Case study

Building Confidence Through Independent Security Testing

FaiceTech wanted an independent assessment of its web application to provide greater confidence in its security and identify weaknesses that might not be apparent through its own development and testing processes.

Client FaiceTech Ltd Service Web Application Penetration Test Where Manchester, UK · Facial recognition & computer vision technology
FaiceTech Ltd logo

About FaiceTech

Founded in Manchester in 2019, FaiceTech is a privately funded UK company developing facial recognition technology designed to help keep people safe.

FaiceTech deploys computer vision solutions for businesses and public organisations that need to know exactly who is in their environment.

As a technology company handling sensitive applications and data, maintaining confidence in the security of its technology is an important part of protecting both its customers and its reputation.

The Challenge

FaiceTech wanted an independent assessment of its web application to provide greater confidence in its security and identify weaknesses that might not be apparent through its own development and testing processes.

The objective was not simply to run automated vulnerability scans. FaiceTech wanted experienced security professionals to actively investigate the application, challenge its security controls and look for weaknesses from an attacker’s perspective.

The resulting report also needed to be clear, professional and useful beyond the technical team, providing documentation that FaiceTech could use internally and share with its customers where appropriate.

Our Approach

Plainsight Security conducted a manual web application penetration test, combining established security testing methodologies with hands-on investigation of the application’s functionality and attack surface.

Testing included areas such as:

  • Authentication and authorisation controls
  • Access control and tenant isolation
  • Input validation and application security
  • File upload functionality
  • Information disclosure
  • Application error handling
  • Data exposure
  • Common web application attack vectors

Where potential weaknesses were identified, we investigated them further to understand their real-world impact rather than relying solely on automated tool output.

This approach allowed us to test the application from an attacker’s perspective and identify areas that required further attention.

The Results

The assessment provided FaiceTech with a detailed understanding of the security of its application, including areas where security controls could be strengthened.

Importantly, the engagement also provided the FaiceTech team with additional insight into how their application could be approached and attacked in ways they had not previously considered.

The findings were documented in a clear and actionable report, giving the team the information needed to understand the issues, assess their significance and plan appropriate remediation.

The assessment therefore delivered value beyond simply identifying technical vulnerabilities. It provided independent assurance, practical learning and evidence of FaiceTech’s commitment to security.

The Client’s Experience

Chris Noden of FaiceTech described the engagement as:

“End to end a very smooth and well-explained process.”

He added:

“It has provided the necessary confidence internally; and as solid documentation we can share with our clients.”

And, reflecting on the depth of the assessment:

“Plainsight are clearly experienced and dug into our system in ways we never envisaged - I'm delighted with the output and learning.”

The Outcome

For FaiceTech, the penetration test delivered more than a technical report.

It provided:

Greater internal confidence
Independent testing gave FaiceTech additional assurance around the security of its application.

Practical security insight
The assessment identified areas for improvement and provided learning that could be fed back into the development process.

Professional security documentation
The resulting report provided evidence that could be retained internally and shared with customers where appropriate.

An independent perspective
Experienced penetration testing provided a fresh perspective on the application’s security and investigated attack paths that might not be considered during normal development and testing.

100% Client Satisfaction

Following the engagement, FaiceTech rated Plainsight Security 5/5 across every area of the assessment, including:

  • Professionalism and conduct
  • Technical quality
  • Communication
  • Timeliness
  • Clarity and usefulness of reporting
  • Overall satisfaction
  • Likelihood of recommending Plainsight Security

The Result

5/5
Technical quality

5/5
Communication

5/5
Reporting

5/5
Overall satisfaction

Independent Testing. Real Security Insight.

A penetration test should be more than a list of vulnerabilities.

At Plainsight Security, we combine technical expertise with manual investigation to understand how an application could actually be attacked, explain the risks clearly and provide practical information that organisations can use to improve their security.

For FaiceTech, that meant an assessment that delivered not only technical findings, but confidence, learning and professional documentation they could take forward with their customers.

Need independent assurance of your web application’s security?

Contact Plainsight Security to discuss your requirements.

“Plainsight are clearly experienced and dug into our system in ways we never envisaged - I'm delighted with the output and learning.”

Chris Noden, FaiceTech
In their words

How FaiceTech Ltd rated the engagement

5/5
Technical quality
5/5
Communication
5/5
Reporting
5/5
Overall satisfaction
Talk to a tester

Want results like this?

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All case studies