Identified vulnerabilities
0FinTech company
Prepared the infrastructure for GDPR requirements, checked the protection of payment systems and implemented comprehensive measures to protect financial data
Critical risks have been eliminated
0Incidents after changes
0
About the client
Ukrainian FinTech company that provides digital financial services for businesses and private users. The platform processes financial transactions, personal data of customers and integrates with banking systems and payment providers.

What problem did the client have?
The company was preparing to expand its partner network and undergo inspections by large corporate clients. Before launching new financial services, it was necessary to evaluate the level of protection of the platform, check the security of the API and make sure that there are no critical risks for client data.

Scope of work
Web application
The user's personal account, shopping cart, ordering and administrative panel
API
Analysis of interaction with payment services, banking systems and external partners
Infrastructure
Server configuration, access and network settings
Payment integrations
Scenarios of payment and processing of financial transactions
How we solved the problem
- [0.1]Conducted a comprehensive cybersecurity audit of the platform.
- [0.2]Performed penetration testing of the web application and API.
- [0.3]Prepared a detailed report with priorities for eliminating risks.
- [0.4]Helped the team implement recommendations to strengthen protection.
- [0.5]Conducted a re-check after implementing the changes.

Customer feedback
“We received not just a list of problems, but a clear action plan to improve the level of security. The SafeNet Cyber team helped us prepare the platform to work with large partners and significantly strengthen access control.”

CISO, FinTech company