Security · Hardening

Application security review

Ironvale Financial — 2025

Penetration testing, secure code review and remediation for a regulated customer portal.

Result
31 findings closed, zero criticals remaining
Timeline
7 weeks
Application security review interface for Ironvale Financial — 2025

The challenge

A financial services firm needed an independent security review of a customer portal before an audit, with no full-time security engineer in house.

What we did

  • Ran an authenticated penetration test mapped to OWASP ASVS.
  • Reviewed authentication, session handling, access control and data exposure in code.
  • Fixed findings alongside the client's team rather than handing over a PDF.
  • Added dependency scanning and security checks into CI.

The outcome

  • 31 findings remediated, including two critical access-control gaps.
  • Passed the external audit with no security exceptions.
  • Ongoing automated scanning in the deployment pipeline.

Stack

  • OWASP ASVS
  • Burp Suite
  • Node.js
  • PostgreSQL
  • WAF

Tell us about your project

Free consultation, no obligations. Send the details or schedule a call for the fastest reply.