Security

Authorized external security assessments of live SaaS platforms: reconnaissance, attack-surface mapping and vulnerability analysis, without credentials and without destructive actions. Each one ends in a report with findings by severity, prioritized fixes and a roadmap for the next phases.

01
Client · External assessment · Brazil

Marketplace sales SaaS

Web platform with customer dashboard, .NET API, self-hosted helpdesk, automation and Stripe billing, behind Cloudflare.

subdomains
6
API endpoints mapped
91
findings
13
critical
0

1 high (authenticated only) · 8 low · 4 informational

What was tested

  • HTTP, DNS and WAF fingerprinting and subdomain enumeration
  • API surface mapped from the public OpenAPI specification
  • Access control on every GET endpoint, with and without valid IDs
  • CORS, known CVEs in the helpdesk version, dangling DNS and subdomain takeover
  • Automated scan with 11,204 nuclei templates

Confirmed secure

  • No unauthenticated IDOR: customer, billing and order data protected
  • No secrets leaked in the source code
  • CORS does not reflect malicious origins
  • WAF active and origin IP hidden

Delivered

6-page report with a known SQL injection in the helpdesk flagged for urgent verification, 8 hardening fixes (DMARC, HSTS, headers, Swagger, dangling DNS) and a 5-phase roadmap.

02
Client · External assessment · Brazil

Construction management SaaS with AI agent

Next.js app, Fastify API, AI agent backend and a Model Context Protocol server with 148 tools behind OAuth2.

subdomains
5
MCP tools
148
findings
6
critical or high
0

0 critical · 0 high · 1 medium · 2 low · 3 informational

What was tested

  • Route discovery and JavaScript bundle mining for routes and secrets
  • Unauthenticated access control on every resource endpoint
  • OAuth2 flow of the MCP server: redirect_uri, PKCE and dynamic client registration
  • Error handling, user enumeration and brute-force protection
  • E-mail and DNS hygiene: SPF, DKIM and DMARC

Confirmed secure

  • Every resource endpoint requires authentication
  • CORS allowlist and OAuth redirect_uri allowlist enforced
  • Strict CSP, X-Frame-Options and HSTS preload on the app
  • Login rate limiting, no secrets in the frontend bundles, TLS 1.2 and 1.3

Delivered

6-page report with a DMARC and SPF fix to stop e-mail spoofing, PKCE hardening, and a roadmap covering multi-tenant IDOR, per-tool MCP authorization and prompt injection in the AI agent.

Names, domains and identifiers are anonymized.

Let’s talk

Have a project in mind? Send me a message on WhatsApp and I’ll get back to you soon.