Case Study

Fintech Platform: Closing an IDOR Chain Before It Reached Production

A Series B fintech client engaged Derivee for a pre-launch web application assessment on their new customer portal.

Manual testing of the session-handling logic surfaced a predictable token pattern that, chained with an authorization gap on an internal support endpoint, allowed escalation from a standard customer session to admin-level access in three requests.

The finding was reported same-day given its severity, fixed within 48 hours, and retested before the platform’s public launch — closing the gap before it ever reached production traffic.

← all case studies