B2B SaaS · Arbor
Cloud misconfiguration that exposed customer exports
Arbor asked for a cloud assessment ahead of an enterprise deal. A world-readable object store held CSV exports from a deprecated job. We showed the path from a leaked CI token to that bucket, then stayed for the fix review.
- Public bucket closed the same afternoon
- Workload identity replaced long-lived keys in CI
- Customer security questionnaire updated with evidence

“They treated our staging environment like production. That is the only reason I trusted the report.”
Elena Voss, VP Engineering
Next step
Tell us what you need answered.
A 30-minute scoping call is enough to know whether a pentest, a cloud review, or a retainer is the right buy. We will say if it is not.
