AI-native LMS platform · SaaS · anonymised

Confirmed

Tested, documented, still stuck.

The GRC programme was active. An established vendor had already run the security testing. Enterprise deals were still stalling at review — because nothing anyone had tested went near the MCP server.

Sector
SaaS · edtech
Stack
Azure · MCP · LLMs
Surface
MCP server, auth, tenancy
Elapsed
Two months
28Findings, root-caused and prioritised
3Critical, alongside eight high
11Critical and high, fixed before the next rollout
2 moFrom first test to deals moving

The journey

How a compliant company stayed blocked.

  1. 01

    A deal stops at security review

    An enterprise buyer halted the deal. Not on price, not on features. The security review did not clear.

  2. 02

    The GRC programme was already running

    Policies in place, controls documented. The governance work every enterprise buyer asks about was done, and could be evidenced.

  3. 03

    And the security testing was already done

    An established vendor had tested the platform. Engagement closed, report in hand.

  4. 04

    The deal was still stuck

    Every remaining deal in the pipeline was asking the same set of questions: DPDP handling, cloud posture, LLM supply-chain risk, and the MCP server.

    That last one had never been in anyone's scope. An MCP server is new attack surface, and the testing they had bought was written for an application — the identity and data boundary around the model was not in it.

  5. 05

    We tested the surface nobody had covered

    The production authentication path and the MCP server, unauthenticated and privileged. Findings mapped per finding to OWASP Top 10 and OWASP LLM Top 10.

  6. 06

    What was sitting there

    28 findings. 3 critical, 8 high.

    • Malformed input returned the tenant ID, the database schema and storage tokens.
    • OAuth registration was open.
    • Two critical cross-tenant isolation failures — one tenant could read another tenant's course content, and inject across the boundary.
  7. 07

    The deals moved

    All 11 critical and high findings were fixed before the next production rollout. Active enterprise deals progressed through security review.

Client feedback

  • Then Manish and his team started working with us. Within weeks, the picture changed completely.

    CEO
  • The team went beyond surface-level scans and uncovered vulnerabilities that had been sitting in our system for months.

    CEO
  • First-principles thinking — not just throwing an LLM over the requirement.

    Head of Security
  • Every finding came with clear proof, severity mapping to OWASP and LLM-specific threat models, and actionable fixes prioritised by impact.

    Head of Security

Both from the AI-native LMS SaaS platform above. Reference available on request.

Stuck in someone else's security review?

Twenty minutes is enough to scope it.

Anonymised and published under written authorization · No client data redistributed