Matomo

Building ironclad data security for M&A solution leader | Cossack Labs
Case studies
Building ironclad data security for M&A solution leader

Building ironclad data security for M&A solution leader

2018 - 2021 SaaS Virtual Data Room Cloud data security
Building ironclad data security for M&A solution leader

Overview

Industry

  • M&A SaaS provider
  • VDR

Technology stack

  • iOS, Android native mobile apps
  • React Native apps
  • Azure cloud

Regulations

  • CCPA, GDPR
  • Internal security policies
  • Encryption Export
    Regulations

Challenges

[01]

Building state-of-the-art VDR security for online document storage and integrating it seamlessly into mobile apps.

[02]

The Customer has a rich virtual data room (VDR) service, which works as secure online storage for processing M&A documents and interacting with legal teams. Pioneering the trend of critical exchanges getting virtual and moving to the cloud, they created web and mobile applications to work with documents from anywhere in the world.

[03]

Adding a new application that works with sensitive data means adding new threat vectors and expanding attack surfaces. The Customer's team was looking for security engineers that could help build state-of-the-art document security and integrate it seamlessly into mobile apps, so they reached out to Cossack Labs.

Technology requirements

Technology requirements

Mitigate mobile-specific threats

As mobile apps introduce new attack vectors, implemented security measures should successfully mitigate them and instil confidence in online deals for Customers' users.

Follow constantly changing mobile security guidelines

Mobile apps security controls should be in line with industry practice, be easy to maintain and update in the changing threat landscape.

Security that doesn't ruin UI/UX

Security measures should not break user experience for legitimate users, but render applications unusable for potentially malicious users.

Our approach

Prevent data leakage without affecting legitimate users

From the Customer's business perspective, the security goals were to prevent leakage and tampering of customer's sensitive data (documents, PII), unauthorized document access, and getting unauthorized party access to functionality and accounts.

At the same time, from the Customer clients' perspective, the security measures shouldn't interrupt access to the documents while providing appropriately managed access to their sensitive data.

We had to cover challenges from both sides.

Improve security release-to-release

Understanding their risk posture and UX requirements, we were introducing security measures one by one, firmly improving the application month-by-month.
Our approach

Solution

Additional relevant materials

Results and outcomes

During several years of engagement, and multiple rewrites of the app itself, we have set up a stable SSDLC process during which we built many mobile-specific security controls, data security layer, security defences against reverse-engineering, assisted in protecting API and fixing vulnerabilities, provided ongoing security verification, tutored developers, and much more.

For extended data protection, we designed and implemented a cryptographic layer based on the free open-source cryptographic library Themis that provides a single API across programming languages while hiding cryptographic details under the hood.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days