Skip to main content

DatHuis: a pentest that mostly proved what was already solid

Gray-box penetration test of a modern SaaS platform on AWS. We went in with an attacker's mindset and came out pleasantly surprised.

|4 min read
Case studyPenetration testingPropTech
BNDL logo

BNDL - DatHuis

PropTech & real estate platform

dathuis.nl

The challenge

DatHuis runs a SaaS platform used daily by real-estate professionals. Fast-growing, fully on AWS, modern GraphQL architecture - exactly the kind of environment where security often lags behind build speed. They wanted no scanner dump and no checklist theater: an honest, business-aware picture of where a real attacker would get in and what the actual impact would be.

About DatHuis

DatHuis is a SaaS platform used daily by real-estate professionals. Fast-growing, fully on AWS, with a modern GraphQL architecture.

Gray-box

Approach (black + white)

OWASP ASVS 2

Assessment standard

Six months

No-obligation re-check

Our approach

A gray-box test: first as an anonymous outsider, then with provided accounts, to judge both the exterior and the application logic realistically. Run against staging, deliberately isolated from production, with no real personal data.

First black-box as an anonymous outsider, then white-box with provided accounts

Assessed against OWASP ASVS level 2, focused on authentication and authorization

Run on staging, deliberately isolated from production and without real personal data

The question that matters: can a user reach another customer's data, or gain more rights than intended?

We test like engineers who have built and run these systems themselves

What we found

This is where the report surprised us. We expected the usual mess of a fast-growing SaaS. Instead, the fundamentals were done right.

Strong on their side

  • +A sound authorization model: no route to another customer's data, no way to quietly gain more rights than intended.
  • +A modern, clean development setup.
  • +Thorough input sanitisation on the key services.
  • +Production properly isolated from staging.
  • +At no point did we gain a foothold into internal systems.

What was left to tidy up

The improvements we did surface were about infrastructure hardening and policy, not broken application logic.

Tighter shielding of operational tooling. Broader roll-out of multifactor authentication. Some dashboards behind an extra barrier.

Just the tidying you want when you are scaling up. And they did.

The outcome

DatHuis acted on the recommendations quickly. Severity stayed limited, no internal access was gained, and the open items were targeted and fixable. Our standard no-obligation six-month re-check was, for DatHuis, more a confirmation than a catch-up.

For us, this was a pleasant assignment. Not because there was nothing to find, but because we met a team that takes security seriously in the way they build, not as a sauce poured on afterwards.

Download the full case study (PDF)

The complete story as a designed document: challenge, approach, findings and outcome. Free, in exchange for your business email address.

PDF

Want an honest read on your own platform?

We test what was actually built, and write up what we actually found. No scanner dump, no checklist theater.