Secured Infinium LLP's 4ig.cloud for license approval with a full third-party VAPT
Perfect QA performed end-to-end security and penetration testing across Infinium LLP's web application and REST APIs, identifying vulnerabilities, guiding developer fixes, and delivering the third-party security certification required for their software license approval
18
Security Issues Detected
2
High-Risk Vulnerabilities Caught
3 Weeks
Assessment to Certificate
Industry
Security
Platform
Web
Desktop
Android
iOS
Windows
MacOS
Services
Security Testing, Penetration Testing (VAPT)
Share this
<Key Takeaways/>
Performed a full third-party VAPT covering the web application, REST API endpoints, authentication, and session management.
Identified 18 security findings across High, Medium, Low, and Informational severity, including 2 high-risk vulnerabilities.
Delivered a severity-graded report with clear remediation guidance the development team could act on directly..
Ran regression retesting after fixes to verify every issue was properly resolved.
Issued the third-party security certificate Infinium LLP needed for their software license approval.
A data governance platform that needed independent security validation
Infinium LLP's 4ig.cloud is an enterprise data governance platform built around a simple promise: know your data, govern your data in-place.
For a product that handles enterprise data, security is not optional, and when their software license approval required a certificate from an independent third-party QA consultancy, self-declared security wasn't enough. The application needed to be tested, fixed, retested, and formally certified by an external team, all within a fixed approval timeline.
Challenge
Infinium LLP needed independent proof that 4ig.cloud was secure, on a deadline. That came with specific challenges:
A third-party certificate was mandatory for the software license approval, and internal testing wouldn't qualify
The application had to be assessed in its real production environment, where testing carries real risk and demands careful handling
Both the web application and its REST APIs were in scope, including authentication flows, session management, and file handling
Findings needed to be fixed and re-verified within the approval timeline, not just documented
VAPT built for certification, not just a scan
Perfect QA ran a structured Vulnerability Assessment and Penetration Testing engagement aligned with OWASP Top 10 risk categories.
Automated scanning with OWASP ZAP covered the full web application and REST API surface: authentication and session management, input validation against injection attacks, HTTP security headers, Content Security Policy, server configuration, client-side JavaScript libraries, and transport security.
Manual testing then probed the areas automation can't judge: business logic, access control, and exploitability of flagged issues. Every finding was documented with severity, impact, and step-by-step remediation guidance for Infinium's developers.
Solution
Scanned the complete web application and REST API endpoints for OWASP Top 10 risk categories
Tested authentication, session management, and access control flows end to end
Validated input handling against injection attacks, and reviewed file download/upload behavior
Audited HTTP security headers, CSP, cookie configuration, and transport security
Flagged outdated client-side JavaScript libraries with known vulnerabilities
Delivered a severity-graded report (High / Medium / Low / Informational) with developer-ready fix guidance, followed by regression retesting of every resolved issue
We needed a third-party security certificate for our license approval and Perfect QA made the whole process straightforward. They tested everything, told our developers exactly what to fix and how, verified the fixes, and gave us the certificate on time. The report was clear enough that we didn't need a security expert to understand it.
Nitesh Gajjar
Infinium LLP
Certified, secured, and approved
The assessment surfaced 18 security findings on the 4ig.cloud application: 2 high-risk vulnerabilities, including a path traversal issue in a file-handling API and a vulnerable JavaScript library, alongside 7 medium-severity misconfigurations in areas like Content Security Policy, cross-domain settings, and clickjacking protection, plus lower-severity information disclosure and header hardening items.
Infinium's team resolved the issues using the report's fix guidance. PerfectQA re-verified each one through regression testing and issued the third-party security certificate. Infinium LLP received their software license approval, and the engagement has since brought new security testing clients to PerfectQA through direct referrals.
Result
Identified 18 security findings, including 2 high-risk vulnerabilities caught before they could be exploited
Every high and medium issue fixed and re-verified through a full regression retest cycle
Third-party security certificate issued and accepted for Infinium LLP's software license approval
Hardened security posture across APIs, headers, session handling, and client-side dependencies
Tools used in this project
The stack behind the results in this success story

OWASM ZAP
Security Testing
Designed to Deliver, no matter the constraints
While the outcome here was achieved in a specific context, the approach is designed to adapt to varying architectures, team structures, and release cycles
What will your story be?
Let’s build your QA strategy with the same precision, speed, and flexibility our clients rely on
Published
Updated