Case studies
What engagements actually look like
Anonymised accounts of real patterns: what was tested, what turned up, and what changed afterwards.
These are illustrative. Engagement reports are confidential, so no client, system, date or figure below is real. Each is a composite written to show the shape of the work and the class of finding, not to record a particular engagement.
Finding the authorisation gaps before launch, not after
A platform preparing to launch asked for a web, API and cloud assessment. The interesting findings were not missing patches but authorisation decisions the application made correctly in the interface and incorrectly in the API behind it.
Read the case study →
The suspected breach that was not a breach, and the real exposure underneath
An organisation believed an outsider had reached a private form. The evidence did not support that. Establishing it surfaced a materially worse exposure that nobody had reported, sitting in plain sight the whole time.
Read the case study →