FinTech API Platform
Challenge
A multi-tenant payment workflow needed validation beyond automated API scanning.
Approach
Tested BOLA/IDOR, JWT boundaries, OAuth assumptions, webhook integrity, IAM exposure, and cloud storage paths together.
Outcome
Found an auth bypass chain that could expose sensitive customer records and converted it into developer-ready remediation steps.