Penetration and data-protection testing for a credential vault
Penetration-tested the credential vault and its sync, verifying encryption and access controls end to end so stored secrets stayed protected.
Encryption verified
Problem, approach, and the outcome
The client is a US provider of a password manager used by healthcare organisations to store and share sensitive credentials. When the product is the vault, the encryption and access controls protecting it are the entire value proposition.
Secrets synced across devices and users, so the data-protection guarantees had to hold not just at rest but everywhere the vault travelled.
The vault's security rested on claims about encryption and access control that had never been independently verified. Unverified cryptographic claims are a liability rather than an assurance.
Sync introduced extra exposure, because credentials moved between devices and users, and any weakness in that flow could undermine the protection of the data at rest. The most sensitive data was also the most mobile.
With healthcare customers depending on the vault, the client needed proof that encryption and access controls held end to end, not just in principle. The guarantee had to be demonstrated, not asserted.
Under a signed scope, we penetration-tested the vault and its sync, probing access controls, data handling, and the cryptographic protections in practice rather than on paper. Testing the implementation is what turns a claim into a verified fact.
We combined static and dynamic analysis to examine how secrets were encrypted, stored, and transmitted, checking that protection held across the full lifecycle. Following the data end to end is what exposes gaps between at-rest and in-transit.
Each finding shipped with impact and remediation detail, and we retested after fixes to confirm the encryption and access controls behaved as designed. The data-protection guarantee moved from asserted to evidenced.
- Vault and sync flows penetration-tested
- Encryption verified at rest and in transit
- Access controls validated end to end
- Findings remediated and retested to confirmation
More Quality Assurance & Testing case studies

Application and API security testing for a SaaS platform
Delivered OWASP-aligned application and API testing that closed the exploitable paths and left the platform with zero critical findings at release.
Read the full case study
Multi-cloud security and misconfiguration assessment
Assessed the attack surface and misconfigurations across AWS, Azure, and GCP and mapped every finding to compliance, leaving the estate audit-ready.
Read the full case study
Authentication and access-control testing for an identity platform
Tested login, SSO, and token flows end to end and hardened the identity layer against real abuse cases before rollout.
Read the full case studyGet a senior architect on the call, first time, every time.
No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.
