en

BookingSync Case Study: API Pentest for Personal Data Protection

Client:
BookingSync — a French platform for short-term rental property management
Industry:
Software Development
Focus:
Protecting personal data of users interacting via web portal and API
Main challenge:
Assessing the security of API endpoints to prevent data leaks and unauthorized access
Market:
International (primarily Europe)
Services provided:
Gray-box API pentest using Burp Suite API Scan and manual testing methods
Key Takeaways
  • Conducted a gray-box pentest of API endpoints
  • Identified several low-level vulnerabilities
  • Delivered a report with security enhancement recommendations
  • Reduced the risk of data leaks and avoided reputational damage
  • 100%
    compliance with API security best practices
    3+
    low-level vulnerabilities identified and mitigated
    3
    weeks total duration of the testing process
    BookingSync Case Study: API Pentest for Personal Data Protection
    Is API expansion always safe for a platform? The international company BookingSync decided not to take any chances and initiated an audit of its API endpoints. The Datami team performed a gray-box pentest and uncovered low-level vulnerabilities. The resulting recommendations helped BookingSync boost its API protection and reduce the risk of data leaks.

    BookingSync is a French technology company that provides a platform for managing short-term rental properties. Serving an international market—primarily across Europe—BookingSync enables thousands of hosts and guests to access its services daily through a user-friendly web portal and API integrations.

    While the company does not operate in a regulated industry, it handles large volumes of user personal data, making robust system security a top priority.

    Objectives and challenges

    BookingSync's primary concerns were unauthorized access to its API and potential data leaks. To proactively mitigate reputational risks, the company initiated a scheduled security assessment.

    Project objective was to identify potential vulnerabilities in API endpoints and assess their resilience against external threats.

     
    • 1. Conduct a gray-box pentest of the current API endpoints.
    • 2. Detect vulnerabilities that could lead to data compromise and evaluate the overall security posture.
    • 3. Deliver a comprehensive report with actionable recommendations for improving API documentation and planning future security testing.
    icon
    Penetration testing
    Gray-box pentest of API endpoints
    icon
    Vulnerability identification
    Discovery and prioritization of security risks
    icon
    Reporting & recommendations
    Detailed report with practical advice for improving security
    Our approach

    To assess the security of BookingSync’s API endpoints, Datami employed a gray-box penetration testing approach. The team had partial access to technical documentation, enabling a deeper analysis of endpoint logic and common access scenarios.

    We combined automated scans using Burp Suite API Scan with manual testing methods to ensure thorough coverage of both standard and unconventional attack vectors.

     

     

    Gray-box
    Gray-box
    The assessment was performed with limited internal knowledge, simulating the actions of a potential attacker with basic access and insight. This approach provided a realistic view of actual risk exposure.
     
    Key stages and solutions

    The Datami team conducted a focused security assessment of BookingSync’s API, targeting vulnerabilities that could potentially lead to personal data exposure. A hybrid approach was used, combining automated scanning via Burp Suite API Scan with manual analysis.

    The process included the following key stages:

     

     

    • Preparation
      Review of technical documentation, test planning, and selection of relevant API endpoints.
    • Testing
      Gray-box pentest using both automated and manual methods, with a focus on authentication mechanisms and resistance to unauthorized access.
    • Analysis & Reporting
      Compilation of a detailed report outlining identified low-level vulnerabilities, along with practical recommendations to improve API security and documentation quality.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations
    Results and recommendations

    At the start of the project, BookingSync faced an undefined risk level: the platform had been continuously expanding its API endpoints without a full security audit, posing potential threats to the integrity of users’ personal data.

    During the gray-box penetration testing, the Datami team identified several low-level vulnerabilities. While not critical, these weaknesses could potentially be exploited to gain unauthorized access.

    Datami provided BookingSync with the following recommendations:

    1. Regularly assess new API endpoints for compliance with security standards.
    2. Improve the structure and clarity of API documentation.
    3. Implement an internal process for continuous API testing prior to releases.

    Following the implementation of the recommendations, the platform’s security posture improved, and the risk of API-related compromise was significantly reduced. The company avoided a potential data breach that could have led to reputational damage.

    The project was completed in just 3 weeks — nearly twice as fast as the typical market timeframe of 4–6 weeks. No critical incidents were detected, and all identified vulnerabilities were promptly addressed.

    Our certificates
    Key project takeaways

    Thanks to Datami's testing, BookingSync gained a current and detailed view of its API security status, mitigated low-level risks, and developed a clear action plan for future improvements.

    The project helped strengthen the protection of users’ personal data and prevent potential breaches.

    This case study confirms that even advanced tech companies with mature digital products require regular penetration testing to maintain a strong security posture.

     

    Category
    Before the project
    After implementation
    Security status
    Undefined risk due to ongoing API expansion
    Improved; several low-level vulnerabilities identified and resolved
    Critical vulnerabilities
    None observed, but potential unauthorized access threats existed
    No critical vulnerabilities detected
    Account compromise risk
    Theoretically possible via API logic
    Risks reduced through improved authentication
    Security compliance
    Partial adherence to best practices
    Achieved compliance with API security best practices
    Timeline
    Typical duration: 4–6 weeks
    Completed in 3 weeks
    More success stories with Datami
    Browse other project case studies
    Case Fraudline: Scheduled Pentest of a Whistleblowing Platform

    Case Fraudline: Scheduled Pentest of a Whistleblowing Platform

    • Identified 6 technical vulnerabilities: 5 low-risk and 1 informational
    • Performed additional manual testing of business logic
    Services:
    automated gray-box pentest, audit of secure coding practices, additional manual review of business logic
    May 30, 2025
    P2P Platform Case Study: Comprehensive Security and GDPR Compliance Audit

    P2P Platform Case Study: Comprehensive Security and GDPR Compliance Audit

    • Identified 10 vulnerabilities, including 3 critical ones
    • Improved GDPR compliance and avoided potential financial losses of up to $300,000
    Services:
    Penetration testing, smart contract audit, code security review, testing for SQLi, XSS, and RCE vulnerabilities, OSINT analysis, and cloud infrastructure security assessment
    May 27, 2025
    Case Study Grindset Software: Payment System Pentest for PCI DSS Compliance

    Case Study Grindset Software: Payment System Pentest for PCI DSS Compliance

    • Conducted a black-box penetration test of critical payment system components
    • Discovered 15 vulnerabilities; 5 critical issues were resolved within 48 hours
    Services:
    Black-box penetration testing of the payment system, including assessment of web applications, servers, databases, and communication channels
    May 11, 2025
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    Datami at the Barcelona Cybersecurity Congress 2025: New Horizons in Cybersecurity Datami Newsroom
    Datami Newsroom

    Datami at the Barcelona Cybersecurity Congress 2025: New Horizons in Cybersecurity

    Datami took part in the Barcelona Cybersecurity Congress 2025, one of Europe’s key events dedicated to cybersecurity innovations and technologies.

    Jun 3, 2025
    Why Your Smartphone Is at Risk: 5 Common Myths About Mobile Security Datami Newsroom
    Datami Newsroom

    Why Your Smartphone Is at Risk: 5 Common Myths About Mobile Security

    Most of us take careful care of our smartphones, protecting them from scratches, drops, or other physical damage. But when it comes to digital security, many people ignore potential threats. Cybercriminals eagerly take advantage of this negligence...

    Jun 3, 2025 5 min
    TOP 5 Largest Cryptocurrency Hacks in History Datami Newsroom
    Datami Newsroom

    TOP 5 Largest Cryptocurrency Hacks in History

    The cryptocurrency industry is still in its formative stage, and its highly complex technologies are not always adequately protected. In addition, inexperienced users often make serious mistakes in securing their assets. This creates various opportunities

    Jun 3, 2025 4 min
    Order a free consulidation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy