← All case studies
B2B SaaSSample Customer (placeholder)EU

Sample Engagement (Placeholder)

A scaffolded case-study record used to wire up the layout. Replace with a real, customer-approved engagement.

Published: 2026-05-06 · 8 min

Published 60 days post-remediation, with the customer’s written consent for every detail used.

Customer profile

A Series B B2B SaaS company (~120 employees, EU-headquartered) that ships weekly to its customer-facing web application and three internal APIs. They run on a modern cloud-native stack with mature CI but had not yet run a deep, scoped offensive engagement on the public surface.

Scope and rules of engagement

DeepMantis ran a 14-day engagement against the customer-facing web application and three internal APIs. Production was in scope; destructive actions, data exfiltration beyond proof, and lateral movement outside the named hosts were explicitly out of scope.

  • Authenticated and unauthenticated paths
  • Tenant isolation under multi-tenant assumptions
  • Webhook surfaces and outbound integrations

Methodology

Recon mapped the public surface and identified high-value flows (authentication, billing export, webhook proxy). Discovery focused on tenant-isolation invariants and trust boundaries between user-controlled input and internal services. Exploitation produced reproducible chains with concrete proof artefacts; reporting framed each finding against the customer's threat model.

Highlighted findings

14 findings total; the two highest-impact ones are summarised below. The full report includes reproduction steps, business-impact analysis, and remediation guidance per finding.

Remediation and outcome

The customer remediated the critical SSRF the same day the proof-of-exploit landed and shipped fixes for both high-severity findings within 12 days. A retest verified every fix; the medium- and low-severity items were rolled into the next sprint.

Highlighted findings

Critical

Server-side request forgery in the webhook layer

A request-forwarding surface in the webhook flow could be coerced into reaching internal services. Reproducible end-to-end and remediated.

High

Cross-tenant access in an export flow

A tenant-isolation gap in an export endpoint let an authenticated tenant retrieve records belonging to another tenant. Remediated by tightening the authorization check.

DeepMantis showed us a working exploit chain in 48 hours. We patched the critical the same day.
Placeholder NameHead of Security, Sample Customer (placeholder)

Outcome

Critical and both high-severity findings remediated within 12 days; retest verified all fixes.

Want a report like this?

Start your pentest

Request a Pentest

Fill out the form and we'll get back to you within 24 hours.

Tell us about your project

Protected by Cloudflare Turnstile.

HQ
Hamburg, Germany
Prefer to talk first?
Book a 15-min call