A logistics platform wanted its new customer API tested before a major retailer signed.
The challenge
A retail customer's procurement team required a recent penetration test report before signing. The API had been built quickly by a small team and reviewed only by automated scanning, which reported nothing significant.
What we did
Testing covered the API as an anonymous user and as two separate customer tenants. Object identifiers were sequential and access checks were applied at the route level rather than the record level, so one tenant could read another's shipment details, including recipient addresses. A second finding allowed rate-limit bypass on the login endpoint.
The outcome
Both findings were fixed within the engagement window with guidance from the consultant. The retest confirmed closure and the updated report was accepted by the retailer's security team. The client added authorization tests to its CI pipeline based on the reproduction steps.
Get the same answer for your systems.
One scoping call, a fixed-price proposal, and a written result you can show your board or your customers.