Case Studies

The Kind of Work We Do

Client engagements are confidential by default — that's part of what an NDA means. Rather than publish names or invented success metrics, here's an honest look at the type and shape of work we take on, with references available directly.

The examples below are illustrative composites describing typical engagement scope by industry — not a specific named client's real results.

Fintech

Payment Platform — Web & API Assessment

A grey-box engagement covering the customer web application and the internal APIs handling transactions, scoped for PCI DSS Requirement 11.4. Testing focused on transaction-authorization boundaries between accounts and business-logic abuse in the payment flow.

SaaS

B2B Platform — Multi-Tenant Isolation Testing

A web application penetration test with an explicit focus on whether one customer's tenant could access another's data, ahead of an enterprise customer's security review requirement.

Healthcare

Patient Portal — HIPAA-Aligned Testing

Testing of a patient-facing portal and its backend API, mapped to HIPAA Security Rule safeguards to support the client's annual risk analysis obligation.

Ecommerce

Storefront & Admin Panel Assessment

A web application test covering the public storefront, checkout logic, and the internal admin/inventory panel, including a custom-built discount engine.

Corporate Network

Internal Network & Active Directory Review

An internal network penetration test simulating a compromised employee laptop, mapping the path from initial foothold to domain admin.

Program

Recurring Vulnerability Assessment Program

A quarterly vulnerability assessment program across a growing infrastructure estate, tracking new and recurring findings release over release.

Want to Talk to a Reference Directly?

With permission from the relevant client, we can put you in touch with a past client in a similar industry to yours instead of asking you to take our word for it.

Ready to Start Your Own Engagement?

Tell us what you'd like tested and we'll scope it properly.