identified security risks
0SaaS product
Conducted web application and API testing, identified weak points in access logic and helped build system protection of cloud infrastructure
critical vulnerabilities are fixed
0incident response time after implementation of recommendations
0
About the client
Ukrainian SaaS company that develops a cloud platform for automating business processes. The service serves thousands of users, stores corporate customer data and provides access through a web application and API.

What problem did the client have?
The company was actively expanding and attracting new corporate clients. Before launching several large integrations, it was necessary to test the security of the platform, evaluate the protection of customer data and ensure that the infrastructure can withstand potential attacks without risking users.

Scope of work
Web application
Verification of personal accounts, business logic, authorization system and administrative panel.
API
Security analysis of public and internal APIs, verification of authorization and data access mechanisms.
Cloud infrastructure
Assessment of server configuration, network policies, data storage and access services.
Access management
Review user roles, privileges, and account security.
How we solved the problem
- [0.1]Conducted an audit of the architecture and cloud infrastructure.
- [0.2]Performed penetration testing of the web application and API.
- [0.3]Checked the mechanisms of authorization and delimitation of accesses.
- [0.4]Provided technical recommendations for eliminating risks.
- [0.5]Confirmed the fix by retesting.

Customer feedback
“SafeNet Cyber helped us see risks that standard screening tools didn't detect. The API audit and recommendations on client data protection became especially valuable. Thanks to this, we were able to confidently scale the platform and work with enterprise clients.”

CTO, SaaS company