Skip to content

Scale the product. We’ll check it’s safe to build on.

A fixed-fee assessment of the design, code and cloud, then the fixes that follow, ready for whoever’s checking it.

Free 30-minute scoping call. Fixed fee for the agreed scope, quoted before work starts.

Unmesha security assessmentsUM-SA-001 · Revision 4.0

One customer can read another customer’s invoices

In this fictional product, a signed-in customer could read another customer’s invoices by changing a number in an invoice link. The data export and the AI search had the same gap. Separately, code and permissions could reach production without the sign-off the team believed was in place.

10Findings

7High

3Medium

Issued before any fixes. One round of retesting is included.

Do first

  1. Make every invoice, export and search request check which customer is asking. (ARC-01, APP-01, AI-01)
  2. Let only the protected release workflow, its own roles and the images it built reach production. (CLD-01 to CLD-03)
  3. Keep the assistant’s send action off until a person signs off each send. (AI-02)

For your engineers

AreaHighMediumMain change
SaaS architecture11Tie each export job to the account that asked for it, and keep webhooks to public addresses.
Application and API21Check the account, the user’s role and current membership on every request.
Cloud and CI/CD21Limit production to the protected workflow, the runtime roles it needs and the images it built.
AI and agents20Filter search by account, and require a person’s sign-off before any external action.

What happens next

  • We build four control packs: identity, cloud monitoring, backups and edge.
  • Your developers make the code changes, from our pattern.
  • We retest every fix and every pack. One round is included.

Fictional sample. The company, systems and data are invented; no real client was assessed.

Unmesha TechnologiesSecurity assessment reportFernleaf Billing Ltd3 / 26

From our fictional sample report: the summary, the findings and the plan.

  • A fixed feeQuoted after the call, before any work starts.

  • One retest includedWe check your fixes once they’re in.

  • Design, code and cloudRead as one system, part by part.

  • A reply in one working dayThen a free 30-minute scoping call.

What do you want to get done?

A customer, an auditor, an insurer, a pentester, or your own AI feature will check your security on the way. Pick yours to see what we hand them.

Is the product’s design safe to keep building on?

A fixed-fee assessment reads the design, code and cloud. Findings go to your developers with our pattern, and we retest.

Security assessment, part by partQuoted on the call

See what we assess

Two stages, one fixed fee each

A customer, an auditor or an insurer wants to see your security before they say yes. We start with a short fixed-fee assessment: their questions answered, with evidence. Then we build only the controls they asked for, as fixed-price packs.

  1. We agree what to look at

    On a free scoping call we work out who’s asking, what they asked for and when they need it. We confirm the fee before any work begins.

  2. We check your systems

    We read the settings, the design and the code with your team. Where you’ve agreed it, we test hands-on with the access you set up.

  3. You get the answers and a plan

    The form or report answered with evidence, the gaps in the order to close them, and a one-page summary you can forward.

  4. We close the gaps

    Infrastructure fixes as fixed-price packs. Code changes go to your developers with our pattern. We check every fix.

What it costs

The assessment
from €3,600

Fixed, and confirmed on the scoping call before any work begins.

A control pack
from €700

Priced after the assessment. You only buy the packs the person asking needs.

Retesting
One round included

After your fixes. Further retests are quoted separately.

What isn’t included
  • Changes to your application code. Your developers make them from our pattern, and we retest.
  • The certification, audit or test itself, and its fees: SOC 2, ISO 27001, the pentest, the insurer's own checks.
  • Licences, such as Entra ID P1, endpoint protection or device management seats, and insurer or broker fees.
  • Incident response.

Every gap comes with its evidence and what fixed looks like

Here’s one, as our fictional sample report writes it up. The one-page summary you forward is built from findings like this.

Finding CLD-02High

The release pipeline can run code under an admin role it was never meant to use.

In the report: deployment permissions can pass an unintended admin role.

What could happen

Anyone who controls the release pipeline could run code with permissions well beyond deployment, including access to data exports.

What fixed looks like

  • The deployment can pass only the approved runtime roles, and only to the service it deploys to.
Unmesha security assessmentsUM-SA-001 · Revision 4.0

CLD-02Cloud and CI/CD

Deployment permissions can pass an unintended admin role

The release pipeline can run code under an admin role it was never meant to use.

Severity
High
Risk
3 × 5 = 15
Status
Open
Proposed owner
Cloud security and platform engineering
Affected
Permissions of the deployment role

What we found

The deployment role may pass any role to the functions it creates and runs. That covers app-runtime, the role it’s meant to pass, and also ops-export-admin, which can export customer data. If ops-export-admin trusts the function service and no other policy blocks it, the pipeline can run code with that role’s authority.

Why it matters

Anyone who controls the release pipeline could run code with permissions well beyond deployment, including access to data exports.

Likelihood 3: it needs the deployment identity and several other conditions to hold. Impact 5: the role it could hand over can export customer data. If another policy layer blocks the path, the rating drops.

Evidence

Figure 9. The deployment role’s permissions. The pass-role statement names no role, so any role in the account can be handed to a function, ops-export-admin included.

deploy-role-permissions.json, excerpt
{
  "Sid": "DeployFunctions",
  "Effect": "Allow",
  "Action": ["lambda:CreateFunction", "lambda:UpdateFunctionCode"],
  "Resource": "arn:aws:lambda:eu-west-1:111122223333:function:billing-*"
},
{
  "Sid": "PassRuntimeRole",
  "Effect": "Allow",
  "Action": "iam:PassRole",
  "Resource": "*"
}

What fixed looks like

  • The deployment can pass only the approved runtime roles, and only to the service it deploys to.
  • An attempt to pass ops-export-admin is refused.

Limit of the test

The permission statements only. Organisation policies, permission boundaries and the trust policy of ops-export-admin weren’t evaluated, and no function was created.

References: R6, listed on page 25.

Unmesha TechnologiesSecurity assessment reportFernleaf Billing Ltd16 / 26
Finding CLD-02, as the report sets it

Who does the work

Security architects and engineers who’ve answered these forms from the vendor’s side and the reviewer’s. You’ll meet us on the scoping call.

About the team
  • 15 yearsin the industry for our most senior consultant, across fintech, banking and healthcare.
  • CISSP and ISO 27001 Lead Auditorcertifications held between us.
  • AWS, Azure and Google Cloudworked in hands-on, from accounts and identity to logging and response.

Tell us what you’re trying to get done

On a free 30-minute scoping call we’ll say what we can answer from day one, what needs fixing, and what it costs.

Request a scoping call
  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.
Not ready to talk? Try the three-minute mini assessment

Or write to contact@unmesha.io.