The client is a company developing a mobile application where brands launch challenges to users in exchange for monetary rewards. The challenges are segmented by location, type, and reward, requiring high reliability and security for the data being managed.
The objective was to evaluate the application's codebase and establish a baseline to monitor development and security improvements over time.
Risks were identified related to:
A comprehensive source code analysis was conducted, focusing on critical aspects:
The analysis enabled the identification and prioritization of critical issues, resulting in: