A tenant isolation flaw found in six hours, and SOC 2 in eleven weeks
Sift needed SOC 2 readiness to close an enterprise contract. The first day of testing found something considerably more urgent.
- Industry
- Health Tech
- Year
- 2025
- Duration
- 11 weeks
Client
Sift Health
- To first critical finding
- 6 hrsTo first critical finding
- Critical flaw patched and verified
- 24 hrsCritical flaw patched and verified
- Findings closed and re-tested
- 31Findings closed and re-tested
- To audit-ready SOC 2 posture
- 11 wksTo audit-ready SOC 2 posture
Where they were starting from.
Sift handles protected health information for 40 clinics and had never been independently tested. An enterprise prospect made SOC 2 Type II a condition of contract, with a hard deadline. The engineering team suspected their permission model had gaps but had no way to characterise the risk.
Four decisions that shaped the outcome.
- 01
Authorise properly, then test hard
Signed rules of engagement, a production mirror, and a live channel with Sift's team. Testing started against a full-fidelity staging environment.
- 02
Report critical findings immediately
Six hours in, we found an object-reference flaw allowing cross-tenant record access. Reported that afternoon, patched the same day, re-tested the next morning.
- 03
Close the class, not the instance
Rather than patching one endpoint, we helped Sift add a tenant-scoping layer at the data-access boundary so the whole category of bug becomes structurally impossible.
- 04
Build the evidence trail
Control implementation, policy drafting and evidence collection mapped to the Trust Services Criteria, ready for an independent auditor.
Sift passed its independent SOC 2 Type II audit on the first attempt and closed the enterprise contract the following month. The tenant-scoping layer has since blocked two would-be regressions in code review.
Built with
- Burp Suite
- Semgrep
- Snyk
- Terraform
- Vault
- AWS Security Hub
They found a broken access control in our API that let one tenant read another tenant's records. Reported within six hours of starting, patched the same day. That single finding justified the entire engagement.
Cyber Security
Authorised penetration testing, secure architecture review and compliance readiness — delivered as fixes, not just findings.
Tell us where it hurts.
If any of this sounded familiar, the call is free and the advice is honest — even when the honest advice is that you do not need us.
Typical reply time: under 4 business hours