Back to Home

Technical Audit Portfolios

Deep dive reports detailing critical logic bugs discovered during our VAPT audits and secure validation patches implemented for client builds.

FinTech

Prevented BOLA Data Leakage & Secured FinTech Core Banking API

The Scoping Challenge:

A Neo-Banking Startup was launching their API platform, but security scanning failed to check complex multi-step authorization logic.

Control Gap Analysis:

Identified access boundary vulnerability where row-level queries on transfer endpoints failed to check context tenant ownership.

Calculated Exposure:

Potential leakage of financial records of over 120,000 users, leading to RBI compliance violations and brand loss.

Applied Solution Patch

Implemented resource-level authorization validation filters, cryptographically signed entity IDs, and rate limits.

Vulnerabilities Found1 Critical (BOLA), 3 High (Auth Bypass, Rate Limit)
Remediation Time48 Hours
Security Score99/100 (A+ Grade)
Retest Verification100% Patched & Verified
Impact Metric120k records secured, blocking potential $1.2M fraud volume
Key Results100% compliance with RBI Annex G rules, reduced audit prep cycle by 45%
Environment Scope:
Node.jsRedisJWTAWS WAFPostgres
HealthTech

Secured HealthTech Patient Portals for Fast-Track HIPAA Compliance

The Scoping Challenge:

A fast-growing HealthTech platform failed an enterprise hospital's onboarding assessment due to insufficient HIPAA controls and exposed patient file URLs.

Control Gap Analysis:

Diagnosed exposed storage buckets lacking pre-signed authorization tokens, permitting resource queries on sensitive records.

Calculated Exposure:

Exposed sensitive patient records, threatening massive HIPAA penalties and blocking a $450k annual recurring revenue enterprise deal.

Applied Solution Patch

Migrated files to private buckets with short-lived AWS CloudFront signed cookies and integrated OAuth2 controls.

Vulnerabilities Found2 Critical (Insecure Buckets, Lack of Auditing), 1 High (Broken Auth)
Remediation Time72 Hours
Security Score95/100 (A Grade)
Retest Verification100% Patched & Verified
Impact MetricPassed HIPAA & SOC2 controls audit in 14 days with zero deficiencies
Key ResultsSuccessfully closed a $450k ARR contract within 3 weeks of retest
Environment Scope:
ReactAWS S3CloudFrontCognitoPython
SaaS Startup

Hardened SaaS Multi-Tenant Connection Pooling on AWS Cloud

The Scoping Challenge:

A B2B SaaS tool had complex database queries where tenant filters could be bypassed using SQL structures, resulting in potential cross-tenant leakage.

Control Gap Analysis:

Identified connection pool context overlap inside custom ORM configurations, permitting session telemetry leak across tenancy boundaries.

Calculated Exposure:

Uncontrolled access to company telemetry, dashboards, and client files, which would ruin customer trust.

Applied Solution Patch

Redefined connection pool configuration to apply row-level security (RLS) on PostgreSQL, separating database contexts.

Vulnerabilities Found1 Critical (Cross-Tenant Leakage), 2 High (Privilege Escalation)
Remediation Time24 Hours
Security Score97/100 (A+ Grade)
Retest Verification100% Patched & Verified
Impact MetricVerified 100% database boundary isolation under 15,000 concurrent threads
Key ResultsReduced client security questionnaire review time from 3 weeks to 24 hours
Environment Scope:
PostgreSQL RLSAWS RDSNext.jsDockerKubernetes
AI Startup

Blocked Prompt Injection & RAG Data Leakage in AI-Agent Core

The Scoping Challenge:

An AI-powered SaaS startup built on LangChain and pgvector had complex agent queries that did not validate user tenant boundaries inside RAG vector search context pools.

Control Gap Analysis:

Exploited prompt injection vector to force the LLM context query to leak confidential databases and document uploads from separate tenants.

Calculated Exposure:

Exposed private corporate strategy files of enterprise accounts, risking contract breach and trust loss.

Applied Solution Patch

Configured metadata filtering in vector searches to restrict database query scopes strictly by the tenant ID context.

Vulnerabilities Found2 Critical (Indirect Prompt Injection, Context Leakage), 2 High
Remediation Time36 Hours
Security Score98/100 (A+ Grade)
Retest Verification100% Patched & Verified
Impact Metric100% secure vector context query isolation across all user tenant spaces
Key ResultsCleared enterprise AI safety audit, unlocking a $120k pilot deployment
Environment Scope:
LangChainpgvectorPineconeOpenAI APIsPythonFastAPI
Cloud Security

Mitigated Kubernetes Host Namespace Pod Breakouts in E-Commerce Cluster

The Scoping Challenge:

An e-commerce gateway ran merchant integrations in isolated Docker containers, but the Kubernetes configuration allowed host namespace access.

Control Gap Analysis:

Bypassed cluster boundaries through hostPath mounting exploit to gain root privileges on the control plane node.

Calculated Exposure:

Potential complete takeover of payment processing containers and cloud service credentials.

Applied Solution Patch

Enforced Pod Security Standards to 'restricted', disabled privileged pods, and configured read-only root filesystems.

Vulnerabilities Found1 Critical (Host Namespace Breakout), 4 High (Docker/K8s Privileges)
Remediation Time5 Days
Security Score96/100 (A+ Grade)
Retest Verification100% Patched & Verified
Impact MetricSecured 85 production microservices nodes, patching hostPath vulnerabilities
Key ResultsPassed annual PCI-DSS v4.0 Level 1 technical segmentation requirements
Environment Scope:
KubernetesDockerAWS EKSKube-benchIAM Policies
Web3/DeFi

Audited DeFi Staking Smart Contracts, Securing $4.2M Liquidity Pools

The Scoping Challenge:

A decentralized liquidity staking protocol was prepping for launch, but custom payout calculation triggers were vulnerable to state reentrancy.

Control Gap Analysis:

Identified logic path where contract payout transactions executed external calls before updating the internal ledger balance state.

Calculated Exposure:

Potential drainage of the entire $4.2M staking token pool on mainnet deploy.

Applied Solution Patch

Restructured Solidity methods to apply Checks-Effects-Interactions pattern and integrated OpenZeppelin ReentrancyGuard.

Vulnerabilities Found1 Critical (State Reentrancy Payout Bypass), 2 Medium
Remediation Time12 Hours
Security Score100/100 (A+ Grade)
Retest Verification100% Patched & Verified
Impact Metric$4.2M total value locked (TVL) protected against EVM reentrancy calls
Key ResultsDelivered formal math-verification report with 100% patch attestation
Environment Scope:
SoliditySlitherEVM bytecodeHardhatERC-20
Mobile VAPT

Remediated Decryption Key Extraction Vulnerability in Android/iOS Wallet

The Scoping Challenge:

A mobile banking wallet app stored local user cache databases encrypted, but the decryption key seed was compiled inside the binary files.

Control Gap Analysis:

Decompiled the Android APK and iOS IPA files using Jadx and Hopper, extracted the cryptographic key, and decrypted local files.

Calculated Exposure:

Loss of transaction telemetry and local authorization cookies on compromised client devices.

Applied Solution Patch

Migrated local storage encryption to Android KeyStore and iOS Keychain services using hardware-backed key seeds.

Vulnerabilities Found1 Critical (Hardcoded Decryption Key), 3 High (SSL Pinning Bypass, Cache Leak)
Remediation Time4 Days
Security Score94/100 (A Grade)
Retest Verification100% Patched & Verified
Impact Metric200k+ mobile wallets hardened using Hardware-backed KeyStore/Keychain
Key ResultsAchieved Indian FinTech regulatory standards compliance, avoiding warning fines
Environment Scope:
FridaJadxHopperAndroid KeyStoreiOS KeychainReact Native