Security Audit2025

ShieldOps

A comprehensive web application penetration test and infrastructure audit for a logistics SaaS serving 50,000+ users. We identified and helped remediate 12 critical and 28 medium severity findings before their Series A close.

12 critical vulnerabilities resolved
ShieldOps

Client

Logistics Tech Corp

Year

2025

Our Role

Cybersecurity Audit · Web Penetration Testing · Remediation Guidance

SecurityPentestingOWASPAudit

The Challenge

What needed solving

The client was preparing for their Series A fundraising round and SOC 2 Type II compliance audit. Operating a high-throughput logistics SaaS processing thousands of daily shipments, their engineering team shipped features rapidly but lacked formal penetration testing. They faced looming compliance deadlines and potential data privacy risks in their API gateway.

The Solution

How we built it

Klytech performed a thorough white-box penetration test and cloud infrastructure security audit across their Next.js web application, REST endpoints, and AWS cloud environment.

01Security Audit

Their Challenges

With a rapidly growing user base of over 50,000 active users, the platform faced significant operational security pressure. High-velocity feature releases had left legacy authentication tokens unrotated, and missing rate-limiting on sensitive API endpoints exposed user data to automated credential stuffing attempts.

Furthermore, their infrastructure lacked automated vulnerability scanning in the CI/CD deployment pipeline, making it difficult to detect misconfigurations before reaching production environments.

02Security Audit

Our Solutions

Decreased Risk Exposure: Our dedicated security engineering team conducted deep manual privilege escalation testing, GraphQL API fuzzing, and automated dependency audits to isolate attack surfaces efficiently.

API & Infrastructure Hardening: We collaborated directly with their core engineering team to implement JWT key rotation, rate-limiting middleware, and tenant isolation database policies.

DevSecOps Integration: We integrated automated static security analysis (SAST) and container vulnerability scanning directly into GitHub Actions, ensuring security checks execute automatically on every pull request.

Deliverables

Audit Findings & Security Outcomes

Identified and safely validated 12 critical and 28 medium-severity security findings

Remediated broken object-level authorization (BOLA) across core API endpoints

Implemented strict tenant data isolation rules preventing multi-tenant data leaks

Hardened AWS IAM policy configurations and automated container security scans

Delivered executive-ready SOC 2 compliance mapping and attestation report

Achieved 100% remediation of critical findings within 14 days post-audit

Have a project in mind?

Let's discuss what you're building — we'd love to be part of it.

Let's Talk