirements</loc>
        <lastmod>2026-05-17</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/hipaa-penetration-testing-healthcare-saas</loc>
        <lastmod>2026-05-17</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/iso-27001-penetration-testing-requirements</loc>
        <lastmod>2026-05-17</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/pci-dss-penetration-testing-checklist</loc>
        <lastmod>2026-05-17</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/soc2-penetration-testing-requirements</loc>
        <lastmod>2026-05-17</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/do-you-need-a-pentest-for-soc2</loc>
        <lastmod>2026-05-17</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/ciso-guide-to-penetration-testing</loc>
        <lastmod>2026-05-15</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/penetration-testing-compliance-requirements</loc>
        <lastmod>2026-05-14</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/founders-guide-to-penetration-testing</loc>
        <lastmod>2026-05-14</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/penetration-testing-for-enterprise-sales</loc>
        <lastmod>2026-05-14</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/hipaa-soc2-compliance-pentest</loc>
        <lastmod>2026-05-14</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/multi-cloud-attack-surface</loc>
        <lastmod>2026-05-19</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/from-scanning-to-attack-path-validation</loc>
        <lastmod>2026-05-19</lastmod>
    </url>
    <url>
        <loc>https://nullstrikesecurity.com/blog/ai-llm-security-testing</loc>
        <lastmod>2026-05-19</lastmod>
    </url>
</urlset>
