Case Studies | SaaS B2B

Autonomous AI security testing for the client's storefront

Autonomous AI Security Testing on AWS

About

A SaaS B2B business working with Cloud Combinator on AWS. The client is anonymised at their request.

Challenge

The challenge had four focus areas, each shaped by the fact that this is a live commerce application on AWS.

Assurance over a live storefront

The application handles customer accounts, catalogue data and a payment flow, so any real weakness in the boundary between the public frontend and the internal backend matters directly to customers and to the business.

Signal over noise

Conventional scanning tends to produce large volumes of unverified alerts that teams then have to triage. The client needed findings that were already proven exploitable, so engineering time went into fixing genuine issues rather than chasing false positives.

Understanding the trust boundary

The public frontend proxies requests to internal API Gateway and Lambda services. Establishing where that boundary was too permissive, and how far a crafted request could reach, was central to understanding real exposure.

Speed and repeatability

Assurance that arrives months later is of limited use to a fast-moving product. The client needed testing that was quick, evidence-based and designed to be re-run after each round of fixes.

Solution

The AWS AI Security Agent operates autonomously and from the outside in. In this black-box engagement it worked solely from the public application, reading the client-side JavaScript, identifying the live API routes behind it, and testing each one using established exploit techniques, without any credentials, source code or infrastructure access.

6

Validated findings, each confirmed by exploitation

0

Critical or high-severity issues identified

100%

Findings evidenced with reproducible steps

By the numbers:

  • 6 - Validated findings, each confirmed by exploitation
  • 0 - Critical or high-severity issues identified
  • 100% - Findings evidenced with reproducible steps
Changes

The assessment identified six confirmed findings, all rated medium, with no critical or high-severity issues and no demonstrated exposure of customer data, credentials or payment information. Each finding was validated through successful exploitation and grouped into two clear underlying causes, giving the client an actionable, correctly ordered remediation plan rather than a backlog of unverified alerts.

  • Validated, not speculativeAll six findings were proven by exploitation, so the team could prioritise real issues with confidence and no false positives to triage.
  • Two root causesThe findings reduced to a permissive frontend-to-backend trust boundary and several controls that checked presence rather than validity, both fixable centrally.
  • A prioritised sequenceA three-tier remediation plan set out what to close first, framed as completing controls already partly in place rather than rebuilding them.
  • Clear scope and honestyThe briefing was explicit about what the black-box run could and could not reach, and recommended a white-box assessment to establish the full extent of exposure.
  • HandoverThe client received an executive briefing for its development and product teams, and an agent designed to be re-run to verify each fix once made.

Alongside the security engagement, Cloud Combinator also carried out a six-month AWS cost review for the client, identifying optimisation quick wins across its accounts. With a validated

Security baseline, a clear remediation path and a recommended white-box follow-up, the client is positioned to keep testing continuously as the storefront evolves.

AWS Stack

AWS App Runner

For hosting the public-facing storefront application.

Amazon API Gateway

And AWS Lambda for the internal backend services behind the storefront.

Amazon DynamoDB

For the product and catalogue data store.

AWS Secrets Manager

And AWS Identity and Access Management for secrets and least-privilege access in scope for the review.

Amazon CloudWatch

For logging and monitoring across the assessed environment.

YOU MIGHT LIKE

Related success stories

View all case studies

Case Studies | Insights

Utilising Language Recognition, Speed, and Enhanced Security to Make Social Media a Force for Good

  • Here, we take a detailed look at how the Cloud Combinator team collaborated with another cutting-edge AI service provider that provides intelligent systems to “make social media more social” for brands and users alike.
  • Arwen AI is a UK-based startup specialising in AI solutions to manage and enhance brands’ social media interactions. Founded in 2020 by Matt McGrory, Dr. David Cole, and Joel Bailey, Arwen. AI focuses on using AI to automatically detect and remove spam, toxic comments, and other unwanted content from social media platforms.
  • The team at Arwen have three core products. ‘Moderate’ is focused on identifying and removing toxic content from social media channels. ‘Engage’ helps brands identify and engage with meaningful conversations on social media, and ‘Customize’ allows brands to apply bespoke algorithms to their channels - creating an even more effective moderation and engagement.
Read more
CONTACT US

Ready to turn AI into impact?

We'll help you spot the highest-value opportunities, reduce risk around your first AI initiative, and define a clear path to results from day one.

Why talk to us:

Outcome-driven recommendations

AWS-recognised delivery expertise

Risk-aware AI adoption

Clear next step, not a sales pitch

Start with a focused 20-minute conversation about your goals — no pressure, no commitment.

This website uses cookies to enhance user experience and to analyze performance and traffic on our website.

See our Privacy Policy for details.