Home > Projects > Synder App

Synder App

Penetration testing for AI-Driven Accounting Platform

Type

Web

Industry

Business & finance

Country

United States

Highlights

  • 9-day security engagement April 07–15, 2025
  • Penetration testing for SOC 2 readiness without social engineering
  • No unauthorized access gained, overall risk assessed as Medium
  • Delivered the list of identified defects 
  • Provided a remediation plan ranked by severity and business impact
Synder App Background with Numbers

Client

CloudBusiness is a software development firm that provides cloud-based solutions for businesses, accountants, and bookkeepers. The Synder App is one of their core offerings. It is an accounting automation tool that synchronizes and reconciles transactions across multiple sales channels and payment platforms.

Challenge

Since the platform processes large volumes of confidential financial data, ensuring strong security and resilience against potential cyber-attacks is especially important. The client was in the process of obtaining SOC 2 certification and engaged SoftTeco’s security team to conduct penetration testing and evaluate the security posture of the Synder App.

Synder App Background with Diagrams

Tech stack

Components

OWASP ZAP

Acunetix

JWT_Tool

Burp Suite

SQLmap

SSLScan

How it works

SoftTeco security testing team assessed the Synder App from April 07, 2025 to April 15, 2025, simulating real attacker actions without social engineering. The team used a hybrid approach combining SAST (static analysis), DAST (dynamic analysis), and manual testing. Our engineers started with automated discovery, validated each finding, and then expanded manual testing to cover edge cases and logic flaws.

Testing followed a Black Box model as an authenticated user with limited knowledge of the environment. Our QA engineers used PTES, OWASP Web Security Testing Guide, and NIST 800-115 to keep coverage structured and repeatable. We then classified every confirmed issue using OWASP Top 10, OWASP API Top 10, and CVSS, so the client could prioritize fixes and use the output as evidence for SOC 2 work.

Have a testing request?

Describe the product you need to test, and our team will send you a cost estimate and the next steps.

Results

SoftTeco’s security testing team did not gain unauthorized access, but identified vulnerabilities that could be exploited over time and rated the overall risk as Medium. Our QA specialists classified each confirmed issue by severity based on its potential impact on the client’s business workflows and on how the application handles confidential financial data. We delivered a report with prioritized corrective actions to strengthen protection against real-world attacks, and the client requested a retest after implementing the recommended changes.

AI Hotel Concierge

AI Hotel Concierge

An AI-Powered Assistant on Cisco Webex Desk Pro

Hospitality

  • ML
Supersapiens

Supersapiens

An energy management system for athletes

Sports & Lifestyle

  • Web
  • Mobile

    Start your digital transformation journey today

    Drop us a line via the form below or contact us at info@softteco.com and our representative will get back to you within one business day.

    I agree with the Privacy Policy and the Terms of Services

    13 REVIEWS

    51 REVIEWS

    Poland

    9A/4U Belwederska st., Warsaw, 00-761

    Lithuania

    82 Laisves al., Kaunas, 44250

    42A, Dariaus ir Gireno st., Vilnius, 02189

    Bulgaria

    Knyaginya Maria Luiza 1 Blvd., Plovdiv, 4000

    Georgia

    1 Meliton And Andria Balanchivadze st., Tbilisi, 0667

    United States

    22 Juniper st., Wenham, Massachusetts, 01984

    United Kingdom

    Loughborough Technology Centre, Epinal Way, Loughborough, LE11 3GE

    United Arab Emirates

    Office No. 19-177MF, Owned by Shamsa Mohammed Ibrahim
    Al-Suwaidi, Al-Murar, Dubai

    13 REVIEWS

    22 REVIEWS

    13 REVIEWS

    22 REVIEWS

    Softteco Logo Footer