Trust & Security
How we test Claify’s security, what we found, and what has been fixed.
- 5
- findings
- 5
- fixed
- 0
- open
- 30 Sep
- assessed, 2026
What we found
- High
Account and organisation deletion could be triggered from another website.
The server now refuses write requests that come from another website.
Fixed 30 Sep 2026
- Medium
Creating invoices, contacts and bank accounts could be triggered from another website.
Same protection: write requests from other websites are refused.
Fixed 30 Sep 2026
- Medium
Signing out could be triggered from another website.
Same protection: write requests from other websites are refused.
Fixed 30 Sep 2026
- Informational
An overly permissive cross-origin header and the framework version were exposed.
The version header is removed and cross-origin access is limited to our own site.
Fixed 30 Sep 2026
- Informational
The Content Security Policy allowed inline scripts.
Scripts now need a one-time token issued for each page load. Inline styles are still allowed.
Fixed 1 Oct 2026
What it covered
- Sign-in, sign-up, password reset and Google sign-in
- Session tokens and sign-in rate limiting
- Separation between companies: one test company trying to read or change another’s data
- Protection against requests forged from other websites
- Server-side request forgery on the accounting connection and OAuth flows
- Mass assignment, account enumeration, security headers and TLS
What it did not cover
We would rather say this than let the page suggest more than it shows.
- The Maya AI assistant. It needs a paid plan, which the test accounts did not have.
- Bank statement import. The test accounts had no upload surface.
- Authenticated Xero and QuickBooks sync. Not reached in this assessment.
- Concurrent invoice and billing actions. Not reached in this assessment.
How we tested
- Target
- claify.homeauto.sg
- Method
- Black-box test following the OWASP Web Security Testing Guide and the OWASP API Security Top 10.
- Runs
- Two deep scans on 30 September 2026: one without a login, and one with two throwaway company accounts to test separation between companies.
- Test data
- The two test accounts were created for the test and removed afterwards. No customer data was used.