Skip to content

E-commerce security

The question isn't whether your store has a flaw — it's who finds it first.

Book an audit

10+ Brazilian stores with flaws found.

Simulation · fictional data
GET/api/account/profilerequest
{
"id": 1043
}
sending id…
200 OKresponse
{
}
Illustrative scenario with made-up data. One sequential ID — and the API returns another customer's entire life.

What we find

The flaws every store swears it doesn't have.

Not theory. It's what shows up, again and again, in the stores we audit.

Critical

Unauthenticated API

Internal endpoints returning data without asking for login — just call the URL.

Critical

SQL Injection

A mishandled input becomes a database command: data read, changed, or wiped.

Critical

Client-side token

An API key or integration token exposed in the site bundle, in plain sight.

How it works

One week. From first access to the fix.

Step 1We map the surface: site, app, APIs, integrations, and checkout.
Step 2Automated scanning + manual analysis, endpoint by endpoint.
Step 3Real exploitation — we prove what's actually exploitable, no false positives.
Step 4Executive + technical report, with severity, proof, and steps.
Step 5Critical flaws fixed — applied, not just flagged. Retest included.

Most pentests stop at the PDF. We're engineers: we deliver the report and fix what matters.

Investment

One price. One result.

From URL to a fixed report, in one week.

Scope agreed before we start. No downtime.

starting at

US$ 4,000

No High or Critical Finding = Don't Pay

  • Offensive audit focused on e-commerce
  • Executive + technical report, with proof of every flaw
  • Critical flaws fixed by our team
  • Retest to confirm they're closed
  • NDA and full confidentiality over the findings

Straight questions

The questions everyone asks

We fix it. A traditional pentest hands over a PDF and leaves — the problem stays in your store. deco is engineering: critical flaws come back fixed within the same week, with a retest to confirm.

No. We test in production carefully (or on staging, if you prefer), without disrupting the operation and without touching real customer data. Scope is agreed before we start.

We start as an external attacker, with just the URL — that's the real scenario. With access to code and infra, we go deeper (grey/white box) and find even more. You choose the level.

It's never happened in e-commerce — but if it does, you get a report attesting your security maturity and a hardening roadmap. You walk away knowing where you stand.

NDA signed before the first access. Findings, proof, and the report stay between your team and ours. Nothing is published, shared, or used as a case without your authorization.

Yes, because the scope is focused on e-commerce — it's not a generic audit of everything. We know where stores break and go straight for it.