How CyVigilant Helped Convin.AI Fix 22 Security Vulnerabilities Across 30+ Enterprise Customer Environments
CyVigilant helped Convin.AI fix 22 security vulnerabilities across 30+ enterprise environments, remediating 100% of Critical findings through a black-box VAPT engagement.
Convin.AI is an AI-powered conversation intelligence platform. Enterprises use it to automate customer interactions through VoiceBots and conversational AI. Its production setup includes internet-facing APIs, cloud services, browser-based applications, and customer communication systems serving more than 30 enterprise customer tenants.
As the platform grew, several production assets went public without proper security controls. The team did not want another list of isolated issues. They wanted a real-world test that proved which attack paths an actual attacker could exploit.
CyVigilant ran a black-box VAPT engagement based on the OWASP Testing Guide v4.2 and the Penetration Testing Execution Standard (PTES). The scope covered production APIs, VoiceBot infrastructure, JavaScript bundles, cloud configurations, and publicly accessible services.
The work moved through four stages: reconnaissance, vulnerability assessment, exploitation, and reporting. Instead of listing issues one by one, the team showed how an attacker could chain them together in a real attack. Testing included JavaScript bundle analysis, endpoint enumeration, authentication bypass, Redis exposure checks, DNS reconnaissance, cloud configuration review, and CORS assessment. Every finding was manually validated with proof of exploitability. The full report, with remediation guidance for all 22 vulnerabilities, reached the team in 14 days.
The assessment confirmed several high-impact exposures. A public Redis instance exposed around 278,398 Redis keys. Anyone could read, modify, or delete application data without logging in. Client-side JavaScript bundles held production API keys, a Google Cloud private key, VoiceBot configuration files, and third-party service credentials. The estimated infrastructure abuse risk crossed USD 70,000 per month.
Several production APIs worked without authentication, opening access across 30+ enterprise customer tenants. CyVigilant also showed that campaign files with nearly 2,000 customer phone numbers, including records linked to a major Indian insurance enterprise, could be downloaded by anyone. Loose CORS settings added the risk of browser-based attacks and unauthorized cross-origin access. Together, these gaps formed a clear attack path to customer data, cloud resources, and enterprise systems.
Convin.AI fixed all 9 Critical vulnerabilities. Production credentials were rotated and removed from client-side code. Redis access was locked to trusted internal networks. Authentication was enforced on every exposed API. Sensitive download endpoints were secured, and CORS policies now use explicit allowlists. The engagement also improved Convin.AI's compliance position under the Digital Personal Data Protection (DPDP) Act, 2023 and GDPR Articles 32 and 33, cutting both operational and regulatory risk.
"CyVigilant showed us exactly how an attacker could chain multiple weaknesses together. Their assessment gave us a clear roadmap to eliminate the risks that mattered most before they became a real incident."
VP of Engineering, Convin.AI (Representative of post-assessment feedback, not a verbatim quote.)
Find what your scanners are missing.
Book a scoping call with an expert and get an exploit-led assessment of your own stack.
Talk to an Expert