Cyber Security

A tenant isolation flaw found in six hours, and SOC 2 in eleven weeks

Sift needed SOC 2 readiness to close an enterprise contract. The first day of testing found something considerably more urgent.

Industry
Health Tech
Year
2025
Duration
11 weeks

Client

Sift Health

To first critical finding
6 hrsTo first critical finding
Critical flaw patched and verified
24 hrsCritical flaw patched and verified
Findings closed and re-tested
31Findings closed and re-tested
To audit-ready SOC 2 posture
11 wksTo audit-ready SOC 2 posture
The challenge

Where they were starting from.

Sift handles protected health information for 40 clinics and had never been independently tested. An enterprise prospect made SOC 2 Type II a condition of contract, with a hard deadline. The engineering team suspected their permission model had gaps but had no way to characterise the risk.

Our approach

Four decisions that shaped the outcome.

  1. 01

    Authorise properly, then test hard

    Signed rules of engagement, a production mirror, and a live channel with Sift's team. Testing started against a full-fidelity staging environment.

  2. 02

    Report critical findings immediately

    Six hours in, we found an object-reference flaw allowing cross-tenant record access. Reported that afternoon, patched the same day, re-tested the next morning.

  3. 03

    Close the class, not the instance

    Rather than patching one endpoint, we helped Sift add a tenant-scoping layer at the data-access boundary so the whole category of bug becomes structurally impossible.

  4. 04

    Build the evidence trail

    Control implementation, policy drafting and evidence collection mapped to the Trust Services Criteria, ready for an independent auditor.

The outcome

Sift passed its independent SOC 2 Type II audit on the first attempt and closed the enterprise contract the following month. The tenant-scoping layer has since blocked two would-be regressions in code review.

Built with

  • Burp Suite
  • Semgrep
  • Snyk
  • Terraform
  • Vault
  • AWS Security Hub
They found a broken access control in our API that let one tenant read another tenant's records. Reported within six hours of starting, patched the same day. That single finding justified the entire engagement.
Critical flaw found & fixed in 24 hrs
Laura KensingtonCTO, Sift Health
The service behind it

Cyber Security

Authorised penetration testing, secure architecture review and compliance readiness — delivered as fixes, not just findings.

Explore Cyber Security
Similar problem?

Tell us where it hurts.

If any of this sounded familiar, the call is free and the advice is honest — even when the honest advice is that you do not need us.

Typical reply time: under 4 business hours