New

Free VAPT consultation for new enterprise clients — Book your security assessment

Case study · SaaS

SaaS platform: VAPT plus DevSecOps rollout

A growing B2B SaaS business needed to close enterprise deals but kept stalling on customer security questionnaires. They engaged FrameYourWeb for a full assessment of their web application, public API, and cloud account — followed by DevSecOps implementation so findings would not regress.

Representative engagement · details anonymized under NDA

Project overview

Client
B2B SaaS company (name withheld under NDA)
Industry
SaaS
Services
VAPT & Penetration Testing, API Security Testing, DevSecOps

The problem

Enterprise prospects required evidence of penetration testing and a vulnerability management process. The team shipped weekly but had no security gates, no API authorization review, and an AWS account that had grown organically since the MVP days.

Requirements

  • Assess the web application, REST API, and AWS account against OWASP standards
  • Produce an auditor-ready report with CVSS ratings and remediation guidance
  • Retest critical findings after fixes
  • Leave behind CI/CD gates the team could operate independently

Key challenges

  • Multi-role SaaS with complex object-level authorization rules
  • Weekly release cadence — gates could not slow shipping
  • Legacy scan backlog with hundreds of unactioned low-severity items

Our solution

  • Scoped the assessment around crown-jewel flows: signup, billing, team invites, and API key management
  • Combined automated DAST/SAST baselines with manual business-logic and BOLA testing
  • Pair-remediated critical findings with the client's engineers, then retested with evidence
  • Implemented PR-level SAST/SCA gates plus nightly DAST, tuned to fail only on new critical issues

Technology stack

Next.jsNode.jsPostgreSQLAWSGitHub ActionsSemgrepOWASP ZAP

Security implementation

  • OWASP Top 10 and API Top 10 coverage with manual exploitation
  • JWT and session handling review, rate-limit verification
  • AWS IAM least-privilege redesign with staged rollout
  • Secrets rotation and leaked-credential response runbook

Performance considerations

Security gates were budgeted inside existing CI minutes; DAST runs nightly against staging so developer pipelines stayed fast.

Results

  • All critical and high findings remediated and verified in retest
  • Customer security questionnaires answered with report + gate evidence
  • Zero gate-bypass incidents in the quarter following rollout
  • Internal security-champion ritual adopted by the engineering team

Lessons learned

  • Scope around business-critical flows first; breadth follows in later cycles
  • Gates that fail only on new issues get kept; noisy gates get disabled
  • Pairing on remediation transfers more knowledge than any report

Have a similar challenge?

Tell our Gurgaon team about your project — reply within one business day.

Start the conversation