Cross-tenant invoice exposure in a payments platform
An object reference in a reconciliation endpoint was trusted from the request body. Any authenticated tenant could read another tenant's invoices by changing one identifier.
Selected engagements, sanitised. Client names, payloads and identifiers are removed or generalised; the technical mechanism, severity and outcome are preserved.
An object reference in a reconciliation endpoint was trusted from the request body. Any authenticated tenant could read another tenant's invoices by changing one identifier.
Role-play chains defeated the guardrail instruction, and indirect injection through retrieved help-centre documents pulled unrelated customer records into the response.
The application was well hardened, but infrastructure drift had left a nightly backup bucket world-readable. A reminder that the perimeter is not the application.
Discount and shipping values were recalculated server-side only for display. The order API accepted client-supplied totals, allowing arbitrary price reduction on any basket.
A repository secret held a deployment token scoped to the entire production subscription. Any contributor with workflow-edit rights could have shipped arbitrary code.
Introspection was disabled, but a subset of resolvers skipped the authorisation middleware entirely — including two that mutated billing settings.
No case studies in this category yet.
Every finding carries the same structure, so engineers can act without a follow-up call and auditors can verify without asking.
We do not disappear after delivering the PDF. Every engagement includes a walkthrough, a fix window and a retest — plus the option to have our engineering team do the work.
A live session where we walk your developers through the findings, answer questions and agree fix order.
Patch review, secure implementation guidance, or our engineers shipping the fix directly in your stack.
Independent confirmation of what is fixed, what regressed, and what remains open — usable as audit evidence.
Findings and captures stay in encrypted storage under a named access list, with destruction on an agreed schedule.
Most engagements start with a 30-minute scoping call and a fixed-scope proposal.