C2C Platform

Web, API and mobile penetration testing for IPO security readiness

Information technology I Japan I Penetration Testing I One-month engagement

Web, API and mobile penetration testing
C2C challenge I Sunbytes Success Story

C2C Platform needed a penetration testing partner that could assess its product across multiple layers and turn the findings into clear remediation and audit-ready evidence.

End-to-end testing I Sunbytes Success Story

Multi-layer testing

Assess security across web, API, iOS, and Android applications.

Assessment I Sunbytes Success Story

OWASP-aligned assessment

Evaluate relevant risks against OWASP Top 10 and API Top 10.

Rating I Sunbytes Success Story

Clear prioritization

Rate findings by severity so the team knew what to address first.

Follow rules I Sunbytes Success Story

Reproducible findings

Provide clear steps so developers could verify each identified issue.

Remediation I Sunbytes Success Story

Remediation guidance

Give practical recommendations the engineering team could act on directly.

IPO audit I Sunbytes Success Story

IPO audit support

Structure findings and documentation to support IPO security audit preparation.

Sunbytes conducted a focused penetration testing engagement in a dedicated test environment, covering C2C Platform’s web, API, iOS, and Android applications.

API pentest I Sunbytes Success Story
  • Web & API penetration testing

    Web application and API security testing

    Tested the web application and API layer to identify exploitable weaknesses across key application flows and interfaces.
  • iOS & Android application testing

    iOS and Android application testing

    Assessed both mobile applications for security issues across authentication, data handling, and application behavior.
  • OWASP I Sunbytes Success Story

    OWASP-aligned security assessment

    Evaluated findings against relevant OWASP Top 10 and OWASP API Security Top 10 risk categories.
  • Report vulnerabilities I Sunbytes Success Story

    Reproducible findings & evidence

    Documented each identified vulnerability with clear severity ratings and reproduction steps for the engineering team.
  • Rating priorities I Sunbytes Success Story

    Prioritized remediation guidance

    Provided practical recommendations and clear priorities to help developers address the identified findings efficiently.
  • Delivery timing I Sunbytes Success Story

    IPO audit reporting support

    Adapted the reporting format and delivery coordination to support C2C Platform’s IPO security audit preparation.

Want to see if the fit is right for your team?

Why teams choose Sunbytes

A Netherlands-led partner that connects security evidence, delivery capability, and operational follow-through

ISO 27001-certified ISMS

Sunbytes operates an ISO 27001-certified ISMS, so information handling and access control have documented governance behind them.

Evidence-first security work

Security recommendations are mapped to evidence, ownership, and next actions so buyers and auditors can review what changed.

Dutch-led communication

European stakeholders get direct scope alignment, clear escalation paths, and accountable follow-up from a Dutch-led team.

Delivery-aware remediation

Security findings can be translated into software, infrastructure, and process changes through Sunbytes delivery capability.

Continuous security route

Baseline, readiness, specialist services, and CyberCare can connect without restarting context at every new request.

One operating partner

Secure work can align with delivery teams and people operations when access, onboarding, or governance affects the control environment.

The penetration testing engagement covered the full assessment cycle, from application testing and vulnerability validation to remediation guidance and audit support.

C2C solutions I Sunbytes Success Story
  • Web app security I Sunbytes Success Story

    Web application & API security

    Assessed the web and API layers for exploitable vulnerabilities across key application flows, interfaces, and exposed functionality.
  • Mobile Security I Sunbytes Success Story

    iOS & Android application security

    Tested both mobile applications for security weaknesses affecting authentication, data handling, and application behavior.
  • Risks I Sunbytes Success Story

    OWASP Top 10 and API Top 10 risk assessment

    Mapped testing and identified risks against relevant OWASP Top 10 and OWASP API Security Top 10 categories.
  • Vulnerability I Sunbytes Success Story

    Vulnerability validation and severity classification

    Validated each identified issue and assigned a severity rating to help the client understand impact and remediation priority.
  • Instruction I Sunbytes Success Story

    Reproduction instructions for identified findings

    Documented clear reproduction steps so C2C’s engineering team could verify and investigate each vulnerability.
  • Guidance I Sunbytes Success Story

    Prioritized remediation guidance

    Provided practical recommendations for each finding, helping the team address the most important security issues first.
  • Audit support I Sunbytes Success Story

    Audit-oriented reporting and clarification support

    Structured the findings for IPO security audit preparation and supported the client with clarification of technical issues and reporting needs.
  • Findings identified I Sunbytes Success Story

    Comprehensive findings documented

    All vulnerabilities identified during the assessment were documented across the web, API, iOS, and Android layers with clear severity ratings.

  • KPIs planning I Sunbytes Success Story

    All identified findings remediated

    C2C Platform completed remediation of all identified findings using the report’s prioritized guidance and reproduction details.

  • IPO security audit I Sunbytes Success Story

    IPO security audit preparation supported

    The final report and follow-up clarification gave the team structured security evidence to support its IPO security audit preparation.

C2C testimonials I Sunbytes Success Story

In their words

“They provided practical, prioritized remediation guidance that our team could act on immediately.”

Yoshiyuki Saigusa
CTO, C2C Platform Co., Ltd.

See also

  • DevSecOps and NIS2: what Dutch companies must do before July 2026

    DevSecOps NIS2 readiness means proving that your software development process has working security controls, not just written policies. Before July 2026, Dutch companies in scope for the Cyberbeveiligingswet need evidence for Article 21 controls such as secure development, supply chain security, access management and effectiveness testing. For engineering teams, the practical evidence usually comes from […]

  • NIS2 penetration testing requirements: what Article 21(2) compliance looks like

    NIS2 penetration testing is not a checkbox exercise. Article 21 does not name one single testing tool that every entity must use. It requires organisations to handle vulnerabilities and assess whether their cybersecurity risk-management measures work in practice. That distinction matters. A vulnerability scan can tell you that a known weakness exists. A DAST scan […]

  • NIS2 implementation roadmap: a 12-week plan for EU SMEs

    A NIS2 implementation roadmap should turn the directive into a sequence your management board, IT team, compliance lead, and suppliers can execute. For most EU SMEs, the work does not fail because Article 21 is unknown. It fails because scope, risk assessment, remediation, evidence, and board approval happen in the wrong order. This 12-week plan […]

  • The NIS2 minimum viable evidence pack: what to prepare for Article 21 compliance

    A NIS2 evidence pack is the documentation your organisation uses to prove that Article 21 cybersecurity risk-management measures are not only written down, but implemented. For EU SMEs, the problem is scattered evidence: one access review in a spreadsheet, one supplier check in procurement, one incident procedure in IT, and no single view that connects […]

  • How to run a NIS2 gap analysis: the 5-step assessment framework

    A NIS2 gap analysis turns regulatory pressure into a working plan. It shows which cybersecurity measures already exist, which ones are missing, which gaps create the highest risk, and what evidence the company needs to produce. For EU companies preparing for NIS2, the goal is not to create another policy document. The goal is to […]

  • NIS2 Article 20: management accountability obligations for company leadership

    NIS2 management accountability is no longer a topic only for the CISO or security team. Under Article 20 of the NIS2 Directive, cybersecurity governance becomes a management responsibility. NIS2 management accountability means the management body of an essential or important entity must approve cybersecurity risk-management measures, oversee their implementation, follow cybersecurity training, and keep evidence […]

Download the full case study!

Get the complete story—challenge, delivery setup, scope, outcomes, and the full testimonial.

Contact I Sunbytes Success Story