en

Preparation of the Platform for Regulatory Audit

Client:
Mid-sized fintech company
Industry:
FinTech
Focus:
Testing of the KYC module and compliance with AML/KYC, GDPR, and PCI DSS
Main challenge:
Verification reliability testing, and preparation for a regulatory audit
Market:
International – EU and Eastern Europe
Services provided:
Key Takeaways
  • The risk of KYC bypass was reduced from high to low.
  • Implemented rate limiting and AI-based deepfake detection.
  • A Gray-box pentest of web and mobile applications, KYC, and API was conducted.
  • 12 vulnerabilities were identified: 3 critical, 5 medium, and 4 low.
  • Critical threats were eliminated in less than 72 hours.
  • 12
    vulnerabilities identified
    80%
    increase in attack resilience
    72
    hours to eliminate threats
    Preparation of the Platform for Regulatory Audit
    The company recorded suspicious attempts to bypass KYC and turned to Datami to verify the reliability of document verification before the regulatory audit. During the pentest, 12 vulnerabilities were identified and eliminated – the platform achieved full compliance with fintech security standards.

    The fintech company operates in the international market of the EU and Eastern Europe, providing users with a platform for online payments and digital wallets.

    The security of KYC processes is critically important, as the business handles large volumes of personal and financial data and must comply with GDPR, PCI DSS, and AML/KYC standards.

    Tasks and challenges
    Before undergoing a regulatory audit, the company recorded suspicious attempts to bypass KYC, which could have caused data theft or money laundering.
    To verify the reliability of document verification and the protection of personal data, it turned to Datami for comprehensive security testing.
     
    • To check the possibility of bypassing KYC through forged documents or photos.
    • To conduct a Gray-box pentest of the KYC backend API, mobile, and web application.
    • To provide a report with PoC and recommendations for conformity to security standards.
    icon
    Verification testing
    KYC module testing: documents, selfies and videos (replay, deepfake, biometrics)
    icon
    Vulnerability discovery
    Gray-box pentest of backend API, web and mobile applications for threats
    icon
    Compliance with standards
    PoC report with risk descriptions and technical recommendations for AML, GDPR and PCI DSS

    Our approach

    To assess the resilience of verification processes, Datami specialists conducted a targeted review of the KYC module: they examined the architecture, test accounts, and APIs using a Gray-box approach.

    For this case study, they used automated scanners and manual testing: OCR analysis, deepfake simulations, authorization, and API logic testing using Burp Suite, MobSF, and custom scripts.

    Gray-box

    Gray-Box

    Penetration testing with limited access to test accounts and documentation for realistic attack modeling.
     
    Key stages of work and solutions

    To avoid disrupting platform users, Datami specialists worked in a clear sequence. After agreeing on key details, they carried out automated and manual testing.

    Based on the assessment results, the client received a detailed PoC report with evidence of vulnerabilities, risk levels, and technical recommendations for compliance with security standards.

    • Preparation
      Analysis of the KYC architecture, agreement on rate limits, creation of test accounts and test data, and planning verification scenarios.
    • Testing
      Scanning the API, web, and mobile applications, manual modeling of KYC bypasses using forged documents, and verification of API logic.
    • PoC report
      Preparation of a report describing vulnerabilities, evidence of their exploitation, and technical recommendations to improve security.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations

    Results and recommendations

    During the fintech platform pentest, the Datami team identified 12 vulnerabilities in the KYC module: 3 critical, 5 medium, and 4 low. The most serious issues – document reuse, lack of rate limiting in the KYC API, and weak video verification – were fixed within 72 hours.

    Following the cybersecurity assessment, the client received recommendations to:

    • conduct an annual KYC audit;
    • implement document uniqueness verification;
    • maintain API rate limiting;
    • update security policies;
    • use AI modules for deepfake detection.

    After implementing the updates, the risk of fraud decreased from high to low, and system resilience increased by 80%. The platform achieved full compliance with AML/KYC, GDPR, and PCI DSS standards, avoiding fines and a negative audit outcome.

    Our certificates

    Datami is a cybersecurity firm whose qualifications are confirmed by 26 certifications and international standards. This allows us to perform tasks of varying complexity while complying with security, confidentiality, and ethical practice requirements.
    Key project results

    For fintech companies, cybersecurity assessment is extremely important, as vulnerabilities can lead to serious losses: data leaks, fines, theft, or money laundering.

    As this case study demonstrates, the pentest allowed the client to proactively eliminate threats, enhance attack resilience, and achieve compliance with security standards. Datami’s recommendations helped the fintech company successfully pass the audit and avoid penalties.

    Direction
    Before the project
    After implementation
    Risk level
    High – possible KYC bypass, document reuse
    Low – threats eliminated, processes secured
    KYC security
    Insufficient control of documents and video verification
    Enhanced document verification, an AI module for deepfake detection added
    Vulnerabilities
    12 identified, including 3 critical
    All eliminated
    System resilience
    Vulnerable to replay attacks and forgeries
    Increased by 80%
    Standards compliance
    Partial
    Full compliance with AML/KYC, GDPR, and PCI DSS
    More success stories with Datami
    Browse other project case studies
    Cloudflare Zero Trust & SIEM for SaaS
    Cloudflare Zero Trust & SIEM for SaaS
    • MTTD reduced to 1–2 hours
    • False positives reduced by 50–65%
    Services:
    Cloudflare Zero Trust and Wazuh SIEM implementation
    Aug 4, 2026
    WordPress Website Recovery After a Hack
    WordPress Website Recovery After a Hack
    • Backdoor infections and web shells were completely removed.
    • 9 unauthorized admin accounts were removed.
    Services:
    WordPress Security Audit (White-box)
    Aug 4, 2026
    SIEM Wazuh Implementation for a Financial Company
    SIEM Wazuh Implementation for a Financial Company
    • PCI DSS & ISO 27001 audit-ready
    • Reduced false positives by 60–70%
    Services:
    SIEM Implementation (Wazuh)
    Jul 1, 2026
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    What Does AI Penetration Testing Include? A Practical Breakdown of 12 Critical Security Checks Oleksandr Filipov
    Oleksandr Filipov
    What Does AI Penetration Testing Include? A Practical Breakdown of 12 Critical Security Checks

    AI Penetration Testing checks not only for prompt injection but also for RAG, memory, agent privileges, and integrations. Find out which 12 tests help identify real risks in AI systems.

    4 min Aug 20, 2026
    Modern LLM Pentesting Goes Far Beyond Prompt Injection Oleksandr Filipov
    Oleksandr Filipov
    Modern LLM Pentesting Goes Far Beyond Prompt Injection

    LLM pentesting goes beyond prompt injection: it audits data leaks, permission bypasses, and harmful actions. Discover what a full AI audit must cover.

    4 min Aug 20, 2026
    Why AI Tokens Introduce a New Class of Smart Contract Risks Oleksandr Filipov
    Oleksandr Filipov
    Why AI Tokens Introduce a New Class of Smart Contract Risks

    A smart contract can pass a Solidity audit without a remark and still be exploitable - if part of the decision-making sits with a model. What a real audit with 40 findings reveals, and what to check before listing.

    4 min Aug 4, 2026
    Order a consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy