SecSmithOps

Portfolio

How we approach an engagement

SecSmithOps is a new company — these are illustrative engagement patterns based on how we work, not a list of past clients. Real, anonymized case studies will replace these as engagements ship.

FintechExternal VAPTIllustrative example

Closing an account-takeover path before launch

A Series B fintech needed its customer portal tested before a public launch. We found a chained authentication flaw that led to full account takeover.

Challenge

The client's engineering team had run automated scans with no critical findings and needed confidence before opening the platform to real customer funds.

Approach

Manual testing of the authentication and session-management flow uncovered a JWT validation flaw that, combined with a predictable password-reset token, allowed full account takeover with no user interaction.

Outcome

The finding was validated with a working proof-of-concept, triaged same-day, and fixed within 48 hours. A free retest confirmed the path was closed before launch.

1

Critical findings

6h

Time to first proof

48h

Fix-to-retest window

Public sectorCloud configuration reviewIllustrative example

Hardening a national agency's cloud tenant

A government agency migrating sensitive records to the cloud needed its Azure and Microsoft 365 tenant reviewed against CIS benchmarks.

Challenge

Multiple teams had provisioned resources independently, leaving inconsistent access controls and no clear picture of tenant-wide exposure.

Approach

We mapped every identity and privilege path across the tenant, identifying several over-permissioned service accounts that created a route to sensitive data stores.

Outcome

Findings were prioritized against CIS Microsoft 365 and Azure benchmarks, giving the agency's IT team a concrete remediation checklist ahead of their compliance review.

3

Privilege escalation paths found

CIS / NIST

Benchmark

2 weeks

Engagement length

SaaSSecure code reviewIllustrative example

Catching a logic flaw automated tools missed

A B2B SaaS platform wanted a manual review of its billing and permissions logic ahead of a SOC 2 audit.

Challenge

Automated SAST tooling was already integrated into CI, but the client's security lead wanted manual eyes on business logic that scanners can't reason about.

Approach

Manual review of the authorization layer found a multi-tenant isolation flaw where a crafted request could read billing data belonging to a different organization.

Outcome

The isolation flaw was fixed before the SOC 2 audit window, and the review gave the engineering team a documented set of secure-coding guidelines for the authorization layer going forward.

1

High-severity logic flaws

12k+

Lines of critical code reviewed

5 days

Time to findings report

Real engagement case studies coming soon. As we complete work with clients — with their permission — we'll publish anonymized write-ups here.

Want to be one of our first published case studies?

We're taking on early engagements now. Let's talk about your environment.

Start a conversation