Client area audit
As soon as a site gives each client their own access, one question truly matters: can one client reach another client's data? FastSolve tests your protected areas from the inside to make sure the answer is no.
This test is carried out with accounts you provide, written authorisation and a perimeter defined together. Nothing is attempted on real client accounts.
This service is billed on an accepted quote. An audit delivers findings, not a tool: the usual rule, test before paying, cannot apply here. The quote states in advance what it covers and how far the analysis goes.
The flaw that does the most damage
A brochure page going down is annoying. One client reading another's file is a data breach, and that is no longer your risk but theirs.
- Changing a number in an address shows another client's document, because the site checks identity but not the right to access.
- A poorly protected session can be replayed or stolen, and you end up logged in as someone else.
- Roles all look alike: a basic account reaches restricted screens, for lack of real separation.
- Password reset lets someone guess who has an account, or take control of it.
These flaws are invisible when browsing normally. They are found by stepping into the shoes of a curious client, then a malicious one.
What the audit covers
The test focuses on what protects, or fails to protect, your clients' data from one another.
1. Data separation
Account in hand, we check that no manipulation of an address, an identifier or a parameter grants access to another user's content.
Typical case. In a billing area, incrementing a number showed the previous client's invoice. The fix was to check the owner on every access, not just the identity.
2. Sessions
Token robustness, expiry, behaviour on logout, cookie scope: we make sure a session cannot be stolen or unduly extended.
Typical case. A session cookie was valid across a whole domain, including less secure environments. Restricting its scope closed the path to session theft.
3. Roles and permissions
We check that each role sees what concerns it and nothing more, and that an ordinary account cannot reach an administration feature.
Typical case. An administration address remained reachable by a basic account that knew it. A server-side role check restored the separation.
4. Sign-in and account recovery
Resistance to brute force, messages that do not reveal whether an account exists, a safe forgotten-password process: the front door deserves as much attention as the inside.
Typical case. A form clearly indicated when the identifier existed, which made targeting easier. A neutral message and an attempt limit cut off that involuntary help.
What this audit does not cover
It focuses on the protected area and its accounts. It does not claim to replace a full examination of the site.
- It does not replace the general site audit, which also looks at the public part, the configuration and exposed files. The two complement each other.
- It does not fix the flaws found: securing is a separate service, which FastSolve also provides.
- It holds for the state of the day. Adding a role or a feature later warrants a new check.
- It does not replace an official certification if your sector requires one.
We would rather scope a precise test and carry it out thoroughly than skim over everything without really checking anything.
Frequently asked questions
Do you need access to my clients' data?
No. The test uses accounts you create for the occasion, containing fictitious data. We never need to see real personal data to check separation.
Is it risky for existing accounts?
No. No real account is targeted, no data is changed. Attempts are made on the test accounts provided, non-destructively.
Do you need to have built the client area?
No. We also audit areas built by others, with your written authorisation and test accounts. That is often where an outside eye brings the most.
What happens if you find a serious flaw?
We warn you without delay, even before the final report, with the steps to close it quickly. A breach of clients' data does not wait.
How much does it cost?
The price depends on the number of roles, data types and journeys to test. A single-role area and a multi-profile platform do not have the same surface. The quote follows the scoping. As a guide, excluding VAT, most client area audits fall between 900 and 2,500 euros. A platform with several profiles can reach 3,000 euros.
Tell us what your clients should never see
See how a project unfolds, from scoping to delivery
See all FastSolve services