SONNET CODE
← Back to all case studies
Fintech 2026 · 4 months

Security hardening for a B2B payments platform

Overview

Every enterprise deal stalled for weeks on the buyer's security questionnaire. We threat-modeled the platform, moved security checks into CI (static analysis, dependency and secrets scanning), replaced shared cloud credentials with SSO and least-privilege roles, and added tamper-evident audit logging. The fraud-screening assistant got its own review: prompt-injection tests, PII redaction before any model call, and tool permissions scoped per action. The team kept the runbooks and a review checklist they now run on every pull request.

What we delivered

  • Threat model & data-flow map
  • CI security gates (SAST, dependency & secrets scanning)
  • SSO + least-privilege IAM
  • Tamper-evident audit logging
  • LLM feature review (prompt injection, PII redaction)
  • Incident-response runbooks

Stack

OWASP ASVS · Semgrep · GitHub Actions · AWS IAM · Terraform · Node.js


Duration: 4 months
Year: 2026
Industry: Fintech

Want us to build yours? Schedule a 15-minute call.