ShieldOps
A comprehensive web application penetration test and infrastructure audit for a logistics SaaS serving 50,000+ users. We identified and helped remediate 12 critical and 28 medium severity findings before their Series A close.

Client
Logistics Tech Corp
Year
2025
Our Role
Cybersecurity Audit · Web Penetration Testing · Remediation Guidance
The Challenge
What needed solving
The client was preparing for their Series A fundraising round and SOC 2 Type II compliance audit. Operating a high-throughput logistics SaaS processing thousands of daily shipments, their engineering team shipped features rapidly but lacked formal penetration testing. They faced looming compliance deadlines and potential data privacy risks in their API gateway.
The Solution
How we built it
Klytech performed a thorough white-box penetration test and cloud infrastructure security audit across their Next.js web application, REST endpoints, and AWS cloud environment.
01 — Security Audit
Their Challenges
With a rapidly growing user base of over 50,000 active users, the platform faced significant operational security pressure. High-velocity feature releases had left legacy authentication tokens unrotated, and missing rate-limiting on sensitive API endpoints exposed user data to automated credential stuffing attempts.
Furthermore, their infrastructure lacked automated vulnerability scanning in the CI/CD deployment pipeline, making it difficult to detect misconfigurations before reaching production environments.
02 — Security Audit
Our Solutions
Decreased Risk Exposure: Our dedicated security engineering team conducted deep manual privilege escalation testing, GraphQL API fuzzing, and automated dependency audits to isolate attack surfaces efficiently.
API & Infrastructure Hardening: We collaborated directly with their core engineering team to implement JWT key rotation, rate-limiting middleware, and tenant isolation database policies.
DevSecOps Integration: We integrated automated static security analysis (SAST) and container vulnerability scanning directly into GitHub Actions, ensuring security checks execute automatically on every pull request.
Deliverables
Audit Findings & Security Outcomes
Identified and safely validated 12 critical and 28 medium-severity security findings
Remediated broken object-level authorization (BOLA) across core API endpoints
Implemented strict tenant data isolation rules preventing multi-tenant data leaks
Hardened AWS IAM policy configurations and automated container security scans
Delivered executive-ready SOC 2 compliance mapping and attestation report
Achieved 100% remediation of critical findings within 14 days post-audit