Case Study - Continuous Security Testing (Every Deploy, Tested)
Friday 23:40 deploy introduced an admin bypass. Saturday 00:15 the pipeline had already blocked the rollout.
Client Context
Fintech lending — 40+ microservices, 15-20 deploys/week, OJK IT governance + ISO 27001 surveillance audit. Security was a pre-release gate that everyone hated (3-day queue).
Challenge
Point-in-time tests expired on merge. Need security testing on schedule and on change — fast enough for DevOps, rigorous enough for auditors — producing a living continuous security posture.
Scope - Snipeyes Continuous Security Testing
- Pipeline hooks (GitHub/GitLab/Jenkins): SAST pattern + SCA + API contract + dynamic checks on ephemeral staging
- Change-based full runs on infra/app diff; nightly baseline on production-readable surface (safe profile)
- Policy gates: block only on validated critical/high with owner + fix hint; everything else as ticket
- Output: continuous posture timeline — exposure and critical trend per service
Key Findings (redacted)
- Blocked pre-prod: Admin role assignable via
role=adminmass-assignment on signup v2 (caught 35 min after commit) - Trend: Auth-service criticals recurred 4x — traced to shared library pinned 9 months old
- Posture chart showed 60% services improving, 3 services deteriorating — focused sprint correctly
Outcome
- Gate time 3 days → 25 minutes; developers stopped bypassing security
- Zero criticals in production for 6 consecutive releases; audit evidence = pipeline logs + posture chart
- Library upgrade + contract tests eliminated the recurring class
Relevance for you: If “tested last quarter” is your answer — move to every-change testing.