Skip to content
Solvex Space
Offensive / TestingFintech / embedded payments3-week engagement

Clearing a payments fintech's attack surface before Series B technical due diligence

Series B embedded-payments platform, ~180 staff, AWS-hosted, sponsor-bank integration

A Series B payments platform had a term sheet contingent on technical due diligence, and its sponsor bank required independent penetration-test attestation covering the payments API and public surface. We tested the application, its APIs and the code behind them under signed scope, proved which flaws were genuinely exploitable, and retested the fixes so the founder walked into the data room with a clean attestation instead of an open question.

Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.

Exploitable findings proven
2 critical, 7 high
manually verified, no scanner noise
Critical & high findings closed and retested clean
100%
within the 3-week window
Broken-authorisation API endpoints fixed
14
merchant-tenant isolation restored
Attestation delivered ahead of deadline
3 weeks
start to signed letter

The challenge

  • A lead investor's technical due diligence and a tier-1 sponsor bank both gated on independent pentest evidence for the payments API and public-facing app.
  • Broken-authorisation flaws in the API risked exposing one merchant's data to another — the kind of issue that stalls both a valuation and a banking partnership.
  • The team had a hard due-diligence deadline three weeks out and no prior third-party attestation to point to.

What we did

  • Scoped and signed authorisation for the public web application, the payments and merchant APIs, and a review of the code paths behind sensitive endpoints.
  • Ran authenticated and unauthenticated web application testing across every user role, chaining findings to prove real business impact.
  • Focused API testing on broken object-level and function-level authorisation (BOLA/IDOR), token handling and merchant-tenant isolation.
  • Fed a targeted secure code review from the exploited paths to find the root cause, not just the symptom.
  • Shared criticals as we found them so engineering could fix in parallel, then ran a free retest to confirm closure before the data room opened.

The outcome

  • Every proven critical and high finding was remediated and confirmed closed on retest inside the engagement window.
  • The most serious issues — cross-tenant data access through broken authorisation — were closed at the source in the API layer.
  • The founder entered technical due diligence with a clean letter of attestation and a documented remediation trail.
  • The sponsor-bank integration proceeded without a security hold.
The report told us which two things actually mattered and which ones didn't, then they came back and proved the fixes held. That turned our security review from the scariest part of due diligence into a footnote.
CTO, Series B payments platformIllustrative — composed to show the kind of feedback this work draws, not a quotation from a named client.
Fintech Pentest Before Series B Due Diligence | Case Study — Solvex Space