en

Security Check of the Exchange Website

Client:
Maple Pay – a fintech company that provides online currency exchange services
Industry:
FinTech
Focus:
Security check of the website and obtaining a cybersecurity certificate
Main challenge:
Confirmation of the resource’s reliability and demonstration of compliance with basic security requirements for marketing purposes
Market:
Canada
Services provided:
Key Takeaways
  • Confirmed the basic level of the platform’s cyber resilience
  • The client received a penetration testing certificate
  • An automated black-box pentest of the website was conducted
  • 6 low-risk vulnerabilities were identified
  • A detailed report on the test results was prepared
  • 6
    vulnerabilities detected
    2
    weeks of testing duration
    6
    scanners used
    Security Check of the Exchange Website
    For financial services, user trust is crucial. To confirm the platform’s reliability and demonstrate transparency of processes, Maple Pay turned to Datami for a penetration test and certification. The cybersecurity assessment of the website revealed 6 low-level vulnerabilities and confirmed the overall security level of the platform.

    Maple Pay is a Canadian fintech company that provides solutions for digital payments and online currency exchange. The platform operates in accordance with FINTRAC requirements and international standards for the security of financial transactions.

    For companies in the financial sector, cybersecurity is the foundation of their reputation. Any vulnerability can put transactions, data, and customer trust at risk. Therefore, a security assessment of the web platform is an essential element of Maple Pay’s strategy.

    Tasks and challenges
    Maple Pay sought to confirm the reliability of its website and demonstrate compliance with core financial-sector security requirements, FINTRAC, and international standards and transparency.
     
    The company engaged Datami for an automated pentest and certification, to be completed within two weeks.
    • Conduct an automated black-box pentest of the company's website
    • Identify potential vulnerabilities and prepare a report with recommendations
    • Provide a certificate for the penetration test
    icon
    Verification of the web platform
    Test the security of the Maple Pay website using a black-box approach
    icon
    Vulnerability discovery
    Check for technical weaknesses and assess the level of risk to users
    icon
    Certification of results
    Prepare a report with recommendations and provide a penetration testing certificate
    Our approach

    Datami applied a Black-box approach to the pentest and performed extensive automated scanning of the web platform. For this, they used 6 tools: Nikto, Wapiti, OWASP ZAP, Nuclei, Nessus, and Burp Scanner.

    For initial reconnaissance, the OSINT methodology was chosen. The DDoS simulation was adapted to the WAF, and the attack simulation was fully controlled and agreed with the client - time windows, rollback, and monitoring were prearranged.

    Black-box
    Black-box
    Pentest strategy without access to source code for assessing surface attack vectors. It simulates the actions of external attackers.
    Key stages of work and solutions

    The Datami team followed a clear sequence to minimize risks for the platform. 

    They began with OSINT reconnaissance, followed by extensive automated scanning and a controlled DDoS simulation. 

    In the final stage, they performed a detailed analysis and prepared a comprehensive report with conclusions and recommendations.

    • OSINT reconnaissance
      Collected publicly available technical information about the target: domains, subdomains, technologies, and potential leaks.
    • Scanning and DDoS simulation
      Launched 6 scanners considering the active WAF and conducted a controlled load simulation with monitoring and rollback mechanisms.
    • Analysis and reporting
      Validated findings, classified risks, compiled a detailed report, and provided recommendations to improve cybersecurity.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations
    Results and recommendations

    As a result of the automated pentest of the Maple Pay web platform, the Datami team identified 6 low-level vulnerabilities. They did not pose a critical threat but could affect the platform’s stability and user experience.

    Following the assessment, the client received a detailed report outlining each vulnerability and its risk level.

    In cases where only non-critical threats are detected, Datami experts recommend:

    • updating CMS components and library versions;
    • strengthening WAF configurations to reduce potential load;
    • regularly scanning for common web vulnerabilities and performing retests after major site updates;
    • planning annual security assessments to maintain regulatory compliance.

    This approach helps maintain a proper level of cybersecurity and prepare for future audits.

    Our certificates
    Key project takeaways

    In the financial sector, user trust is just as important as technological stability. Maple Pay initiated a cybersecurity assessment not only to test the platform but also to demonstrate transparency and a responsible approach to data protection.

    This Datami case study confirmed that automated pentesting is an effective tool for showcasing service reliability. The company received a testing certificate, a clear understanding of its current security level, and a foundation for future audits.

    Direction
    Before the project
    After the pentest
    Risk level
    Unknown
    Low
    Vulnerabilities
    Not officially recorded
    6 low-level vulnerabilities identified
    Platform resilience
    Unknown
    Basic level of cyber resilience confirmed
    Timeline
    Project completed in 2 weeks
    More success stories with Datami
    Browse other project case studies
    Mobile App Security Outstaff Audit

    Mobile App Security Outstaff Audit

    • Identified dangerous configurations and data leaks
    • Strengthened security before product launch
    Services:
    Nov 20, 2025
    Security Policy Audit for a Fintech Company

    Security Policy Audit for a Fintech Company

    • Seven key cybersecurity policies were reviewed and assessed
    • Regulations aligned with ISO 27001, DORA, GDPR, and NBG
    Services:
    Security policy and compliance audit
    Nov 20, 2025
    Security Testing of the DonorUA Medical Platform

    Security Testing of the DonorUA Medical Platform

    • Provided a security recommendations report.
    • No critical security threats were confirmed.
    Services:
    Web application pentest (Black-box)
    Nov 18, 2025
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    Modern Phishing Campaigns Use PDF Files for Attacks Datami Newsroom
    Datami Newsroom

    Modern Phishing Campaigns Use PDF Files for Attacks

    Next-generation phishing campaigns disguise themselves as well-known brands and use artificial intelligence to mislead users. In 2025, companies face a wave of sophisticated attacks that are changing cybersecurity rules.

    Nov 24, 2025 3 min
    KillSec Ransomware Attacks Healthcare Datami Newsroom
    Datami Newsroom

    KillSec Ransomware Attacks Healthcare

    The hacker group KillSec has recently been actively attacking the IT systems of the healthcare sector in Latin America and other countries — the attackers have already stolen dozens of gigabytes and nearly 95,000 files.

    Nov 18, 2025
    Datami at MERGE Madrid and EBC 25 Datami Newsroom
    Datami Newsroom

    Datami at MERGE Madrid and EBC 25

    The Datami team attended MERGE Madrid and the European Blockchain Convention 2025 to share their expertise and witness how Web3 is evolving. This year, the focus shifted toward real-world solutions – security, auditing, and transparent standards.

    Nov 13, 2025 3 min
    Order a free consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy