Case study · Cybersecurity

A 1080° adversarial audit of our own software found 59 issues

Before advising anyone else on their security posture, we ran an adversarial audit against our own shipped software — and then fixed what it found, in tracked batches.

Work carried out on our own production systems. Published 2026-06-10.

Findings in one audit
59
IDORs closed in one push
6
Also fixed
MFA takeover, brute-force, DoS
Remediation batches shipped
4

The situation

What we did

Outcome

What it cost us to learn

Every one of those access-control findings was in software that worked correctly for every legitimate user, passed its tests, and shipped. Nothing errored. That is the shape of the failure worth planning for: not the bug that breaks the page, but the one that serves the wrong person’s data perfectly.

Want this done to your systems?

Start with cybersecurity, or just tell us what is worrying you.

Get a Quote