Research Library / Case Studies /

Fintech (Digital Credit Card)

AWS Cloud Configuration Review & Pentesting of a Thriving Fintech Start- Up

A credit card startup needed proof its AWS cloud wouldn't leak customer data. Payatu found a database open to the internet, storage ripe for raiding, and IAM roles handing out privileges they shouldn't, then closed every gap before launch.
Cloud Security Assessment

At a glance

INDUSTRY

Fintech (Digital Credit Card)

CLIENT PROFILE

A fintech startup, founded in 2019, building a mobile-first credit card product for a fully digital customer experience

SERVICES

Cloud Security Assessment

ENGAGEMENT

AWS cloud security assessment and pentest for a compliance-driven fintech startup

Key Takeaways

  • Client – A fintech startup, founded in 2019, building a mobile-first credit card product with full digital control over limits, rewards and transactions.

  • Problem – A lack of cybersecurity assurance around its AWS environment was undermining brand confidence and putting compliance requirements at risk.

  • What Payatu did – Ran a real-time AWS configuration review with internal and external penetration testing, scoped to minimum permissions across the client’s multi-account AWS architecture, and mapped issues to technical and business impact.

  • Outcome – The client received a detailed report with a prioritized mitigation plan covering IAM, RDS, S3, EC2 and EBS, giving it a clear path to a more secure, compliance-ready cloud environment.

the challenge

Why the client called us in

Founded in 2019, this fintech startup was building a mobile-first credit card product giving users full control over their credit limit, rewards, and domestic and international transactions. A fully digital product built on AWS needed a cloud environment that customers and regulators alike could trust, but a lack of cybersecurity investment left the product vulnerable and made it harder to build that brand confidence. The client needed to know exactly where its AWS configuration and application security fell short before it could meet its compliance requirements.

  • Confirm access control and user rights management are properly enforced
  • Review logging, monitoring, backup and disaster recovery across the AWS environment
  • Assess the overall security posture of the application and cloud infrastructure for exploitable gaps

‍
‍

‍

scope of engagement

What was in scope

  1. Access control and user rights management across the AWS environment
  2. Logging and monitoring configuration across the infrastructure
  3. Security group configuration and rules
  4. HTTP communication permitted to S3 buckets and load balancers
  5. Data backup and disaster recovery implementation
  6. Rotation of access keys and identification of credentials unused for more than 90 days
  7. Internal and external penetration testing to identify configuration mistakes that could leak sensitive information
  8. Overall security posture assessment of the application and cloud infrastructure for vulnerabilities and gaps

Our Approach

How Payatu ran the engagement

01

Scoping Across a Multi-Account Architecture
Using the client's architectural diagrams, Payatu mapped the number of resources across the brand's multi-account AWS setup to define an accurate scope and timeline for the assessment.

02

Permission-Minimized Access
Because the client was reluctant to share SSH access or broad IAM roles, Payatu scoped the audit to the minimum permissions required and completed it with the brand's approval.

03

Real-Time Cloud Security Assessment
The team performed a real-time assessment of the AWS infrastructure, covering IAM, RDS, S3, EC2, EBS and load balancer configurations, alongside internal and external penetration testing.

04

Impact Analysis and Reporting
Each issue was mapped to its technical and business impact and compiled into a report with a mitigation plan to guide remediation.

Key findings

What we found

IAM & Privilege Escalation
Misconfigured IAM roles could be chained to escalate privileges, letting an attacker disrupt business logic or destroy cloud resources and data.
Stale Access Keys
Credentials unused for more than 90 days remained active, creating an account takeover risk if the keys were ever leaked.
Public RDS Exposure
Publicly accessible RDS instances increased the risk of password brute-force attacks, and HTTP-only communication opened the door to man-in-the-middle attacks.
Missing Access Logging
S3 bucket access logging was disabled, meaning a compromise would leave no evidence trail to investigate.
Unencrypted EBS Volumes
An attacker with account access could attach an unencrypted EBS volume and extract sensitive data directly.

the outcome

Results and Impact

Payatu gave this fintech startup a clear-eyed view of where its AWS environment actually stood, translating misconfigurations into concrete technical and business impact. The mitigation plan let the client prioritize fixes across IAM, storage and network exposure without disrupting a lean product team.

‍

  • Delivered a prioritized mitigation plan covering IAM, RDS, S3, EC2 and EBS misconfigurations

  • Completed the audit under a minimum-permissions model, without requiring SSH or root account access

  • Gave the client a clear path to key rotation, MFA enforcement and encrypted storage ahead of compliance reviews

  • Strengthened brand confidence in the startup's cloud security posture as it scales its credit card product

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment