Synder App
Highlights
- Conducted manual and dynamic application security testing (DAST) using OWASP ZAP
- Utilized SqlmMap to detect and confirm SQL injection vulnerabilities in backend data handling processes
- Applied sslscan to assess SSL/TLS configurations and detect cryptographic weaknesses
- Generated a comprehensive report detailing findings, risk levels, and actionable remediation steps to enhance the application’s security posture

Client
CloudBusiness is a software development firm that provides cloud-based solutions for businesses, accountants, and bookkeepers. The Synder App is one of their core offerings. It is an accounting automation tool that synchronizes and reconciles transactions across multiple sales channels and payment platforms.
Challenge
Since the platform processes large volumes of confidential financial data, ensuring strong security and resilience against potential cyber-attacks is especially important. The client is in the process of obtaining SOC 2 certification and has engaged SoftTeco’s security team to conduct penetration testing and evaluate the security posture of the Synder App.

Tech Stack
Components
OWASP ZAP
Acunetix
JWT_Tool
Burp Suite
SqlmMap
slscan
How it works
Our security testing team began with automated vulnerability scanning using OWASP ZAP, Acunetix, SqlmMap, and sslscan tools. Based on the results and the tester’s expertise, the security team also performed manual testing to uncover any issues that the automated tools may have overlooked. Penetration testing was conducted using the Black Box testing model, following the PTES, OWASP Web Security Testing Guide, and NIST 800-115 methodologies.
Have a project in mind?
Let us know what kind of software solution you need, and our specialists will provide an estimate cost and deadline.
Results
Penetration testing did not result in a system breach, but SoftTeco’s team found several potential vulnerabilities and delivered a comprehensive report with suggested improvements. The client is
taking steps to enhance security and has requested a retest after implementing the necessary changes.