We went looking for
ways to steal from ourselves.
Six passes, each one written as an attacker rather than as a reviewer, and this page is what they found. Including the pass that discovered our own ledger could be credited by anyone willing to send one unauthenticated POST.
A security page that lists only successes is a marketing page. The useful version names the failures, because the thing you actually want to know about a payments company is not whether it has ever been wrong. It is what happens when it is.
6
adversarial passes
Each with a written brief and a record.
3
critical findings
All closed, all described below.
115
handlers traced
Every route, to the service behind it.
434
leaked credentials
In one local session, before the fix. Now zero.