BookingSync is a French technology company that provides a platform for managing short-term rental properties. Serving an international market—primarily across Europe—BookingSync enables thousands of hosts and guests to access its services daily through a user-friendly web portal and API integrations.
While the company does not operate in a regulated industry, it handles large volumes of user personal data, making robust system security a top priority.
BookingSync's primary concerns were unauthorized access to its API and potential data leaks. To proactively mitigate reputational risks, the company initiated a scheduled security assessment.
Project objective was to identify potential vulnerabilities in API endpoints and assess their resilience against external threats.
To assess the security of BookingSync’s API endpoints, Datami employed a gray-box penetration testing approach. The team had partial access to technical documentation, enabling a deeper analysis of endpoint logic and common access scenarios.
We combined automated scans using Burp Suite API Scan with manual testing methods to ensure thorough coverage of both standard and unconventional attack vectors.
The Datami team conducted a focused security assessment of BookingSync’s API, targeting vulnerabilities that could potentially lead to personal data exposure. A hybrid approach was used, combining automated scanning via Burp Suite API Scan with manual analysis.
The process included the following key stages:
Every
At the start of the project, BookingSync faced an undefined risk level: the platform had been continuously expanding its API endpoints without a full security audit, posing potential threats to the integrity of users’ personal data.
During the gray-box penetration testing, the Datami team identified several low-level vulnerabilities. While not critical, these weaknesses could potentially be exploited to gain unauthorized access.
Datami provided BookingSync with the following recommendations:
Following the implementation of the recommendations, the platform’s security posture improved, and the risk of API-related compromise was significantly reduced. The company avoided a potential data breach that could have led to reputational damage.
The project was completed in just 3 weeks — nearly twice as fast as the typical market timeframe of 4–6 weeks. No critical incidents were detected, and all identified vulnerabilities were promptly addressed.
Thanks to Datami's testing, BookingSync gained a current and detailed view of its API security status, mitigated low-level risks, and developed a clear action plan for future improvements.
The project helped strengthen the protection of users’ personal data and prevent potential breaches.
This case study confirms that even advanced tech companies with mature digital products require regular penetration testing to maintain a strong security posture.
CV Summit 2025 brought together leaders in fintech, blockchain, and artificial intelligence in Switzerland. The Datami team participated in the global dialogue on how technology is shaping the new financial landscape.
Web applications are targeted by attacks every day - from simple scanners to deliberate breaches. To understand how vulnerable a web application is and how to protect it from hackers’ actions, a special assessment is conducted - penetration testing (pente
Microsoft announced a new update to Defender for Office 365 that automatically detects and blocks email bombing attacks. The rollout started in June, and most users will receive the feature by mid-July 2025.