korelex.ai

DATA-01 · Broken object-level authorization · Anonymised

Confirmed

One request. Then ninety‑five customers.

Reconstructed from the assessment log, at the speed it actually happened. Every frame below corresponds to a request we made and recorded — from a free trial seat, with no elevated privileges.

GET /v3/accounts/1042/report  → 200 OK Free trial seat · tenant A
0 Reports retrieved
Trial account revoked
Link validity 7 days remaining

Press play to run the reconstruction.

Click any beat to jump · 22s

For your engineers

  • Authorize the object, not the route — check ownership server-side on every report fetch.
  • Signed URLs measured in minutes, bound to the session that requested them.
  • Regression test: tenant A's session fetching tenant B's report must return 403.

Three changes · one sprint

For your regulator

  • GDPR Art. 32 security of processing · Art. 25 protection by design.
  • Art. 33 notification assessment triggers if the reports carry non-public personal data.
  • India DPDPA Sec. 8(5) reasonable security safeguards.

Ceiling · €20M or 4% of global turnover

For your buyer

  • The questionnaire answer, in one line: object-level authorization enforced server-side and independently retested.
  • Retest dated, signed and attached to the claim — not a checkbox.

The reason the deal moves

DATA-01 is one finding of eighteen. Read the full case study →