Skip to content

What a report from us looks like

Our report on Fernleaf Billing, a made-up online billing service. It has ten findings, each with why it matters and what fixed looks like.

Download the PDF

Fictional sample: an invented company, test systems and made-up data. No real client was assessed. PDF, 24 pages, 1.5 MB.

The findings at a glance

7 high and 3 medium, found before any fixes.

7 high3 medium

Biggest risk
A signed-in customer could read another customer’s invoices by changing a number in the link. The data export and the AI search had the same gap.
Do first
Make every invoice, export and search request check which customer is asking.
Page 3 of the fictional sample report: the executive summary, with ten findings, seven high and three medium, and the order to fix them.
Page 3 of 24: the executive summary.
Fictional Fernleaf Billing app signed in to Alder Studio’s account. The address bar shows /invoices/208, and the invoice on screen is billed to Birch Dental, a different customer. The invoice number in the address and the Billed to name are outlined.
The proof for the biggest risk, APP-01. Invoice 208 belongs to Birch Dental, yet it opens in Alder Studio’s account once the number in the link is changed from 104.

The findings, part by part

Each finding sits in one part of the product, lit on the diagram. Open one to see why it matters and what fixed looks like.

  • Every part

    How the product is designed, from one end to the other.

    2 findings, filed under SaaS architecture

    ARC-01High

    A customer can download another customer’s invoices through the export feature.

    ARC-02Medium

    A customer can set a webhook that calls services inside Fernleaf’s own network.

  • Web app and API

    What a signed-in customer can see and do.

    3 findings, filed under Application & API

    APP-01High

    Changing one number in an invoice link shows another customer’s invoice.

    APP-02High

    A user with read-only access can give someone full control of the customer account.

    APP-03Medium

    A person removed from a customer account can still see its data while they stay signed in.

  • Pipeline and cloud account

    Which code reaches production, and which cloud roles it can use.

    3 findings, filed under Cloud & CI/CD

    CLD-01High

    A test branch can get the same production access as an approved release.

    CLD-02High

    The release pipeline can run code under an admin role it was never meant to use.

    CLD-03Medium

    The release you approve isn’t guaranteed to be the one that goes live.

  • AI features

    What the AI features can read and do.

    2 findings, filed under AI & agent security

    AI-01High

    The AI search can show one customer’s documents to another customer.

    AI-02High

    The AI assistant can email a report outside the company without anyone approving it.

Inside the PDF

Twenty-four pages, set out the way your report would be.

  • Executive summary page from the fictional sample report

    Executive summary

    Page 3

    What matters most and what to fix first, for the people who decide.

  • Findings page from the fictional sample report

    Findings

    Page 11

    Each issue with its evidence, the systems it affects and why we rated it as we did.

  • Prioritised fixes page from the fictional sample report

    Prioritised fixes

    Page 21

    The changes to make, most urgent first, each with a way to check it worked.

  • Closure checklist page from the fictional sample report

    Closure checklist

    Page 22

    What has to be true before you mark each finding as closed.

Download the PDF

Want a report like this on your platform?

Tell us about your platform on a free 30-minute scoping call. Leave passwords and customer data out of your first message.