ShadowSec Lab

B2B SaaS · Arbor

Cloud misconfiguration that exposed customer exports

Arbor asked for a cloud assessment ahead of an enterprise deal. A world-readable object store held CSV exports from a deprecated job. We showed the path from a leaked CI token to that bucket, then stayed for the fix review.

  • Public bucket closed the same afternoon
  • Workload identity replaced long-lived keys in CI
  • Customer security questionnaire updated with evidence
Start a similar engagement
Elena Voss, VP Engineering
They treated our staging environment like production. That is the only reason I trusted the report.

Elena Voss, VP Engineering

Next step

Tell us what you need answered.

A 30-minute scoping call is enough to know whether a pentest, a cloud review, or a retainer is the right buy. We will say if it is not.