Skip to content

Case Study / Continuous VAPT program

A three-year continuous testing partnership

A developer assessment and hiring platform used by enterprises worldwide holds two things attackers want: sensitive candidate data and proprietary assessment content. A clean annual pentest would say little about the eleven months that follow it, so the client committed to a continuous VAPT program instead: quarterly cycles, the same senior testers each time, now running for three years.

Developer assessment platform · US

What we found

Candidate-record exposure

A directory-level file listing made sensitive candidate information potentially reachable without authorization.

CSRF on critical transactions

Several transaction endpoints operated without anti-forgery safeguards, permitting state-changing requests a victim never intended.

Cross-site scripting (XSS)

User inputs allowed arbitrary markup on key application pages, an XSS-class flaw and the classic path to session and content compromise.

Missing rate controls

Core functionality lacked request-volume controls, exposing it to automated abuse and enumeration.

Privilege escalation

Session-token validation and role mappings were misaligned, producing inconsistent privileges an attacker could exploit.

How the engagement ran

Quarterly assessment cycles

Recurring testing synchronized with development milestones, so new features get assessed when they ship, not a year later.

Hybrid coverage

Automated scanning for breadth, targeted manual testing for depth, and realistic internal/external attack simulations.

Business-impact triage

Regular risk-triage reviews translate technical findings into business-impact scores the client prioritizes against.

Developer enablement

Threat-modeling and secure-coding sessions run alongside testing: the same testers, teaching from the same findings.

Technologies & methods

  • Web, network, cloud, and native-application surfaces
  • Automated scanning paired with targeted manual testing
  • Internal and external attack simulation
  • Business-impact risk triage
  • Threat-modeling and secure-coding sessions

What changed

  • A repeatable VAPT framework that scales with platform growth and each release.
  • Continuous visibility into emerging threats, shortening exposure windows.
  • Three years on: the same senior testers, deepening platform context, and findings trending down cycle over cycle.

Client identity is confidential by agreement. The engagement is published anonymized; we never publish metrics we didn't measure.

What this engagement taught us

Continuity compounds. Testers who carry years of platform context stop re-learning old ground and start anticipating where new features will break, something a point-in-time engagement can never buy. Findings trending down over that span is what the program was designed to produce.

Ready to scope the work?

A 30-minute call with the engineers who will do the testing, not a sales gate.