Offensive / TestingFintech / embedded payments3-week engagement
Clearing a payments fintech's attack surface before Series B technical due diligence
Series B embedded-payments platform, ~180 staff, AWS-hosted, sponsor-bank integration
A Series B payments platform had a term sheet contingent on technical due diligence, and its sponsor bank required independent penetration-test attestation covering the payments API and public surface. We tested the application, its APIs and the code behind them under signed scope, proved which flaws were genuinely exploitable, and retested the fixes so the founder walked into the data room with a clean attestation instead of an open question.
Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.
- Exploitable findings proven
- 2 critical, 7 high
- manually verified, no scanner noise
- Critical & high findings closed and retested clean
- 100%
- within the 3-week window
- Broken-authorisation API endpoints fixed
- 14
- merchant-tenant isolation restored
- Attestation delivered ahead of deadline
- 3 weeks
- start to signed letter
The challenge
- A lead investor's technical due diligence and a tier-1 sponsor bank both gated on independent pentest evidence for the payments API and public-facing app.
- Broken-authorisation flaws in the API risked exposing one merchant's data to another — the kind of issue that stalls both a valuation and a banking partnership.
- The team had a hard due-diligence deadline three weeks out and no prior third-party attestation to point to.
What we did
- Scoped and signed authorisation for the public web application, the payments and merchant APIs, and a review of the code paths behind sensitive endpoints.
- Ran authenticated and unauthenticated web application testing across every user role, chaining findings to prove real business impact.
- Focused API testing on broken object-level and function-level authorisation (BOLA/IDOR), token handling and merchant-tenant isolation.
- Fed a targeted secure code review from the exploited paths to find the root cause, not just the symptom.
- Shared criticals as we found them so engineering could fix in parallel, then ran a free retest to confirm closure before the data room opened.
The outcome
- Every proven critical and high finding was remediated and confirmed closed on retest inside the engagement window.
- The most serious issues — cross-tenant data access through broken authorisation — were closed at the source in the API layer.
- The founder entered technical due diligence with a clean letter of attestation and a documented remediation trail.
- The sponsor-bank integration proceeded without a security hold.
“The report told us which two things actually mattered and which ones didn't, then they came back and proved the fixes held. That turned our security review from the scariest part of due diligence into a footnote.”