UM-SA-001 · Revision 4.0How Fernleaf keeps each customer’s data apart
We tested Fernleaf Billing from the inside: signed in as different customers, and reading the design and the cloud setup. This page goes to Fernleaf’s customers after our retest: what we found, and what’s now fixed and checked.
Who it’s for
What we checked
Whether one customer can reach another’s invoices, exports or documents, through the screens, the API and the AI search. Who can put code and permissions into production.
What we found
- Three routes to another customer’s data: the invoice link, the export and the AI search.
- Production accepted code and roles without the sign-off Fernleaf believed was in place.
- Ten findings in all, plus four gaps in the basics. All were found in Fernleaf’s test environment.
In place now
- All three routes are closed. In our retest, no customer could reach another’s data.
- Only the protected release workflow reaches production, with the images that were signed off.
- MFA on every staff account, and single sign-on for the core apps.
Planned
- Web firewall: traffic filtered before it reaches the app2 to 3 weeks
Evidence
Every answer on this page points at an item in the evidence index on page 25: exports, policy files, restore logs.
Questions
Want the detail behind a line? Ask Fernleaf for the finding pages, and we’ll walk you through them.
Fictional sample. The company, systems and data are invented; no real client was assessed.