success case

Base de Clientes

Base de Clientes already had continuous security practices in place, including periodic code reviews, automated testing, and authorization and scope validation. To complement these efforts with an independent offensive perspective, the company conducted its first penetration test using Conviso's AI-powered Autonomous Pentest. In the very first execution, two findings were identified, allowing them to be fixed before any exploitation could occur in production.

With Conviso's AI-powered Autonomous Pentest, Base de Clientes identified two vulnerabilities in its first execution—one of them had existed since the product's launch and was identified before anyone could exploit it in production.

15min

to configure the first test

1st

experience company's pentesting

Critical finding

identified proactively

13

successful exploitations performed

Issue identified before

any real-world exploitation
A vulnerability in the customer portal was identified during the pentest and remediated proactively before it could be exploited.

Fast setup
Using the platform's built-in templates, the pentest was configured and running in less than 15 minutes. The execution could also be scheduled to run at the most convenient time for the company.

Product decision driven by pentest findings
One of the findings identified served as the basis for a business decision made by the team.

Pentest Autonomous Pentest with AI

Run real-world attack simulations, identify vulnerabilities, and receive a severity-prioritized list of findings, complete with technical evidence, proof of concept, documented attack chains, and a full history for continuous retesting.

The same solution used by Abler, which can integrate directly into your company’s development lifecycle.

Talk to our experts

The challenge

The company's security practices were already mature for its stage of growth, including regular code reviews, API authorization and privilege validation, and automated tests to ensure data was not improperly exposed across different user roles.

What was missing was an offensive assessment from an external perspective—one that could go beyond what the internal team was able to identify and test less obvious attack paths, such as the generic customer portal used by companies that chose not to customize their own interface.

Main areas of concern

Our security strategy was based on regular code reviews and automated testing. The pentest provided a complementary offensive perspective that we didn't have before.

Igor Nichele

The pentest journey with Conviso

Base de Clientes conducted its first penetration test using Conviso's Autonomous AI Pentest, across two execution rounds. Setup was fast: using the platform's built-in templates, the assessment was ready to run in approximately 15 minutes, without requiring a large amount of technical configuration.

The assessment focused on the customer portal and the platform's APIs, covering authentication, authorization, and access flows across different user profiles.

The engagement included:

AI-powered API penetration testing
Authentication and authorization testing
Customer portal vulnerability assessment
Report with proof of concept
Remediation guidance for every finding

A atuação contemplou:

Pentest com IA nas APIs
Exploração lógica de vulnerabilidades
Remediação guiada pela plataforma
Análise de dependências desatualizadas
Integração ao pipeline de CI/CD

Differentiators recognized by Base de Clientes

1

Complete visibility into what is being tested

In Igor's previous experience at another company, a large customer conducted a penetration test and simply delivered the final report without any visibility into the process. With the Conviso Platform, things were different. Igor defined the testing scope, watched the attack flow in real time, and reviewed every finding with full context.

This level of transparency changed how the team viewed the entire process. Instead of treating penetration testing as a black-box service, it became a tool the team could operate and fully understand.

It was really great to watch everything happening in real time. Afterwards, you can review exactly what was tested, which is much easier than getting a long list of findings and going through them one by one.

Igor Nichele

2

Contextualizing findings with business logic

Not every pentest finding represents a vulnerability that needs to be fixed. Some reflect intentional product decisions or known system limitations. Igor highlighted that the Conviso Platform allows every finding to be classified and documented with business context, clearly distinguishing intentional design decisions from real security exposures.

This prevents the team from wasting time investigating false positives and ensures their efforts remain focused on fixing what truly matters.

Sometimes it points out something that's actually a limitation we already know about. You can classify it and say: This is a known business limitation. We're aware of it—it was designed this way.

Igor Nichele

3

Reports detailed enough to accelerate remediation

For every finding, the report clearly described what had been discovered, how the AI identified the issue, and how it could be remediated. The level of detail exceeded expectations. Igor was even able to feed the report directly into an AI assistant to discuss remediation strategies without first having to investigate the root cause manually.

A report that can immediately serve as input for another tool without additional work is a strong indicator of completeness.

The report was so complete that I could simply feed it into an AI and discuss the remediation. It was much easier than trying to investigate everything from scratch. It made the whole process a lot easier.

Igor Nichele

4

A tool for the engineering team's workflow

Today, Base de Clientes' CTO views penetration testing not as part of every CI/CD pipeline execution, but as an essential safeguard for high-impact releases—major stack migrations, significant version upgrades, or large-scale application rewrites.

This demonstrates a mature security strategy while leveraging the strengths of AI-powered offensive security: covering what internal reviews may miss while providing complete attack-chain visibility and actionable evidence for engineering teams.

We'll run it at the beginning of the year, whenever we rewrite major parts of the platform, or when we migrate to a new stack. Those are the moments when issues can slip in without anyone noticing.

Igor Nichele

Results Achieved

The most significant finding identified during the pentest was a vulnerability in the generic customer portal that had not been detected by internal security validations. The issue was identified before any exploitation in production, allowing the team to take preventive action.

After reviewing access logs and confirming there was no evidence of exploitation, Base de Clientes decided to evolve the solution’s architecture. The generic portal was discontinued, and today, all customers use their own domains or customized subdomains on the platform.

The pentest uncovered an issue that hadn't been detected by our internal security validations. We were able to fix it quickly and even improve the architecture of the solution.

Igor Nichele

Learn more about our AI-powered pentesting service