Case Study
From an unattended staging environment to payment-API access — and every hole closed.
A digital vault platform trusted with its customers' most sensitive documents asked SecurityBoat one question: what could a real attacker actually do? The answer started in a forgotten staging environment and ended at the payment API — and every finding was fixed and retest-verified before the engagement closed.
01
Challenge
The client runs a digital vault platform — comparable to DigiLocker — where individuals and businesses store the documents they can least afford to lose: identity records, agreements, financial paperwork. Payments run through integrated APIs. For a product like this, trust is the product. A single authorization flaw doesn't leak one account — it breaks the promise the entire platform is built on.
The engineering team had done the responsible things — hardened production, passed scanner runs, cleaned up the obvious. What they couldn't answer was the question scanners never ask: can a determined human chain small gaps into real impact? They needed deep manual testing from an attacker's perspective, findings they could act on immediately rather than a PDF at the end, and proof that fixes actually held.
02
Solution
SecurityBoat ran the assessment as a TriNetra PTaaS engagement: one live engagement record from scoping to closure, instead of a report that arrives after the damage window has already passed.
Scoped in the open. Guided scoping captured the technical, business, and risk context up front — the vault's document flows, the payment integration, the environments in play — with explicit in-scope and out-of-scope rules on the engagement record.
Two testing lenses. A black-box phase approached the platform exactly as an outside attacker would — no credentials, no documentation, no hints. A grey-box phase followed with authenticated access across user roles, going deep on authorization, session handling, and business logic.
Findings as they were verified — not at the end. Every verified finding published straight to the client's role-scoped dashboard with CVSS scoring, steps to reproduce, raw request and response, and remediation guidance. Remediation planning started while testing was still live.
A retest gate, not a handshake. No finding closed on “we fixed it.” The client marked fixes ready for retest; the same testers re-attacked and either confirmed the fix or sent it back.
Pentest Engagements
Total 20Active 14Completed 603
Methodology
The engagement moved through TriNetra PTaaS's 12-state lifecycle — Requested → Draft → Scoping → Open for bids → Team formed → Scheduled → Live → Report drafting → Report review → Delivered → Remediation → Closed — with an append-only history of every transition.
Black-box phase. Reconnaissance and asset enumeration across the platform's exposed surface, unauthenticated attack-surface probing, and input testing against everything reachable — mapping what an attacker with zero inside knowledge could find and touch.
Grey-box phase. Authenticated testing across user roles against the engagement's auto-seeded methodology checklist: authorization and object-level access control, session and token handling, business-logic abuse of document and payment flows, and API testing against the payment integration. Coverage percentage was tracked live as testers worked, so “thorough” was measurable, not asserted.
Findings discipline. Every finding carried scored and decomposed severity, CWE references, CIA-triad impact, steps to reproduce, and raw request/response evidence. The findings lifecycle kept pre-verification triage internal — the client's dashboard only ever showed verified, actionable signal.
04
Attack Lifecycle
The finding this engagement is remembered for wasn't a single exotic bug. It was a chain of ordinary oversights that, linked together, reached the payment API.
- 01
Step 1 — Reconnaissance. During black-box enumeration, testers surfaced an unattended staging environment — stood up for an earlier release cycle, still publicly reachable, and no longer on anyone's radar. Production was hardened. Staging wasn't.
- 02
Step 2 — Foothold. The staging build ran with weaker controls than production. Exploiting it yielded sensitive information disclosure: internal configuration details and material that was never meant to leave the perimeter.
- 03
Step 3 — Escalation. The disclosed material opened a path to the platform's payment APIs. Testers demonstrated — safely, against controlled proof-of-concept accounts — that an attacker could invoke payment-API functionality on behalf of other customers. The forgotten environment had become a bridge into the most sensitive transaction path the platform has.
- 04
Step 4 — Contained disclosure. The chain stopped at proof of concept. It was written up with full request/response evidence and published to the client's dashboard as a verified finding the moment validation completed — not weeks later in a final report — so containment and remediation started immediately.
- 05
Step 5 — Fix and retest. The staging environment was decommissioned, the disclosure vectors were closed, and the payment-API authorization gap was fixed. Each fix went through the retest gate: the same testers re-ran the attack chain and confirmed it was dead before the finding — and the engagement — closed.
Client Testimonial
“Ninad and his young team are enthusiastic, professional and are fully aware of the implications of their work… Their detailed report and handholding are invaluable.”
On the record
Every hole closed — and proven closed.
No finding closed on “we fixed it.” The retest gate — the same testers re-attacking until the fix held — is part of the engagement itself.
SQL injection in legacy reporting export
payments-service · reported by PTaaS engagement PT-2026-182
Retest queued the moment the fix landed — the loop that proves the fix held.Retest SLA · 3d
06
Key Outcomes
Comprehensive testing, measurably so. Black-box and grey-box coverage tracked against the engagement's methodology checklist — the client could see coverage climb, not take it on faith.
The chain that mattered, found before an attacker found it. A staging-to-payment-API path that no scanner flagged, demonstrated safely and reported with full evidence.
Actionable remediation, immediately. Verified findings hit the live dashboard with reproduction steps and remediation guidance while testing was still running — no waiting for a final PDF to start fixing.
Every hole closed — and proven closed. The enforced retest gate meant no finding was marked done until testers re-attacked and confirmed the fix held.
One governed record. The full engagement — scope, findings, comments, retests, report — lives in one TriNetra PTaaS engagement record with an append-only history, ready for the next cycle instead of resetting to zero.
Ready when you are
Your platform has a chain like this. Find it first.
Tell SecurityBoat what you're protecting. We'll scope a PTaaS engagement on TriNetra — findings live as they're verified, retested until they're closed.
