Risk-Based, ISO/IEC 27001 and GDPR-Aligned Gray-Box Pentest for a SaaS Coaching Platform
Summary
INNERLUXES verified the security of the web and mobile apps and an API for a SaaS coaching and leadership platform. The testers simulated role-specific attack scenarios to verify the security controls that matter most to enterprise buyers.
About the Client
The Client is an enterprise SaaS product company specializing in corporate coaching and leadership development. It offers individual and group coaching through web and mobile apps, backed by a network of certified coaches, and serves global enterprise customers.
The Client invests heavily in ISO/IEC 27001 certification and GDPR compliance to maintain the privacy of its clients' data. As part of its security program, the company conducts regular third-party penetration testing of its continuously evolving digital coaching platform, and brought INNERLUXES in for gray-box pentesting.
Risk-Based Gray-Box Pentesting of a Digital Coaching Platform
INNERLUXES and the Client began the engagement by defining the testing goals, limits, and scope to ensure alignment with business priorities and protection of critical assets. The testing scope covered the following components of the digital coaching platform: iOS, Android, and web apps, as well as an API.
The Client selected the gray-box approach, which combines the speed of black-box testing with white-box depth where it matters most. The testing process followed the PTES, the OWASP Web Security Testing Guide, the OWASP Mobile Security Testing Guide, and the NIST 800-115 methodology. The team began by using open-source intelligence (OSINT) to map the attack surface, including domain names, subdomains, and publicly accessible assets. Based on the gathered data, the testers identified and prioritized potential entry points and the most relevant attack vectors.
During the active testing phase, the team used automated scans to catch known vulnerabilities quickly, then proceeded with manual testing to eliminate false positives and simulate real-world attacks, including exploitation scenarios.
Using pre-approved logins for the learner, HR specialist, and coach roles, INNERLUXES targeted the highest-impact risk areas. The focus areas included:
- Authorization and multi-tenant isolation — for example, verifying that permission checks reliably blocked learners or coaches from HR-only functions and from accessing other customers' environments.
- Session and tokens — verifying token expiration, rotation, and secure storage.
- Reporting and export safety — ensuring file exports were sanitized to prevent CSV injection.
- Mobile security — assessing local device data protection, root and jailbreak detection, and OS-version policy (no installs on deprecated Android/iOS versions) for the mobile apps.
INNERLUXES documented every confirmed vulnerability, detailing its potential business impact, reproducible evidence, and remediation steps. The team classified the issues according to the OWASP Top 10, the OWASP Mobile Top 10, and the OWASP API Top 10, and prioritized them by severity using NIST CVSS. The Client received a comprehensive report with both technical details and an executive summary, and for each item INNERLUXES recommended the responsible team (e.g., Development, DevOps, Security) to streamline ownership. After the Client's in-house IT teams applied the fixes, INNERLUXES verified the remediation through a retest.
Key Outcomes
- Testing efforts were guided by the Client's business priorities, resulting in a precise assessment focused on risks that could directly threaten the platform.
- The testing and reporting methodology, based on PTES, NIST SP 800-115, and OWASP, supports ISO/IEC 27001 and GDPR Article 32 expectations for regular, risk-based security testing and evidence, contributing to the Client's compliance program.
- Targeted automation, combined with manual verification, provided fast, reliable pentesting results free of false positives and backed by reproducible, real-world attack paths.
- Structured pentest documentation — with clear vulnerability impact and exploitation likelihood estimates, reproducible evidence, and a remediation plan with suggested ownership — helped the Client streamline issue resolution.
- The executive summary provided actionable insights for business stakeholders, helping them make quick, informed decisions on remediation efforts.
- INNERLUXES confirmed applied remediations with a post-fix retest, giving the Client confidence in the strengthened security posture.
Technologies and Tools
Acunetix, Burp Suite, Metasploit, Nmap, SQLMap, Nikto, Apktool, apksigner, jadx, STEWS, Zed Attack Proxy (ZAP), MobSF, Postman, Python, PHP, Bash, PowerShell.