en

Mobile App Security Outstaff Audit

Client:
A company providing veterinary services through a mobile platform
Industry:
Healthcare
Focus:
Security audit of the mobile application and AWS before MVP launch
Main challenge:
Check the security level of key assets before release in an outstaffing format.
Market:
International
Key Takeaways
  • Identified dangerous configurations and data leaks
  • Strengthened security before product launch
  • Used manual and automated testing
  • Found 26 vulnerabilities, including 4 critical
  • Delivered a remediation recommendations report
  • 2
    components checked
    26
    vulnerabilities identified
    1.5
    months of project duration
    Mobile App Security Outstaff Audit
    Is there value in a security audit before releasing an MVP? This case study confirms that there is. The company brought a Datami specialist into the developer’s team. He performed a pentest and code review of the mobile application and AWS, identifying critical vulnerabilities and risks for the MVP.

    An international company is developing a mobile service for remote communication between veterinarians and their clients. The platform combines a mobile application with cloud infrastructure.

    Cybersecurity is crucial for the company because the developer’s service processes users’ personal data, and any vulnerability may lead to data leaks, financial losses, or even disrupt the MVP launch.

    Tasks and challenges
    The client was preparing to launch the MVP. To prevent data loss and eliminate financial and reputational risks, it was necessary to conduct an external security assessment of the mobile application and AWS infrastructure.

    The company decided to involve a Datami specialist to obtain an independent evaluation of the risk level and recommendations for its mitigation before the release.
    • Evaluate the security of the AWS infrastructure and the mobile application
    • Conduct a technical review of the code and critical configurations
    • Prepare a detailed report with recommendations for eliminating vulnerabilities
    icon
    Mobile application pentest
    Test the app’s security using automated and manual methods
    icon
    AWS penetration test
    Check the console, servers, and configurations for vulnerabilities
    icon
    Code security audit
    Analyze the software code to identify issues and improve security

    Work in an outstaff format

    The Datami specialist was integrated into the client’s internal team. This cooperation model ensured efficiency and transparent communication: the security assessment was performed without interrupting processes and with full control remaining on the client’s side.

    For the pentest and code security audit, a White-Box strategy was applied. During the project, our expert combined automated tools and manual testing methods to achieve the most accurate and comprehensive result.

    White-box

    White-Box

    Deep testing with full access to the code and configurations to identify vulnerabilities.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations

    Results and recommendations

    To assess the security of the cloud infrastructure and the mobile application, the Datami specialist used a White-Box strategy. 

    During the pentest and code security audit, 26 vulnerabilities of varying severity were identified: 4 critical, 7 high, 11 medium, and 4 low. Both technical issues and configuration errors were discovered, including:

    • data exposure,
    • unsafe settings,
    • incorrect administrator permissions,
    • exposed API keys in the code,
    • outdated, vulnerable modules and libraries,
    • storage of sensitive information in the source code.

    Based on the security assessment, a report describing the risks was prepared. Each vulnerability was accompanied by specific recommendations, including:

    • configuring secure storage of keys in the code,
    • implementing two-factor authentication,
    • strengthening access control for configurations,
    • regularly updating third-party modules.

    Our certificates

    Datami is a cybersecurity firm whose qualifications are confirmed by 26 certifications and international standards. This allows us to perform tasks of varying complexity while complying with security, confidentiality, and ethical practice requirements.
    Key project takeaways

    Thanks to the collaboration with Datami, the client quickly received a full risk assessment and a clear plan for improving security before the MVP release. This will help them successfully pass future audits and strengthen user trust.

    This case study also demonstrates the effectiveness of the outstaff approach to cybersecurity testing: integrating an external specialist into the internal team made it possible to efficiently conduct an independent audit without halting development or expanding the staff.

    Security status
    No expertise
    26 vulnerabilities identified, a report with remediation instructions prepared
    Confidential data
    Risk of leakage
    Recommendations provided on 2FA, access policies, and key storage
    Code protection
    Vulnerabilities and secrets in the code
    Error remediation plan prepared
    More success stories with Datami
    Browse other project case studies
    Cloudflare Zero Trust & SIEM for SaaS
    Cloudflare Zero Trust & SIEM for SaaS
    • MTTD reduced to 1–2 hours
    • False positives reduced by 50–65%
    Services:
    Cloudflare Zero Trust and Wazuh SIEM implementation
    Aug 4, 2026
    WordPress Website Recovery After a Hack
    WordPress Website Recovery After a Hack
    • Backdoor infections and web shells were completely removed.
    • 9 unauthorized admin accounts were removed.
    Services:
    WordPress Security Audit (White-box)
    Aug 4, 2026
    SIEM Wazuh Implementation for a Financial Company
    SIEM Wazuh Implementation for a Financial Company
    • PCI DSS & ISO 27001 audit-ready
    • Reduced false positives by 60–70%
    Services:
    SIEM Implementation (Wazuh)
    Jul 1, 2026
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    Why AI Tokens Introduce a New Class of Smart Contract Risks Oleksandr Filipov
    Oleksandr Filipov
    Why AI Tokens Introduce a New Class of Smart Contract Risks

    A smart contract can pass a Solidity audit without a remark and still be exploitable - if part of the decision-making sits with a model. What a real audit with 40 findings reveals, and what to check before listing.

    4 min Aug 4, 2026
    When AI Meets Smart Contracts: How Prompt Injection Creates a New Web3 Attack Surface Oleksandr Filipov
    Oleksandr Filipov
    When AI Meets Smart Contracts: How Prompt Injection Creates a New Web3 Attack Surface

    A smart contract can pass the most rigorous audit and the product around it can still be exposed. All it takes is an AI reading on-chain text as a command. A new class of Web3 risk, from a real Datami finding.

    3 min Aug 3, 2026
    Cybersecurity Risk Self-Assessment: 6 Gaps Fintech Companies Notice Last Oleksandr Filipov
    Oleksandr Filipov
    Cybersecurity Risk Self-Assessment: 6 Gaps Fintech Companies Notice Last

    Most companies learn about their weak spots not from their own team, but from a due diligence partner or an attacker. We explain which gaps in fintech remain unnoticed the longest and why.

    4 min Jul 27, 2026
    Order a consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy