Start a build Book an assessment
Services Work Trust Insights Company Contact Start a build Book an assessment

The findings nobody wants to publish.

Selected engagements, sanitised. Client names, payloads and identifiers are removed or generalised; the technical mechanism, severity and outcome are preserved.

FintechAPI pentest

Cross-tenant invoice exposure in a payments platform

An object reference in a reconciliation endpoint was trusted from the request body. Any authenticated tenant could read another tenant's invoices by changing one identifier.

CriticalIDORAuthZ
3Critical
7High
9dTo fix
SaaSLLM pentest

System prompt and data leakage in a support assistant

Role-play chains defeated the guardrail instruction, and indirect injection through retrieved help-centre documents pulled unrelated customer records into the response.

HighPrompt injectionRAG
1Critical
6High
12dTo fix
HealthcareCloud review

Public backup bucket behind a private patient portal

The application was well hardened, but infrastructure drift had left a nightly backup bucket world-readable. A reminder that the perimeter is not the application.

CriticalCloud configIaC drift
2Critical
4High
3dTo fix
E-commerceWeb app pentest

Checkout totals decided by the client

Discount and shipping values were recalculated server-side only for display. The order API accepted client-supplied totals, allowing arbitrary price reduction on any basket.

CriticalBusiness logicTrust boundary
1Critical
5High
6dTo fix
FintechCloud / CI-CD

Build pipeline token with production write access

A repository secret held a deployment token scoped to the entire production subscription. Any contributor with workflow-edit rights could have shipped arbitrary code.

HighSupply chainLeast privilege
0Critical
4High
5dTo fix
SaaSAPI pentest

GraphQL resolvers without authorisation checks

Introspection was disabled, but a subset of resolvers skipped the authorisation middleware entirely — including two that mutated billing settings.

CriticalGraphQLMissing authz
2Critical
5High
8dTo fix
Anatomy of a finding

What one line of a RASTTSec report contains.

Every finding carries the same structure, so engineers can act without a follow-up call and auditors can verify without asking.

FINDING-04 · CRITICAL · CVSS 9.3

Broken object-level authorisation in reconciliation endpoint

  • Impact: read access to any tenant's invoice records
  • Prerequisite: one valid low-privilege tenant account
  • Reproduction: authenticated request with a modified object identifier
  • Evidence: request/response captures retained for retest
  • Fix: server-side ownership check on the object before the query executes
Finding record
Critical CVSS 9.3 CWE-639 API1 BOLA
StatusConfirmed — reproduced twice on the client's staging environment
PrerequisiteOne valid low-privilege tenant account
EvidenceRequest and response captures, retained for retest
RetestPassed on the second attempt
After the report

A finding is only useful if it gets fixed.

We do not disappear after delivering the PDF. Every engagement includes a walkthrough, a fix window and a retest — plus the option to have our engineering team do the work.

Engineer walkthrough

A live session where we walk your developers through the findings, answer questions and agree fix order.

Remediation support

Patch review, secure implementation guidance, or our engineers shipping the fix directly in your stack.

Retest and closure letter

Independent confirmation of what is fixed, what regressed, and what remains open — usable as audit evidence.

Evidence handling

Findings and captures stay in encrypted storage under a named access list, with destruction on an agreed schedule.

0
Engagements delivered
0
Findings reproduced before reporting
0
Typical report turnaround
0
Unreproducible findings reported

Want to know what we would find in your product?

Most engagements start with a 30-minute scoping call and a fixed-scope proposal.