The report is the product.
Cover
Engagement metadata first. Anyone picking the document up six months later can read what was tested, when, by whom and against which version.
Assessment.
Executive summary
Plain language, for the people signing the cheque. What was tested, what was found, what it means for the business, what to do first. No CVSS, no jargon. Findings appear as a one-glance heatmap with impact stated in money or in regulatory terms, not in technical severity alone.
A longer board write-up is available on request, complimentary with any engagement.
What we found
Across the 3-week engagement, we identified 14 findings, of which 2 are critical and require immediate action. The most material issue is an authentication bypass in the customer-facing API that exposes data for any tenant given a single valid token.
Patched in parallel during testing: 6 findings. Outstanding at report delivery: 8.
| Customer API · api.acme.com | 4 | |
| Web application · app.acme.com | 5 | |
| Import service · internal | 3 | |
| Build and release pipeline | 2 |
Technical findings
One structured page per finding: title, CVSS v3.1 vector and score, business impact, affected components, evidence, numbered reproduction steps, and remediation. Fix-in-context code where it helps.
The same findings come as CSV or JSON on request, with ID, title, severity, owner and status pre-filled, so they drop into Jira, Linear or GitHub Issues.
Want to read the real thing? A full sanitised report goes out under NDA. Ask by email and it comes back quickly.
Request a sanitised report →Tenant authentication bypass via predictable workspace token
The workspace bearer token is derived from a non-cryptographic hash of the workspace identifier. An authenticated user in any workspace can derive valid tokens for arbitrary other workspaces and read their secrets.
{"ok": true, "secrets": [...]}
content-type: application/json
{"ok": true, "workspace": 49213, "owner": "northwind-ltd",
"secrets": [{"key": "stripe_live", "value": "sk_live_••••"}]}
Replace the derived token with an opaque, server-issued workspace token bound to the authenticated user. Invalidate all existing tokens on rotation. See appendix A for a drop-in middleware patch.