Selected engagement notes

Client names and identifying details are withheld. Each note records the tested surface, representative findings and changes verified during the engagement.

Pentest Web + API 3 weeks

Fintech startup preparing for ISO 27001

2 critical fixed in 2 weeks Retest confirmed priority fixes Audit evidence pack delivered

Context

Mid-size fintech preparing its ISO 27001 evidence. The previous assessment concentrated on automated findings; the team wanted a manual review of authorization and payment workflows plus reproducible evidence for remediation.

Scope

Customer-facing web app, internal admin dashboard, REST API handling payment flows. Authenticated + unauthenticated perspectives.

Findings

  • 2 critical: authentication bypass via case-sensitivity + broken access control on admin endpoints
  • 3 high: IDOR exposing payment metadata, stored XSS in internal dashboard, SSRF in attachment upload
  • 3 medium + several info-level: missing rate limits, verbose error disclosure, predictable session tokens

Outcome

The team fixed the critical and high findings within 2 weeks. The retest recorded each fix and the final appendix was added to the organization's audit evidence. Engineering also adopted an authorization checklist based on the affected flows.

"We were preparing for our ISO 27001 certification and needed a proper pentest. Martín found issues that our previous vendor and automated scans had completely missed. Clear report, zero fluff, and he took the time to walk our devs through every fix."

The client on this engagement
Pentest API + multi-tenant 2 weeks

B2B SaaS pre-launch API review

Critical IDOR fixed pre-launch Cross-tenant CI tests added Pre-launch retest completed

Context

B2B SaaS with multi-tenant architecture about to ship a public API. The team wanted a hardening pass focused on tenant isolation before onboarding enterprise customers.

Scope

REST API (~80 endpoints), OAuth 2.0 token flows, two tenant accounts created for cross-tenant testing.

Findings

  • 1 critical: cross-tenant data read via predictable object IDs (classic IDOR)
  • 2 high: OAuth scope escalation through a token-refresh race condition; admin action log filterable by other tenants' users
  • 4 medium: missing authorization on 3 lesser-used endpoints, weak UUID generator for invite tokens

Outcome

The critical and high findings were fixed and retested before launch. The team centralized authorization checks and added automated cross-tenant cases to CI so the affected boundary remains covered.

LLM red team GenAI assistant 1 week

Customer-facing GenAI assistant red team

Cross-account RAG leak closed Tool authorization tightened LLM red-team checklist in release process

Context

SaaS platform shipping an LLM-powered assistant to customers. Grounded on internal RAG with access to account data. Concern: prompt injection, system-prompt leak, cross-account data exposure.

Scope

Assistant UI + backend tool calls + RAG retrieval. Two customer accounts created for cross-account testing.

Findings

  • Internal instruction disclosure via indirect prompt injection through user-uploaded documents; useful for mapping tool behavior, but not treated as impact on its own
  • Tool call abuse: assistant could be coerced to call an internal admin function never meant to be user-exposed
  • Cross-account data leak: RAG retrieved chunks from a different customer's context when a specific multi-step prompt was used
  • Output filter bypass via encoding tricks (base64, homoglyphs)

Outcome

Launch delayed 2 weeks to fix the cross-account leak. Input sanitization and output filters rewritten. Tool-call allowlist tightened. Team now runs an internal LLM red-team checklist before every feature release.

CVE research WordPress plugin Public disclosure

CVE-2025-3769: IDOR in a WordPress plugin with 100K installs

100K active installs at disclosure CVE-2025-3769 issued 4 weeks: report → public CVE

Context

Independent vulnerability research against widely-deployed WordPress plugins. Target: LatePoint, a booking plugin with 100,000+ active installs.

Approach

Source code audit. Traced the plugin's custom ACL system to an AJAX handler that rendered booking details without checking ownership of the booking ID.

Findings

  • IDOR (CWE-639) allowing any registered customer to read any booking in the database: name, email, appointment time, service
  • Same pattern missing in two sibling functions in the same file

Outcome

Coordinated disclosure through Wordfence. Patch shipped in 5.1.93, 4 weeks from report to public CVE. Full writeup on the blog.

Review the report structure

A full anonymised sample report: executive summary, findings mapped to ISO 27001 and SOC 2 controls, proof-of-concept and concrete remediation. No email required.

Download the sample report (PDF) →

Have a similar boundary to test?

Send the application, roles and target date. The pentest page explains the process and deliverables.