ShieldOps
A comprehensive web application penetration test and infrastructure audit for a growing SaaS platform. We identified and helped remediate critical and medium-severity security findings across their application and cloud infrastructure.

Client
Private Company
Timelines
1 Month
Our Role
Cybersecurity Audit · Web Penetration Testing · Remediation Guidance
The Challenge
What needed solving
The client was preparing for an investment round and SOC 2 Type II compliance audit. Operating a high-throughput SaaS platform, their engineering team shipped features rapidly but lacked formal penetration testing. They faced looming compliance deadlines and potential data privacy risks in their API gateway.
The Solution
How we built it
Klytech performed a thorough white-box penetration test and cloud infrastructure security audit across their Next.js web application, REST endpoints, and AWS cloud environment.
01 — Security Audit
Their Challenges
With rapid business growth and increasing platform usage, the platform faced significant operational security pressure. High-velocity feature releases had left legacy authentication tokens unrotated, and missing rate-limiting on sensitive API endpoints exposed user data to automated credential stuffing attempts.
Furthermore, their infrastructure lacked automated vulnerability scanning in the CI/CD deployment pipeline, making it difficult to detect misconfigurations before reaching production environments.
02 — Security Audit
Our Solutions
Decreased Risk Exposure: Our dedicated security engineering team conducted deep manual privilege escalation testing, GraphQL API fuzzing, and automated dependency audits to isolate attack surfaces efficiently.
API & Infrastructure Hardening: We collaborated directly with their core engineering team to implement JWT key rotation, rate-limiting middleware, and tenant isolation database policies.
DevSecOps Integration: We integrated automated static security analysis (SAST) and container vulnerability scanning directly into GitHub Actions, ensuring security checks execute automatically on every pull request.
Deliverables
Audit Findings & Security Outcomes
Identified and safely validated critical and medium-severity security findings
Remediated broken object-level authorization (BOLA) across core API endpoints
Implemented strict tenant data isolation rules preventing multi-tenant data leaks
Hardened AWS IAM policy configurations and automated container security scans
Delivered executive-ready SOC 2 compliance mapping and attestation report
Achieved complete remediation of critical findings within a rapid turnaround