The challenge
DatHuis runs a SaaS platform used daily by real-estate professionals. Fast-growing, fully on AWS, modern GraphQL architecture - exactly the kind of environment where security often lags behind build speed. They wanted no scanner dump and no checklist theater: an honest, business-aware picture of where a real attacker would get in and what the actual impact would be.
About DatHuis
DatHuis is a SaaS platform used daily by real-estate professionals. Fast-growing, fully on AWS, with a modern GraphQL architecture.
Gray-box
Approach (black + white)
OWASP ASVS 2
Assessment standard
Six months
No-obligation re-check
Our approach
A gray-box test: first as an anonymous outsider, then with provided accounts, to judge both the exterior and the application logic realistically. Run against staging, deliberately isolated from production, with no real personal data.
First black-box as an anonymous outsider, then white-box with provided accounts
Assessed against OWASP ASVS level 2, focused on authentication and authorization
Run on staging, deliberately isolated from production and without real personal data
The question that matters: can a user reach another customer's data, or gain more rights than intended?
We test like engineers who have built and run these systems themselves
What we found
This is where the report surprised us. We expected the usual mess of a fast-growing SaaS. Instead, the fundamentals were done right.
Strong on their side
- +A sound authorization model: no route to another customer's data, no way to quietly gain more rights than intended.
- +A modern, clean development setup.
- +Thorough input sanitisation on the key services.
- +Production properly isolated from staging.
- +At no point did we gain a foothold into internal systems.
What was left to tidy up
The improvements we did surface were about infrastructure hardening and policy, not broken application logic.
Tighter shielding of operational tooling. Broader roll-out of multifactor authentication. Some dashboards behind an extra barrier.
Just the tidying you want when you are scaling up. And they did.
The outcome
DatHuis acted on the recommendations quickly. Severity stayed limited, no internal access was gained, and the open items were targeted and fixable. Our standard no-obligation six-month re-check was, for DatHuis, more a confirmation than a catch-up.
For us, this was a pleasant assignment. Not because there was nothing to find, but because we met a team that takes security seriously in the way they build, not as a sauce poured on afterwards.
Download the full case study (PDF)
The complete story as a designed document: challenge, approach, findings and outcome. Free, in exchange for your business email address.
Want an honest read on your own platform?
We test what was actually built, and write up what we actually found. No scanner dump, no checklist theater.