How we work

Services

Industries

Success Stories

Blog

How we work

Services

Industries

Success Stories

Blog

Secured Infinium LLP's 4ig.cloud for license approval with a full third-party VAPT

Perfect QA performed end-to-end security and penetration testing across Infinium LLP's web application and REST APIs, identifying vulnerabilities, guiding developer fixes, and delivering the third-party security certification required for their software license approval

18

Security Issues Detected

2

High-Risk Vulnerabilities Caught

3 Weeks

Assessment to Certificate

Industry

Security

Platform

Web

Desktop

Android

iOS

Windows

MacOS

Tools

Services

Security Testing, Penetration Testing (VAPT)

Share this

<Key Takeaways/>

  • Performed a full third-party VAPT covering the web application, REST API endpoints, authentication, and session management.

  • Identified 18 security findings across High, Medium, Low, and Informational severity, including 2 high-risk vulnerabilities.

  • Delivered a severity-graded report with clear remediation guidance the development team could act on directly..

  • Ran regression retesting after fixes to verify every issue was properly resolved.

  • Issued the third-party security certificate Infinium LLP needed for their software license approval.

A data governance platform that needed independent security validation

Infinium LLP's 4ig.cloud is an enterprise data governance platform built around a simple promise: know your data, govern your data in-place.

For a product that handles enterprise data, security is not optional, and when their software license approval required a certificate from an independent third-party QA consultancy, self-declared security wasn't enough. The application needed to be tested, fixed, retested, and formally certified by an external team, all within a fixed approval timeline.

Challenge

Infinium LLP needed independent proof that 4ig.cloud was secure, on a deadline. That came with specific challenges:

  • A third-party certificate was mandatory for the software license approval, and internal testing wouldn't qualify

  • The application had to be assessed in its real production environment, where testing carries real risk and demands careful handling

  • Both the web application and its REST APIs were in scope, including authentication flows, session management, and file handling

  • Findings needed to be fixed and re-verified within the approval timeline, not just documented

VAPT built for certification, not just a scan

Perfect QA ran a structured Vulnerability Assessment and Penetration Testing engagement aligned with OWASP Top 10 risk categories.

Automated scanning with OWASP ZAP covered the full web application and REST API surface: authentication and session management, input validation against injection attacks, HTTP security headers, Content Security Policy, server configuration, client-side JavaScript libraries, and transport security.

Manual testing then probed the areas automation can't judge: business logic, access control, and exploitability of flagged issues. Every finding was documented with severity, impact, and step-by-step remediation guidance for Infinium's developers.

Solution

  • Scanned the complete web application and REST API endpoints for OWASP Top 10 risk categories

  • Tested authentication, session management, and access control flows end to end

  • Validated input handling against injection attacks, and reviewed file download/upload behavior

  • Audited HTTP security headers, CSP, cookie configuration, and transport security

  • Flagged outdated client-side JavaScript libraries with known vulnerabilities

  • Delivered a severity-graded report (High / Medium / Low / Informational) with developer-ready fix guidance, followed by regression retesting of every resolved issue

We needed a third-party security certificate for our license approval and Perfect QA made the whole process straightforward. They tested everything, told our developers exactly what to fix and how, verified the fixes, and gave us the certificate on time. The report was clear enough that we didn't need a security expert to understand it.

Nitesh Gajjar

Infinium LLP

Certified, secured, and approved

The assessment surfaced 18 security findings on the 4ig.cloud application: 2 high-risk vulnerabilities, including a path traversal issue in a file-handling API and a vulnerable JavaScript library, alongside 7 medium-severity misconfigurations in areas like Content Security Policy, cross-domain settings, and clickjacking protection, plus lower-severity information disclosure and header hardening items.

Infinium's team resolved the issues using the report's fix guidance. PerfectQA re-verified each one through regression testing and issued the third-party security certificate. Infinium LLP received their software license approval, and the engagement has since brought new security testing clients to PerfectQA through direct referrals.

Result

  • Identified 18 security findings, including 2 high-risk vulnerabilities caught before they could be exploited

  • Every high and medium issue fixed and re-verified through a full regression retest cycle

  • Third-party security certificate issued and accepted for Infinium LLP's software license approval

  • Hardened security posture across APIs, headers, session handling, and client-side dependencies

Tools used in this project

The stack behind the results in this success story

OWASM ZAP

Security Testing

Designed to Deliver, no matter the constraints

While the outcome here was achieved in a specific context, the approach is designed to adapt to varying architectures, team structures, and release cycles

What will your story be?

Let’s build your QA strategy with the same precision, speed, and flexibility our clients rely on

Published

Updated