Security · Hardening
Application security review
Ironvale Financial — 2025
Penetration testing, secure code review and remediation for a regulated customer portal.
- Result
- 31 findings closed, zero criticals remaining
- Timeline
- 7 weeks

The challenge
A financial services firm needed an independent security review of a customer portal before an audit, with no full-time security engineer in house.
What we did
- Ran an authenticated penetration test mapped to OWASP ASVS.
- Reviewed authentication, session handling, access control and data exposure in code.
- Fixed findings alongside the client's team rather than handing over a PDF.
- Added dependency scanning and security checks into CI.
The outcome
- 31 findings remediated, including two critical access-control gaps.
- Passed the external audit with no security exceptions.
- Ongoing automated scanning in the deployment pipeline.
Stack
- OWASP ASVS
- Burp Suite
- Node.js
- PostgreSQL
- WAF
Tell us about your project
Free consultation, no obligations. Send the details or schedule a call for the fastest reply.