R208Projects2025
Sentinel Bank
A regional bank preparing for audit with six months of unreviewed releases behind it.

The challenge
Rapid feature shipping had outpaced review. No threat model existed, access control was inconsistent across three services, and secrets were being passed through CI logs.
Our approach
Threat model workshop, then a manual penetration test across auth, session handling and business logic. We found 19 issues, four critical. Each came with reproduction steps and a patch. We then added security gates to CI and paired with their team on the fixes.
The outcome
All critical and high findings closed in three weeks. Audit passed first attempt. Security checks now block merge automatically.