Skip to main content
Unnamed
ServicesCase StudiesProcessAbout
Book a call
Unnamed Development
v.2026 · us-east-1
ServicesCase StudiesProcessAboutPricingContact
Book a call
← All case studiesMarketplace

Marketplace Architecture Audit

$0in critical security findings after remediation

Marketplace Architecture Audit

Note: This is placeholder content. The full case study is pending client sign-off for publication.

The problem

A two-sided marketplace was preparing for a Series A raise. The lead investor's technical advisor had flagged concerns about data isolation between buyer and seller accounts and the absence of audit logging. The founding CTO needed a credible third-party assessment to address those concerns before the next partner meeting.

They gave us three weeks and full read access to the codebase, infrastructure, and AWS account.

Our approach

We ran a structured audit across four dimensions: application security (OWASP Top 10), data architecture, infrastructure posture, and engineering practices. We used a combination of static analysis, manual code review, and live infrastructure inspection.

We did not write any production code during the audit — our only deliverable was a written report.

The outcome

We surfaced 14 findings across three severity tiers. Three were rated high severity: an IDOR vulnerability in the seller API, missing row-level security on a shared DynamoDB table, and CloudTrail disabled in two regions.

All three were remediated by the client's engineering team within 10 days of receiving the report, guided by our remediation roadmap.

  • Zero critical or high findings remaining at the time of the Series A close
  • The audit report was shared directly with the investor's technical advisor
  • Client raised their Series A three weeks after remediation was complete
⚠

The IDOR vulnerability would have allowed any authenticated seller to read buyer contact details. It had been present in the codebase for 14 months.

"The audit was the most valuable three weeks of engineering spend we made that year."

— CTO, Marketplace client (name withheld)

Next case study

SaaS Platform MVP →

Project details

Industry
Marketplace
Duration
3 weeks
Team
1 senior engineer
Tech stack
  • AWS
  • Terraform
  • Node.js
  • Redis

Building something similar?

Book a 30-minute call to talk through your project.

Book a call
// 06.let_s_talk

Let’s ship the thing you’ve been meaning to ship.

Book a discovery call Apply for embedded
Studio
Services
Work
Process
Pricing
Office
About
Security
Legal
Contact
hello@theunnamed.dev
Book a call
Unnamed Development
©2026 The Unnamed Corp · us-east-1
Terms · Privacy · DPA