All case studies
Public Sector
Web Application Penetration Testing
Citizen services portal hardened ahead of a national rollout
Pre-launch testing of a citizen identity portal focused on authentication, session handling and document upload paths, with all findings closed before go-live.
- Client
- Government agency portal serving 2.5M citizens
- Duration
- 4 weeks including two retests
- Headline issue
- Unauthenticated identity document retrieval via predictable storage references
- Sector
- Public Sector
The challenge
The portal handled identity documents and had a fixed public launch date, leaving no room for post-launch remediation of serious issues.
Our approach
- Prioritised authentication, session lifecycle and file handling in week one so fixes could start immediately.
- Ran two scheduled retests aligned to the client's release train.
- Produced an executive summary written for non-technical programme sponsors.
Outcome
- All high and critical findings closed before launch.
- Document upload pipeline rebuilt with content validation and isolated storage.
- Launch proceeded on schedule with a signed attestation letter.
More case studies
Financial Services
Payments platform API penetration test uncovers account takeover chain
A grey-box API assessment across 180 endpoints exposed a broken object-level authorisation chain that allowed full merchant account takeover without user interaction.
SaaS & Platforms
Multi-tenant isolation review for a B2B SaaS ahead of enterprise onboarding
Authenticated testing across four tenant personas confirmed strong perimeter controls but revealed cross-tenant data leakage through an export job and a background webhook worker.