Cross-tenant invoice exposure in a payments platform
A single missing object-level authorisation check let any authenticated tenant read another tenant's invoices. Reproduced with two test accounts.
RASTTSec is a cybersecurity and software development partner. We test your web, API, cloud and LLM systems the way a real adversary would — and then we build the software that closes what we find, from customer-facing web applications to the internal platforms behind them.
Methodology aligned to the standards your auditors already read
RASTTSec exists because the gap between a penetration test report and a working fix is where most security programmes quietly fail. Our testers hand findings to engineers who sit in the same stand-ups, so remediation is realistic, prioritised and — if you want it — delivered rather than described.
Attack surface first, then the engineering to close it. Most clients start with an assessment and grow into a retainer or a build.
External, internal and assumed-breach testing across networks, hosts and infrastructure. Real exploitation, not scanner output.
Authentication, authorisation, session handling, business logic and injection classes — mapped to the OWASP Top 10.
REST, GraphQL and gRPC: broken object-level authorisation, mass assignment, rate limits, token lifecycle and SSRF.
Prompt injection, jailbreaks, system-prompt disclosure, tool abuse and data exfiltration in RAG and agentic systems.
IAM review, exposed services, container and Kubernetes posture, secrets sprawl and CI/CD supply-chain risk.
ISO 27001, SOC 2 and PCI DSS control testing with the evidence pack your auditor actually asks for.
Manual review of the risky 10% of your codebase, with SAST results triaged so nobody drowns in false positives.
Secure-by-design web products: modern front ends, hardened auth, and the same team testing what it built.
Custom platforms, integrations and automation — including the internal security tooling you keep rebuilding by hand.
Sector context changes what matters. A test on a fintech ledger and a test on a hospital portal look nothing alike, even when the underlying flaw is the same class.
Every engagement is run by senior testers who exploit the finding, capture the evidence, and write the reproduction steps your engineers need. No raw tool dumps, no severity inflation.
Kickoff within days of scope sign-off. Critical issues are escalated the moment they are confirmed — you do not wait for the report.
An executive brief your board can read and a technical report with CVSS v4 vectors, payloads and step-by-step reproduction.
NDA-first, minimum data handling, encrypted evidence storage and destruction timelines agreed up front.
Our engineers ship software too, so remediation advice is written by people who have to live with the fix.
Targets, exclusions, testing windows, emergency contacts and legal authorisation are agreed in writing before testing starts.
Passive and active discovery of assets, endpoints, identities and third-party dependencies to define the real attack surface.
Manual testing targeted at the flaws automation cannot reason about: authorisation logic, chained trust boundaries, prompt injection, privilege escalation.
Every candidate finding is reproduced and scored with CVSS v4. What cannot be reproduced is not reported as a confirmed issue.
Executive summary, technical detail, remediation guidance and a live session with your engineers to answer questions.
A retest window confirms what was fixed, what regressed, and what still needs attention — evidence retained for your auditors.
Named references available under NDA on request.
We sign before scoping detail is shared — yours or ours, whichever your legal team prefers.
Data processing addendum and vendor security questionnaires completed by a named contact, not a template bot.
Written scope, deliverables, timeline and price before you commit. Change requests are agreed in writing.
Speak to an existing client in your sector on request — including one where the finding was uncomfortable.
Sanitised case studies from engagements across fintech, healthcare, e-commerce and SaaS.
A single missing object-level authorisation check let any authenticated tenant read another tenant's invoices. Reproduced with two test accounts.
Role-play chains and indirect injection through retrieved documents exposed the system prompt and unrelated customer records.
An IaC drift left a backup bucket world-readable while the application itself was solid — a reminder that the perimeter is not the app.
“They found the authorisation flaw our own penetration test and two scanners missed, then sat with our engineers until the fix was in production.”
“The LLM testing was the first time anyone gave us something actionable about our assistant instead of a generic checklist.”
“Audit-ready evidence, clear severity, no drama. Our ISO auditor accepted the report without a single follow-up question.”
Sample content for preview — replace with approved client quotes and attribution.
Still unsure what you need? Send us the architecture and we will tell you what is worth testing first.
A complete directory — what we do, how we work, what we have delivered, and how to reach a human.
Tell us what you are building or running. We will come back with a scoped plan, a fixed price and a testing window — usually within one business day.