Case study · SaaS
SaaS platform: VAPT plus DevSecOps rollout
A growing B2B SaaS business needed to close enterprise deals but kept stalling on customer security questionnaires. They engaged FrameYourWeb for a full assessment of their web application, public API, and cloud account — followed by DevSecOps implementation so findings would not regress.
Representative engagement · details anonymized under NDA
Project overview
- Client
- B2B SaaS company (name withheld under NDA)
- Industry
- SaaS
- Services
- VAPT & Penetration Testing, API Security Testing, DevSecOps
The problem
Enterprise prospects required evidence of penetration testing and a vulnerability management process. The team shipped weekly but had no security gates, no API authorization review, and an AWS account that had grown organically since the MVP days.
Requirements
- Assess the web application, REST API, and AWS account against OWASP standards
- Produce an auditor-ready report with CVSS ratings and remediation guidance
- Retest critical findings after fixes
- Leave behind CI/CD gates the team could operate independently
Key challenges
- Multi-role SaaS with complex object-level authorization rules
- Weekly release cadence — gates could not slow shipping
- Legacy scan backlog with hundreds of unactioned low-severity items
Our solution
- Scoped the assessment around crown-jewel flows: signup, billing, team invites, and API key management
- Combined automated DAST/SAST baselines with manual business-logic and BOLA testing
- Pair-remediated critical findings with the client's engineers, then retested with evidence
- Implemented PR-level SAST/SCA gates plus nightly DAST, tuned to fail only on new critical issues
Technology stack
Security implementation
- OWASP Top 10 and API Top 10 coverage with manual exploitation
- JWT and session handling review, rate-limit verification
- AWS IAM least-privilege redesign with staged rollout
- Secrets rotation and leaked-credential response runbook
Performance considerations
Security gates were budgeted inside existing CI minutes; DAST runs nightly against staging so developer pipelines stayed fast.
Results
- All critical and high findings remediated and verified in retest
- Customer security questionnaires answered with report + gate evidence
- Zero gate-bypass incidents in the quarter following rollout
- Internal security-champion ritual adopted by the engineering team
Lessons learned
- Scope around business-critical flows first; breadth follows in later cycles
- Gates that fail only on new issues get kept; noisy gates get disabled
- Pairing on remediation transfers more knowledge than any report
Keep exploring
Related services
Have a similar challenge?
Tell our Gurgaon team about your project — reply within one business day.
Start the conversation