Trust & Security

How we test Claify’s security, what we found, and what has been fixed.

5
findings
5
fixed
0
open
30 Sep
assessed, 2026

What we found

  • High

    Account and organisation deletion could be triggered from another website.

    The server now refuses write requests that come from another website.

    Fixed 30 Sep 2026

  • Medium

    Creating invoices, contacts and bank accounts could be triggered from another website.

    Same protection: write requests from other websites are refused.

    Fixed 30 Sep 2026

  • Medium

    Signing out could be triggered from another website.

    Same protection: write requests from other websites are refused.

    Fixed 30 Sep 2026

  • Informational

    An overly permissive cross-origin header and the framework version were exposed.

    The version header is removed and cross-origin access is limited to our own site.

    Fixed 30 Sep 2026

  • Informational

    The Content Security Policy allowed inline scripts.

    Scripts now need a one-time token issued for each page load. Inline styles are still allowed.

    Fixed 1 Oct 2026

What it covered

  • Sign-in, sign-up, password reset and Google sign-in
  • Session tokens and sign-in rate limiting
  • Separation between companies: one test company trying to read or change another’s data
  • Protection against requests forged from other websites
  • Server-side request forgery on the accounting connection and OAuth flows
  • Mass assignment, account enumeration, security headers and TLS

What it did not cover

We would rather say this than let the page suggest more than it shows.

  • The Maya AI assistant. It needs a paid plan, which the test accounts did not have.
  • Bank statement import. The test accounts had no upload surface.
  • Authenticated Xero and QuickBooks sync. Not reached in this assessment.
  • Concurrent invoice and billing actions. Not reached in this assessment.

How we tested

Target
claify.homeauto.sg
Method
Black-box test following the OWASP Web Security Testing Guide and the OWASP API Security Top 10.
Runs
Two deep scans on 30 September 2026: one without a login, and one with two throwaway company accounts to test separation between companies.
Test data
The two test accounts were created for the test and removed afterwards. No customer data was used.