AI-native LMS platform · SaaS · anonymised
ConfirmedTested, documented, still stuck.
The GRC programme was active. An established vendor had already run the security testing. Enterprise deals were still stalling at review — because nothing anyone had tested went near the MCP server.
The journey
How a compliant company stayed blocked.
-
01
A deal stops at security review
An enterprise buyer halted the deal. Not on price, not on features. The security review did not clear.
-
02
The GRC programme was already running
Policies in place, controls documented. The governance work every enterprise buyer asks about was done, and could be evidenced.
-
03
And the security testing was already done
An established vendor had tested the platform. Engagement closed, report in hand.
-
04
The deal was still stuck
Every remaining deal in the pipeline was asking the same set of questions: DPDP handling, cloud posture, LLM supply-chain risk, and the MCP server.
That last one had never been in anyone's scope. An MCP server is new attack surface, and the testing they had bought was written for an application — the identity and data boundary around the model was not in it.
-
05
We tested the surface nobody had covered
The production authentication path and the MCP server, unauthenticated and privileged. Findings mapped per finding to OWASP Top 10 and OWASP LLM Top 10.
-
06
What was sitting there
28 findings. 3 critical, 8 high.
- Malformed input returned the tenant ID, the database schema and storage tokens.
- OAuth registration was open.
- Two critical cross-tenant isolation failures — one tenant could read another tenant's course content, and inject across the boundary.
-
07
The deals moved
All 11 critical and high findings were fixed before the next production rollout. Active enterprise deals progressed through security review.
Client feedback
-
Then Manish and his team started working with us. Within weeks, the picture changed completely.
CEO -
The team went beyond surface-level scans and uncovered vulnerabilities that had been sitting in our system for months.
CEO -
First-principles thinking — not just throwing an LLM over the requirement.
Head of Security -
Every finding came with clear proof, severity mapping to OWASP and LLM-specific threat models, and actionable fixes prioritised by impact.
Head of Security
Both from the AI-native LMS SaaS platform above. Reference available on request.
Stuck in someone else's security review?
Twenty minutes is enough to scope it.
Anonymised and published under written authorization · No client data redistributed