Skip to content

Your customer’s security review, answered and the gaps closed

Your customer sent a questionnaire or a vendor-risk portal link. We answer it with evidence and close what’s missing, so the deal moves.

Free 30-minute call. The assessment from €4,500, fixed and confirmed before any work begins.

Unmesha security assessmentsUM-SA-001 · Revision 4.0

How Fernleaf keeps each customer’s data apart

We tested Fernleaf Billing from the inside: signed in as different customers, and reading the design and the cloud setup. This page says what we found and what Fernleaf is doing about it.

Who it’s for

Your customer’s security team

What we checked

Whether one customer can reach another’s invoices, exports or documents, through the screens, the API and the AI search. Who can put code and permissions into production.

What we found

  • Three routes to another customer’s data: the invoice link, the export and the AI search. All three are rated High.
  • Production accepted code and roles without the sign-off Fernleaf believed was in place.
  • Ten findings in all, seven High and three Medium. All were found in Fernleaf’s test environment.

In place now

  • Exports are switched off until the export fix is retested.
  • The assistant can’t send email until each send needs a person’s sign-off.
  • MFA on the cloud console and the code repository for everyone who can deploy.

Planned

  • Code fixes for all ten findings, by Fernleaf’s developers from our pattern4 to 6 weeks
  • Our retest of every fix, one round includedAfter the fixes
  • Identity: MFA everywhere and single sign-on3 to 4 weeks
  • Edge: a web application firewall in front of the app2 to 3 weeks

Evidence

Every answer on this page points at an item in the evidence index on page 24: exports, policy files, restore logs.

Questions

Want the detail behind a line? Ask Fernleaf for the finding pages, and we’ll walk you through them.

Fictional sample. The company, systems and data are invented; no real client was assessed.

Prepared by Unmesha Technologies for Fernleaf Billing Ltd
An example of the one-page summary you forward, from our fictional sample report.Read the whole sample report

When you need it

Usually one of these, often with a date attached.

  • A customer sends a security questionnaire or a vendor-risk portal link.
  • Procurement adds supplier clauses from DORA, NIS2 or similar.
  • An investor’s due diligence list includes security.
  • You’re about to sell to bigger companies and know the questionnaire is coming.

What you get, and what it costs

Step 1 is the assessment, at one fixed fee. Step 2 is only the fixes the person asking needs. Every fix, with prices.

Step 1: what the assessment includes

  • A gap check against what the customer actually asked.
  • The questionnaire answered, with evidence where it exists.
  • A remediation plan in priority order, with calendar time per item.
  • A one-page security summary you can forward.

Variants

  • Investor due diligenceThe same assessment, with a data-room summary in place of a questionnaire.
  • Regulated buyerDORA and NIS2 clause mapping for a customer in a regulated sector.

How it works

Three steps. You know the price before each one starts.

  1. A free call

    Tell us what you need and who’s asking. We’ll say what we’d check and give you a fixed price.

    30 minutesFree

  2. We check your product

    Your app, your cloud and how code gets to production. You get a report, a plan and a one-page summary to send to whoever’s asking.

    About two weeksfrom €4,500

  3. We fix what’s missing

    We set up what your product lacks, like MFA, alerts and tested backups. Your developers make any code changes, with our help. Then we retest, at no extra cost.

    Fixed price per fixfrom €1,400

Before you enquire

What people ask us most. Anything else, ask on the call.

Do you fill in the portal for us?

We draft every answer and gather the evidence. Then you paste them in, or we do it with you on a call. Some portals only accept the vendor’s own login.

What if the honest answer is no?

Then the answer says no, with the date it becomes yes from the plan. Most customers accept a dated plan. A yes that doesn’t hold up costs you the deal later.

What do you need from us?

The form, questionnaire or report, and a call with whoever runs your cloud and your workspace. For a fix, a named admin account for the systems it changes, set up the way we describe on the call.

How do you handle our admin access?

You create a named account for us with only the rights the fix needs, and you can see everything it does. We never use shared logins. Each fix lists its changes, when they happen and how to roll them back, and you remove the account when the fix is done.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Send us the questionnaire

Who sent it, when they need it back, and roughly how many questions. On the call we’ll say what we can answer from day one.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team

Request a free call

Send a short outline of what you want checked and any deadline.

Email Unmesha

Please leave out passwords and customer data. How we handle enquiry information.