Skip to content
BritonOne Technology
Quality Assurance & TestingHealthcare

Penetration and data-protection testing for a credential vault

Penetration-tested the credential vault and its sync, verifying encryption and access controls end to end so stored secrets stayed protected.

Encryption verified
Burp SuiteCryptographySASTDAST
Penetration and data-protection testing for a credential vault
IndustryHealthcare
DisciplineSecurity Testing
CountryUnited States
Headline resultEncryption verified
The story

Problem, approach, and the outcome

About the client

The client is a US provider of a password manager used by healthcare organisations to store and share sensitive credentials. When the product is the vault, the encryption and access controls protecting it are the entire value proposition.

Secrets synced across devices and users, so the data-protection guarantees had to hold not just at rest but everywhere the vault travelled.

The challenge

The vault's security rested on claims about encryption and access control that had never been independently verified. Unverified cryptographic claims are a liability rather than an assurance.

Sync introduced extra exposure, because credentials moved between devices and users, and any weakness in that flow could undermine the protection of the data at rest. The most sensitive data was also the most mobile.

With healthcare customers depending on the vault, the client needed proof that encryption and access controls held end to end, not just in principle. The guarantee had to be demonstrated, not asserted.

Our approach

Under a signed scope, we penetration-tested the vault and its sync, probing access controls, data handling, and the cryptographic protections in practice rather than on paper. Testing the implementation is what turns a claim into a verified fact.

We combined static and dynamic analysis to examine how secrets were encrypted, stored, and transmitted, checking that protection held across the full lifecycle. Following the data end to end is what exposes gaps between at-rest and in-transit.

Each finding shipped with impact and remediation detail, and we retested after fixes to confirm the encryption and access controls behaved as designed. The data-protection guarantee moved from asserted to evidenced.

Results
  • Vault and sync flows penetration-tested
  • Encryption verified at rest and in transit
  • Access controls validated end to end
  • Findings remediated and retested to confirmation
Next step

Get a senior architect on the call, first time, every time.

No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.