Workflow and actors
With product, engineering and ERP and business owners, we trace the quoting tool, portal or agent from input to write, review controls, reproduce findings, and agree priority, remediation and retest.
You shipped an AI quoting tool on Cursor, a customer portal on v0 or an order assistant on Lovable. We audit before one customer sees what you priced for another, or before an ERP token leaks.
The workflows, examples and figures on this page are illustrative composites and modelled targets, not measured client results. In a real project, we define the baseline, thresholds and human review with your data before rollout.
Every B2B customer has their price, their discount, their payment terms, their reserved stock. The AI tools your team built (quoting tools, customer portals, order assistants) handle all of that. When the ownership filter fails, Customer Small can see the price you charge Customer Large. An external audit catches it before your sales team does.
We audit what your team built through the sector lens: strict isolation between customer accounts, custody of ERP tokens, exposure of cost and margin data, and the spots where an AI agent has more permissions on your ERP than it should.
With product, engineering and ERP and business owners, we trace the quoting tool, portal or agent from input to write, review controls, reproduce findings, and agree priority, remediation and retest.
Scope may cover code, APIs, authentication, database queries and policies, secrets, logs and ERP connectors handling accounts, prices, discounts, cost, margin and inventory.
We avoid using real data or writing to production where a controlled environment is enough. An exposed secret or cross-account leak is reported immediately so it can be contained before the audit continues.
The business owner validates commercial impact and account boundaries; engineering approves the remediation. We only close a finding once the fix has passed a reproducible verification.
We start with a threat model and combine manual code review, authorisation and tenant checks, API testing and permission analysis. The report separates evidence, risk, remediation and acceptance criteria.
We review the connectors and scopes the application actually uses in SAP, Holded, Odoo, Sage, Dynamics or another ERP; naming a vendor does not imply access to or coverage of modules outside scope.
The target design limits each customer to their own prices, discounts and payment terms. We verify the control at the SQL layer, not just the UI, and across the public APIs exposed by the quoting tool or portal.
Tokens to SAP, Holded, Odoo, Sage, Microsoft Dynamics. What the agent can read, what it can write, what it should never touch (chart of accounts, master agreements, vendor data). Explicit deny.
Quoting endpoints returning internal stock, vendor cost or computed margin in responses customers can inspect. What the UI hides, the API sometimes reveals.
If your group runs multiple legal entities, brands or channels (wholesale vs. retail), we audit that a Channel-B customer can't reach Channel-A data by changing a subdomain or tenant ID.
Modelled risk to test: the interface might show each customer their catalogue while the query reads the full catalogue by customer_id and filters only in the UI, exposing other accounts' prices through DevTools. The Holded integration could also use a token with write access to chart-of-accounts entries outside its intended scope.
Modelled illustrative outcome: an audit could identify 14 findings and prioritise 4 criticals: an ownership filter in SQL, responses without cost or margin, a minimum-permission Holded token and a policy preventing full orders from reaching external logs. The remaining 10 would be documented with priority, deadline and owner.
Enterprise CRM with fine-grained permissions, AI workflows that respect the data model.
Enterprise CRM/ERP suite in the Microsoft ecosystem, native fit with 365 and Power Platform.
Reference ERP for mid-market distribution and manufacturing, document extraction and ops orchestration.
Spanish cloud ERP widely adopted by SMBs, invoicing, expenses and reconciliation automation.
Modular open-source ERP, AI agents and workflows on top of sales, inventory and project modules.
Email, calendar and SharePoint as channel and context, triage, drafting and RAG over your inbox and files.
Under NDA, with read-only repository access. We don't copy real commercial data. If the audit needs to probe a real flow, we use test accounts your team sets up in staging.
Yes. We audit the connector: which token it uses, which objects it can read, which it can write, how it tells apart environments (sandbox vs production), how it handles errors and retries. If the connector writes to chart-of-accounts or stock, we read closely what stops it from writing when it shouldn't.
We audit quoting flows and API responses for price-exposure risk. It isn't real-time monitoring, which is a separate service, but the report prioritises controls that reduce the risk and explains how to look for historical evidence of exposure.
Yes, and it's usually where the most findings cluster. B2B multi-tenant mixes legal entities, subdomains, shared tables and overlapping pricing rules. We map every boundary and verify the code respects it, not just the documentation.
At intake we agree scope, environments and owners. We combine static review with dynamic tests in staging using synthetic accounts across the quoting tool, tenant boundaries and ERP permissions; the report prioritises findings and assigns each remediation to an owner on your team. We then retest corrected controls, and the distributor's designated owner accepts closure against the agreed criteria.
We design for privacy from the start, human control, traceability, usage limits, permissioning and documentation. For sensitive processes, we help assess risk and applicable obligations under GDPR and the EU AI Act.
Every engagement is led personally by one of the partners. If there's a fit, you get a personal first read of your case within one business day, not a canned demo.