UM-SA-001 · Revision 4.0How Fernleaf keeps each customer’s data apart
We tested Fernleaf Billing from the inside: signed in as different customers, and reading the design and the cloud setup. This page says what we found and what Fernleaf is doing about it.
Who it’s for
What we checked
Whether one customer can reach another’s invoices, exports or documents, through the screens, the API and the AI search. Who can put code and permissions into production.
What we found
- Three routes to another customer’s data: the invoice link, the export and the AI search. All three are rated High.
- Production accepted code and roles without the sign-off Fernleaf believed was in place.
- Ten findings in all, seven High and three Medium. All were found in Fernleaf’s test environment.
In place now
- Exports are switched off until the export fix is retested.
- The assistant can’t send email until each send needs a person’s sign-off.
- MFA on the cloud console and the code repository for everyone who can deploy.
Planned
- Code fixes for all ten findings, by Fernleaf’s developers from our pattern4 to 6 weeks
- Our retest of every fix, one round includedAfter the fixes
- Identity: MFA everywhere and single sign-on3 to 4 weeks
- Edge: a web application firewall in front of the app2 to 3 weeks
Evidence
Every answer on this page points at an item in the evidence index on page 24: exports, policy files, restore logs.
Questions
Want the detail behind a line? Ask Fernleaf for the finding pages, and we’ll walk you through them.
Fictional sample. The company, systems and data are invented; no real client was assessed.