Building state-of-the-art VDR security for online document storage and integrating it seamlessly into mobile apps.
Building ironclad data security for M&A solution leader

Overview
In the mergers and acquisitions (M&A) world, everything at the desk must be clear and secure across the entire deal process. That is why [REDACTED], a leading SaaS provider for the M&A industry, chose Cossack Labs for their ironclad data security.
[REDACTED] has a half-century history and sets a world-class standard for market leaders in deal data management. They used their extensive experience to revolutionize the M&A lifecycle with data security in mind.
Industry
- M&A SaaS provider
- VDR
Technology stack
- iOS, Android native mobile apps
- React Native apps
- Azure cloud
Regulations
- CCPA, GDPR
- Internal security policies
- Encryption Export
Regulations
Challenges
The Customer has a rich virtual data room (VDR) service, which works as secure online storage for processing M&A documents and interacting with legal teams. Pioneering the trend of critical exchanges getting virtual and moving to the cloud, they created web and mobile applications to work with documents from anywhere in the world.
Adding a new application that works with sensitive data means adding new threat vectors and expanding attack surfaces. The Customer's team was looking for security engineers that could help build state-of-the-art document security and integrate it seamlessly into mobile apps, so they reached out to Cossack Labs.
Technology requirements

Mitigate mobile-specific threats
Follow constantly changing mobile security guidelines
Security that doesn't ruin UI/UX
Our approach
Our approach
Prevent data leakage without affecting legitimate users
At the same time, from the Customer clients' perspective, the security measures shouldn't interrupt access to the documents while providing appropriately managed access to their sensitive data.
We had to cover challenges from both sides.
Improve security release-to-release

Solution
- Based on risks and threats assessment, we aligned mobile apps security strategy with the Customer's Security Strategy and Information Security Policy.
- We have set up a stable SSDLC process during which we built data security layer and security defences against reverse-engineering. We assisted in protecting API and fixing vulnerabilities, provided ongoing security verification, tutored developers, and much more.
- Under our security guidance, the development team worked together with us on designing, implementing product features with security in mind, and security features with UX in mind.
- For extended data protection, we designed and implemented a cryptographic layer based on the free open-source cryptographic library Themis that provides a single API across programming languages while hiding cryptographic details under the hood.
- Aside from the relevant privacy, healthcare, and corporate regulations, the following security standards were applied: OWASP MASVS 1.3 L2, Apple platform security, Android app security best practices, US Encryption Export Regulations.
Additional relevant materials

Results and outcomes
During several years of engagement, and multiple rewrites of the app itself, we have set up a stable SSDLC process during which we built many mobile-specific security controls, data security layer, security defences against reverse-engineering, assisted in protecting API and fixing vulnerabilities, provided ongoing security verification, tutored developers, and much more.
For extended data protection, we designed and implemented a cryptographic layer based on the free open-source cryptographic library Themis that provides a single API across programming languages while hiding cryptographic details under the hood.
Got a challenge that's still standing?
Let’s start a conversation.

