Customer story

Security from codebase to attack surface

A representative walkthrough of a payments service — payflow-api — taken from a failing security grade to a merged fix. Every number below comes from a real Orvanta scan you can reproduce in under a minute.

25
findings
9
critical
D → improving
grade
01

Understand

Orvanta mapped the service in seconds — Flask + Express, a SQLite data layer, JWT auth, and 8 API routes — before flagging a single issue.

02

Detect

The scan surfaced 25 findings: 9 critical, 13 high. SQL injection, disabled JWT verification, OS command injection, and vulnerable dependencies with public CVEs.

03

Explain

Each finding came with a concrete attack — e.g. an attacker sending ?src=img.png;rm -rf … to reach the shell — and its business impact.

04

Fix

Orvanta wrote parameterized queries, switched exec to execFile, and re-enabled signature verification — then reviewed each patch for regressions before the team saw it.

05

Ship

Approved fixes were packaged into a single security pull request with a unified diff and risk summary, moving the score up on every merge.

See it on your own code

Run the same scan on the demo repo, or your own project, free — real findings, real fixes, in under a minute.

This is an illustrative walkthrough using Orvanta's demo project — not a claim about a specific customer.