Atleta
Improving SaaS security through penetration testing
Technology, Information and Internet I Netherlands I Penetration Testing I 1 month engagement (Feb – Mar 2025)

The Clients
- Industry:
- Technology, Information and Internet
- Location:
- Netherlands
- Delivery model:
- Project-based
- Duration:
- 1 month
- Support areas:
-
Validate authentication layers + identify vulnerabilities - Platform context:
-
The #1 tool for organizing sports events, from registration to bib numbers.
The challenge
To validate whether existing security measures were effective, while also testing a newly implemented authentication layer:
• Improving the overall security posture of their SaaS software
• Testing a new authentication layer
• Verifying existing security measures to uncover potential vulnerabilities
Dealing with a similar setup? Let’s discuss your requirements.
What the client needed
Atleta needed an independent security assessment to validate its platform, test a new authentication layer, and uncover hidden vulnerabilities.
A stronger security baseline
Assess the SaaS platform to understand its current security posture and identify areas requiring attention.
Validation of a new authentication layer
Test the newly implemented authentication mechanism against potential attack scenarios and weaknesses.
Visibility into hidden vulnerabilities
Go beyond existing controls to uncover security issues that may not have been identified internally.
Clear remediation priorities
Turn security findings into actionable priorities the team could use to plan remediation.
What Sunbytes Delivered
Sunbytes conducted a focused penetration testing engagement to identify, assess, and prioritize security vulnerabilities across Atleta’s platform.
Manual & automated penetration testing
Combined hands-on testing with automated tools to uncover vulnerabilities beyond surface-level scanning.Authentication & application security testing
Tested key application and authentication controls against realistic attack scenarios.Vulnerability analysis & prioritization
Classified identified issues by severity, impact, and exploitability to support remediation decisions.Security reporting & follow-up guidance
Delivered documented findings, actionable recommendations, and follow-up support for remediation and retesting.
Want to see if the fit is right for your team?
Why teams choose Sunbytes
A Netherlands-led partner that connects security evidence, delivery capability, and operational follow-through
ISO 27001-certified ISMS
Sunbytes operates an ISO 27001-certified ISMS, so information handling and access control have documented governance behind them.
Evidence-first security work
Security recommendations are mapped to evidence, ownership, and next actions so buyers and auditors can review what changed.
Dutch-led communication
European stakeholders get direct scope alignment, clear escalation paths, and accountable follow-up from a Dutch-led team.
Delivery-aware remediation
Security findings can be translated into software, infrastructure, and process changes through Sunbytes delivery capability.
Continuous security route
Baseline, readiness, specialist services, and CyberCare can connect without restarting context at every new request.
One operating partner
Secure work can align with delivery teams and people operations when access, onboarding, or governance affects the control environment.
What the team covered
The engagement covered the full assessment cycle, from security testing to findings, reporting, and follow-up.
Security testing across the SaaS platform
Combined manual and automated techniques to simulate realistic attack scenarios and identify vulnerabilities.Authentication layer validation
Tested the new authentication mechanism for weaknesses, reliability, and resistance to potential attacks.Vulnerability analysis & prioritization
Reviewed identified issues based on severity, impact, and exploitability to support remediation decisions.Security reporting & recommendations
Documented findings, potential risks, and practical recommendations in a structured assessment report.Post-assessment consultation & retesting
Reviewed findings with the client and supported remediation planning, retesting, and follow-up where needed.
Outcomes
The assessment resulted in:
In their words
“We were impressed by the vulnerabilities that were discovered. We can tell that the pentesters digged deep to discover the vulnerabilities, and not just a surface scan”.
Jarno van Leeuwen
Co-Founder, Atleta
See also
Download the full case study!
Get the complete story—challenge, delivery setup, scope, outcomes, and the full testimonial.















