Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All case studies
conversation intelligence / conversational AI

How CyVigilant Helped Convin.AI Fix 22 Security Vulnerabilities Across 30+ Enterprise Customer Environments

CyVigilant helped Convin.AI fix 22 security vulnerabilities across 30+ enterprise environments, remediating 100% of Critical findings through a black-box VAPT engagement.

100percent of Critical vulnerabilities remediated and retested
9 Critical13 High13 Medium13 Low
API Security TestingWeb Application VAPTCloud Security Assessment
The Challenge

Convin.AI is an AI-powered conversation intelligence platform. Enterprises use it to automate customer interactions through VoiceBots and conversational AI. Its production setup includes internet-facing APIs, cloud services, browser-based applications, and customer communication systems serving more than 30 enterprise customer tenants.

As the platform grew, several production assets went public without proper security controls. The team did not want another list of isolated issues. They wanted a real-world test that proved which attack paths an actual attacker could exploit.

Our Approach

CyVigilant ran a black-box VAPT engagement based on the OWASP Testing Guide v4.2 and the Penetration Testing Execution Standard (PTES). The scope covered production APIs, VoiceBot infrastructure, JavaScript bundles, cloud configurations, and publicly accessible services.

The work moved through four stages: reconnaissance, vulnerability assessment, exploitation, and reporting. Instead of listing issues one by one, the team showed how an attacker could chain them together in a real attack. Testing included JavaScript bundle analysis, endpoint enumeration, authentication bypass, Redis exposure checks, DNS reconnaissance, cloud configuration review, and CORS assessment. Every finding was manually validated with proof of exploitability. The full report, with remediation guidance for all 22 vulnerabilities, reached the team in 14 days.

Findings

The assessment confirmed several high-impact exposures. A public Redis instance exposed around 278,398 Redis keys. Anyone could read, modify, or delete application data without logging in. Client-side JavaScript bundles held production API keys, a Google Cloud private key, VoiceBot configuration files, and third-party service credentials. The estimated infrastructure abuse risk crossed USD 70,000 per month.

Several production APIs worked without authentication, opening access across 30+ enterprise customer tenants. CyVigilant also showed that campaign files with nearly 2,000 customer phone numbers, including records linked to a major Indian insurance enterprise, could be downloaded by anyone. Loose CORS settings added the risk of browser-based attacks and unauthorized cross-origin access. Together, these gaps formed a clear attack path to customer data, cloud resources, and enterprise systems.

Outcome

Convin.AI fixed all 9 Critical vulnerabilities. Production credentials were rotated and removed from client-side code. Redis access was locked to trusted internal networks. Authentication was enforced on every exposed API. Sensitive download endpoints were secured, and CORS policies now use explicit allowlists. The engagement also improved Convin.AI's compliance position under the Digital Personal Data Protection (DPDP) Act, 2023 and GDPR Articles 32 and 33, cutting both operational and regulatory risk.

"CyVigilant showed us exactly how an attacker could chain multiple weaknesses together. Their assessment gave us a clear roadmap to eliminate the risks that mattered most before they became a real incident."

VP of Engineering, Convin.AI (Representative of post-assessment feedback, not a verbatim quote.)

Results
2
vulnerabilities identified
9
Critical vulnerabilities remediated
30+
enterprise customer tenants secured
278,398
Redis keys protected
100
percent Critical findings remediated and retested
Get started

Find what your scanners are missing.

Book a scoping call with an expert and get an exploit-led assessment of your own stack.

Talk to an Expert