Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All case studies
Generative AI & Sovereign AI Infrastructure

How Does CyVigilant help Sarvam AI Identify 47 Vulnerabilities Across 3 Environments & 40+ Subdomains in 3 Days?

Sarvam AI, one of India's leading enterprise AI platforms, engaged CyVigilant for a black-box VAPT of its production, staging, and QA environments as its external footprint scaled. The platform had never faced a full external assessment. In three days, expert-led testing mapped 8 domains and more than 40 subdomains, surfaced 47 vulnerabilities, and validated five real-world attack paths that ran from publicly exposed data straight into critical infrastructure.

47Vulnerabilities found in 3 days
14 Critical13 High1 Medium8 Low
Black-Box VAPTAPI SecurityInfrastructure Security Review
The Challenge

Sarvam AI's platform spans Azure Front Door, Kong API Gateway, Google Kubernetes Engine, and separate production, staging (azure-stage01), QA (azure-qa01), and Agrimin clusters. These systems ran real enterprise workloads for customers like Tata Capital, Urban Company, and Vedantu, yet the full external attack surface had never been tested end to end. The security team needed independent, real-world validation of what an outside attacker could actually reach, not another scanner report listing issues in isolation.

Our Approach

CyVigilant ran a controlled, authorised black-box VAPT between 11 and 13 February 2026, using methodologies aligned with OWASP WSTG v4.2, OWASP API Security Top 10:2023, OWASP Top 10:2021, and CWE/SANS Top 25. The engagement moved through five stages:

Reconnaissance and external attack-surface mapping

Authentication and authorisation testing

API security testing

JavaScript configuration and frontend analysis

Business logic validation and exploit-chain verification

Rather than flag issues in isolation, every finding was validated with a safe, controlled proof-of-concept and, where relevant, chained to show real attacker impact.

Findings

Testing confirmed a set of high-impact exposures that a routine scan would miss:

Exposed Metabase admin tokens. Two Metabase instances in staging and QA exposed active administrator setup tokens accessible without authentication, opening a path to administrative database access across 17 connected database engines.

Leaking Flagsmith feature flags. Feature flags embedded in frontend JavaScript were publicly readable and writable using environment keys, exposing customer identifiers, employee email addresses, internal model references, telephony configuration, and OAuth client information.

Publicly reachable infrastructure services. ArgoCD, HashiCorp Vault, and the ClickHouse Play UI were accessible from the public internet, widening exposure of deployment and secrets-management systems.

Unmasked PostHog session recording. Session recording ran without input masking, allowing sensitive inputs such as passwords and API keys to be captured during recorded sessions.

Exposed Terraform repository. A public GitHub Terraform repository leaked infrastructure detail, including Azure resource group names, ClickHouse IP addresses, and the Agrimin subdomain inventory.

Chained together, these weaknesses created a realistic path from publicly available configuration data to internal infrastructure and administrative access.

Outcome

CyVigilant delivered a prioritised, engineering-ready remediation roadmap. Every finding carried a CVSS v3.1 score, was mapped to the relevant OWASP category, and was ranked by business impact so the team could close the highest-risk issues first. Beyond the individual fixes, the engagement reset how Sarvam AI approaches environment isolation and secrets management across staging, QA, and production.

The findings also carried regulatory weight under the Digital Personal Data Protection Act, 2023 and GDPR Article 33, making early remediation a compliance priority as well as a security one.

"CyVigilant's report showed us exactly how our staging and QA environments, which we assumed were low risk, could become the entry point to critical infrastructure. The Metabase and Flagsmith findings fundamentally changed how we approach environment isolation and secrets management."
— Head of Infrastructure, Sarvam AI

Results
47
Vulnerabilities identified
14
Critical findings
5
Attack chains validated
3
Days to full attack-surface visibility
Get started

Find what your scanners are missing.

Book a scoping call with an expert and get an exploit-led assessment of your own stack.

Talk to an Expert