Skip to content

What a report from us looks like

Our report on Fernleaf Billing, a made-up online billing service. It has ten findings, each with why it matters and what fixed looks like.

Fictional sample: an invented company, test systems and made-up data. No real client was assessed. PDF, 26 pages, 1.0 MB.

The findings at a glance

7 high and 3 medium, found before any fixes.

7 high3 medium

Biggest risk
A signed-in customer could read another customer’s invoices by changing a number in the link. The data export and the AI search had the same gap.
Do first
Make every invoice, export and search request check which customer is asking.

Four pages from the report

Set out the way your report would be. The PDF has all 26, with the contents on page 2.

  1. Page 3 of 26

    Executive summary

    What matters most and what to fix first, for the people who decide.

    Unmesha security assessmentsUM-SA-001 · Revision 4.0

    One customer can read another customer’s invoices

    In this fictional product, a signed-in customer could read another customer’s invoices by changing a number in an invoice link. The data export and the AI search had the same gap. Separately, code and permissions could reach production without the sign-off the team believed was in place.

    10Findings

    7High

    3Medium

    Issued before any fixes. One round of retesting is included.

    Do first

    1. Make every invoice, export and search request check which customer is asking. (ARC-01, APP-01, AI-01)
    2. Let only the protected release workflow, its own roles and the images it built reach production. (CLD-01 to CLD-03)
    3. Keep the assistant’s send action off until a person signs off each send. (AI-02)

    For your engineers

    AreaHighMediumMain change
    SaaS architecture11Tie each export job to the account that asked for it, and keep webhooks to public addresses.
    Application and API21Check the account, the user’s role and current membership on every request.
    Cloud and CI/CD21Limit production to the protected workflow, the runtime roles it needs and the images it built.
    AI and agents20Filter search by account, and require a person’s sign-off before any external action.

    What happens next

    • We make four fixes at a fixed price: identity, cloud monitoring, backups and edge.
    • Your developers make the code changes, from our pattern.
    • We retest every fix, ours and your developers’. One round is included.

    Fictional sample. The company, systems and data are invented; no real client was assessed.

    Unmesha TechnologiesSecurity assessment reportFernleaf Billing Ltd3 / 26
  2. Page 11 of 26

    A finding

    What we found, why it matters, the evidence and what fixed looks like. This is APP-01, the biggest risk.

    Unmesha security assessmentsUM-SA-001 · Revision 4.0

    APP-01Application and API

    Invoice reads skip the account ownership check

    Changing one number in an invoice link shows another customer’s invoice.

    Severity
    High
    Risk
    4 × 4 = 16
    Status
    Open
    Proposed owner
    Application engineering
    Affected
    Invoice page and GET /api/invoices/{id}

    What we found

    Signed in as a Member of Alder Studio, we opened Alder Studio’s invoice 104 and changed the number in the address to 208. The page showed invoice 208, which is billed to Birch Dental, with its amount and line items. The API behind the page returned the same invoice with status 200. The session was valid, but nothing checked that the invoice belongs to Alder Studio.

    Why it matters

    Any signed-in customer who changes the number in an invoice link can read another customer’s invoice, including the customer’s billing email and the amount owed.

    Likelihood 4: an ordinary member changes one number in the link. Impact 4: another customer’s billing record comes back, and we treat invoices as confidential between customers.

    Evidence

    Figure 4. Invoice 208, billed to Birch Dental, open in Alder Studio’s account. The number in the address was changed from 104.

    Fictional Fernleaf Billing app signed in to Alder Studio’s account. The address bar shows /invoices/208, and the invoice on screen is billed to Birch Dental, a different customer. The invoice number in the address and the Billed to name are outlined.

    Reproduce and fix

    Page 12 has the steps to reproduce it, the fix, what fixed looks like and the limit of the test.

    Unmesha TechnologiesSecurity assessment reportFernleaf Billing Ltd11 / 26
  3. Page 21 of 26

    The plan

    The fixes we make at a fixed price, and the code changes your developers make from our pattern.

    Unmesha security assessmentsUM-SA-001 · Revision 4.0

    What we fix, and what your developers fix

    Two kinds of work close the gaps. We make four fixes at fixed prices. Your developers make the code changes, working from our pattern.

    The fixes we make

    FixWhat we set upCalendar time
    IdentityMFA covers only the people who deploy.MFA enforced everywhere, with break-glass accounts. Single sign-on for your core apps. Conditional access rolled out report-only first, then enforced.3 to 4 weeks
    Cloud monitoringCloud logs are kept, but nobody is alerted.CloudTrail, GuardDuty and Security Hub on AWS, Microsoft Defender on Azure, or Security Command Center on Google Cloud, with alerts routed to your team.1 to 2 weeks
    Backups and recoveryNightly backups have never been restored in a test.Backups configured with retention, and made immutable where your platform allows it. One restore test, documented.1 week
    EdgeNothing filters traffic in front of the app.A web application firewall in front of your app: count mode first, then tuning, then block.2 to 3 weeks

    The code changes your developers make

    Grouped by the boundary each one repairs. Fernleaf’s developers estimate 4 to 6 weeks for all five.

    Work packageFindingsWhat changesHow you know it worked
    Customer data isolationARC-01APP-01AI-01The account is taken from the signed-in session for every request, export job and search. No field the caller controls can widen what they see.Own-account and cross-account cases run through the screens, the API, exports and search, cached results included.
    Roles and membershipAPP-02APP-03AI-02Current role, current membership and a person’s verified sign-off are checked before any change or external action.Refused cases leave nothing behind. Removals and expired sign-offs take effect on the next request.
    Production identityCLD-01CLD-02Only the production workflow can assume the production role, and it can pass on only the runtime roles on its list.A matrix of allowed and refused subjects and roles, checked with every policy layer in place.
    Webhook destinationsARC-02An application rule for allowed destinations, backed by network egress controls.Internal, redirected and re-resolved addresses fail from the real delivery network.
    Release imagesCLD-03Sign-off and deployment both use the same verified image digest.The deployed digest matches the one signed off, and any other image is refused.

    Retest

    We check each fix. One round of retesting is included.

    Unmesha TechnologiesSecurity assessment reportFernleaf Billing Ltd21 / 26
  4. Page 22 of 26

    Closure checklist

    What has to be true before a finding closes, and the retest that’s included.

    Unmesha security assessmentsUM-SA-001 · Revision 4.0

    What we need to see before a finding closes

    StageRecordAccepted when
    TriageOwner, affected release, agreed severity and scope.The evidence supports the finding and its impact.
    FixChange reference, the design or policy change, and every entry point it covers.Each affected entry point has a named place where the check happens.
    VerificationRefused and permitted cases run against the fixed build.The refused action fails with no side effects, and normal use still works.
    RetestRequest and result record, environment and build reference.A reviewer can repeat the original case and see it refused.
    Residual riskAnything left untested, accepted limits and the decision record.Nothing unresolved is reported as fixed.

    Checks for every finding

    • Run the same account and role checks on direct API calls, background jobs, cached reads and assistant actions.
    • Change authority between a request and its execution, for example by removing a user, and confirm the change is honoured.
    • Confirm that refused requests leave no queued work, files, messages or data behind.
    • Where permissions are cached, repeat the checks on more than one server.

    Retest

    One round is included. Once your team has made the code changes, we retest them and check each of our fixes.

    Handover

    For each finding, supply the finding ID, the build or policy version, the results of the refused and permitted cases, log references and anything left untested. Keep credentials and confidential data out of tickets.

    Unmesha TechnologiesSecurity assessment reportFernleaf Billing Ltd22 / 26
Download all 26 pages

The findings, part by part

Each finding sits in one part of the product, lit on the diagram. Open one to see why it matters and what fixed looks like.

  • Every part

    How the product is designed, from one end to the other.

    2 findings, filed under SaaS architecture

    ARC-01High

    A customer can download another customer’s invoices through the export feature.

    ARC-02Medium

    A customer can set a webhook that calls services inside Fernleaf’s own network.

  • Web app and API

    What a signed-in customer can see and do.

    3 findings, filed under Application & API

    APP-01High

    Changing one number in an invoice link shows another customer’s invoice.

    APP-02High

    A user with read-only access can give someone full control of the customer account.

    APP-03Medium

    A person removed from a customer account can still see its data while they stay signed in.

  • Pipeline and cloud account

    Which code reaches production, and which cloud roles it can use.

    3 findings, filed under Cloud & CI/CD

    CLD-01High

    A test branch can get the same production access as an approved release.

    CLD-02High

    The release pipeline can run code under an admin role it was never meant to use.

    CLD-03Medium

    The release you approve isn’t guaranteed to be the one that goes live.

  • AI features

    What the AI features can read and do.

    2 findings, filed under AI & agent security

    AI-01High

    The AI search can show one customer’s documents to another customer.

    AI-02High

    The AI assistant can email a report outside the company without anyone approving it.

Want a report like this on your platform?

Tell us about your platform on a free 30-minute call. Leave passwords and customer data out of your first message.

Request a free call
  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.
Or see what a mini assessment report looks like