Our work

Strengthening shipment security after an incident.

Understand the risk. Define the response. Build the controls.

Deprisa delivery trucks at the loading docks of its logistics hub.
The operation behind every shipment.Photo: Deprisa / Portafolio

The partnership

Following a security incident involving shipment tracking, Deprisa needed a technical response connected to the way its web and API services operate. We combined security assessment with API architecture and engineering, translating technical findings into a prioritized response and access controls for shipment information.

What we delivered

  • Web & API security assessment
  • Remediation planning
  • Identity integration
  • API security architecture
People wearing safety vests during a visit inside the Deprisa hub.
Inside the Deprisa hub.Photo: Deprisa
Two members of the Deprisa team working at computers.
The team at work.Photo: Deprisa

Outcomes & value created

An actionable view of risk

Automated testing and manual validation informed a focused set of findings and a prioritized remediation roadmap.

Verification in the service flow

The integration layer supports one-time-code delivery and verification before returning the associated shipment details.

Controls connected to operations

Managed secret access, configurable authentication, and request correlation bring identity and operational context into the same API architecture.

The challenge

After the incident, the priority was to translate security evidence into concrete changes to shipment access. The work needed to connect assessment evidence to the architecture, access model, and operational responsibilities behind the services.

  • Prioritize actionable findings through technical validation.
  • Distinguish basic shipment status from information requiring verification.
  • Keep security controls understandable for the team operating the services.

Secure by design.

Security response works better when the findings, the engineering changes, and the people operating the cloud share the same context.

Access with context.

Simplified architecture
Digital channels
  • Web
  • App
  • Partners
Microsoft Azure
Access controlsAPI ManagementAuthentication · API policies
Identity verification.NET BFFOne-time-code flow
Shipment information
  • Basic status
  • Verified details
Key VaultApplication InsightsDocker

The access model distinguishes a basic status request from information that needs identity verification.

The identity flow sends and verifies a one-time code before returning the associated shipment details.

A simplified view of the service architecture.

Technology & tools

  • Microsoft Azure
  • API Management
  • Key Vault
  • Managed Identity
  • .NET
  • Burp Suite

How we delivered the work

  1. Assess and validate

    We evaluated the web and API surface using automated security testing and manual validation. The assessment focused on actionable risks and the controls relevant to the environment.

  2. Prioritize the response

    We organized the findings into a remediation roadmap, connecting the most relevant access risks with service hardening and architectural improvements.

  3. Connect identity to the APIs

    We implemented identity-verification service flows in the backend-for-frontend and connected secret management, authentication configuration, and request tracing to the integration architecture.

Ready to stabilize and scale your cloud?

Start with a technical conversation about the infrastructure issues creating risk, instability, or friction for your team.

Talk to an expert