What a report from us looks like
Our report on Fernleaf Billing, a made-up online billing service. It has ten findings, each with why it matters and what fixed looks like.
Download the PDFFictional sample: an invented company, test systems and made-up data. No real client was assessed. PDF, 24 pages, 1.5 MB.
The findings at a glance
7 high and 3 medium, found before any fixes.
7 high3 medium
- Biggest risk
- A signed-in customer could read another customer’s invoices by changing a number in the link. The data export and the AI search had the same gap.
- Do first
- Make every invoice, export and search request check which customer is asking.


The findings, part by part
Each finding sits in one part of the product, lit on the diagram. Open one to see why it matters and what fixed looks like.
Every part
How the product is designed, from one end to the other.
2 findings, filed under SaaS architecture
ARC-01High
A customer can download another customer’s invoices through the export feature.
Why it matters
One request can hand a customer another customer’s billing records. An export holds many invoices at once, so this route leaks more than a single page view, even though the normal screens filter correctly.
What fixed looks like
- A customer’s export contains only that customer’s records.
- A request for another customer’s export is refused before any job is created.
- Someone removed from an account can no longer download exports they started earlier.
Owner: Platform engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
ARC-02Medium
A customer can set a webhook that calls services inside Fernleaf’s own network.
Why it matters
If the server that sends webhooks can reach internal services, a customer could make it send requests to systems they cannot reach themselves. How serious that is depends on which internal services answer.
What fixed looks like
- Webhooks to customers’ own public addresses keep working.
- Internal, loopback and link-local addresses are refused before any connection is made.
- A redirect or a DNS change cannot move an approved webhook onto an internal address.
- The network blocks those addresses even if the application check is skipped.
Owner: Platform and network engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
Web app and API
What a signed-in customer can see and do.
3 findings, filed under Application & API
APP-01High
Changing one number in an invoice link shows another customer’s invoice.
Why it matters
Any signed-in customer who changes the number in an invoice link can read another customer’s invoice, including the customer’s billing email and the amount owed.
What fixed looks like
- A member can open their own account’s invoices and no one else’s.
- A request for another customer’s invoice returns no invoice data, from the API or from a cache.
- Unknown and foreign invoice numbers get the same response.
Owner: Application engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
APP-02High
A user with read-only access can give someone full control of the customer account.
Why it matters
Anyone with read-only access can give full control of the account to a second address of their own or to someone outside the business. A Billing admin can change payment details and download every invoice.
What fixed looks like
- Only Billing admins can invite users, through the screens and through the API.
- A refused invitation creates no user and sends no email.
- Every invitation records who sent it and the role it grants.
Owner: Application and identity engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
APP-03Medium
A person removed from a customer account can still see its data while they stay signed in.
Why it matters
When a customer removes someone, for example a person who has left the business, that person can keep reading the account’s billing information until their session ends.
What fixed looks like
- The first request after someone is removed is refused.
- Removal takes effect on every server and every cache.
- People who were not removed keep their access.
Owner: Identity and application engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
Pipeline and cloud account
Which code reaches production, and which cloud roles it can use.
3 findings, filed under Cloud & CI/CD
CLD-01High
A test branch can get the same production access as an approved release.
Why it matters
Code from a branch that has not been through release approval could obtain production deployment permissions, unless another cloud control blocks it.
What fixed looks like
- Only the protected production environment can assume the production role.
- Feature branches, pull requests and other environments are refused.
- Each production deployment records which workflow ran it.
Owner: Cloud platform and release engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
CLD-02High
The release pipeline can run code under an admin role it was never meant to use.
Why it matters
Anyone who controls the release pipeline could run code with permissions well beyond deployment, including access to data exports.
What fixed looks like
- The deployment can pass only the approved runtime roles, and only to the service it deploys to.
- An attempt to pass ops-export-admin is refused.
Owner: Cloud security and platform engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
CLD-03Medium
The release you approve isn’t guaranteed to be the one that goes live.
Why it matters
The software running in production can differ from what was reviewed. An accidental retag or a compromised publishing account could get past the approval step.
What fixed looks like
- Production runs the exact image that was approved.
- Moving a tag after approval does not change what is deployed.
- An image from an untrusted build is refused at release.
- Rollback goes to an earlier approved image.
Owner: Release engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
AI features
What the AI features can read and do.
2 findings, filed under AI & agent security
AI-01High
The AI search can show one customer’s documents to another customer.
Why it matters
Another customer’s content can reach the assistant’s answer, its citations or any tool it calls.
What fixed looks like
- Two customers asking the same question each see only their own documents.
- Citations, caches and batch jobs follow the same rule.
- Documents a user loses access to stop appearing in their results.
Owner: AI platform and application engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
AI-02High
The AI assistant can email a report outside the company without anyone approving it.
Why it matters
A document from outside the business, or a mistaken instruction, can make the assistant send account data to an outside address with no person involved.
What fixed looks like
- No report is queued or sent without a person’s approval for that recipient and that report.
- Changing the recipient or the report cancels the approval.
- An approval cannot be used twice.
Owner: Agent platform and product engineering
In a client report this part also gives your engineers the steps to reproduce it, the evidence and the fix.
Inside the PDF
Twenty-four pages, set out the way your report would be.

Executive summary
Page 3What matters most and what to fix first, for the people who decide.

Findings
Page 11Each issue with its evidence, the systems it affects and why we rated it as we did.

Prioritised fixes
Page 21The changes to make, most urgent first, each with a way to check it worked.

Closure checklist
Page 22What has to be true before you mark each finding as closed.
Want a report like this on your platform?
Tell us about your platform on a free 30-minute scoping call. Leave passwords and customer data out of your first message.
