C2C Platform
Web, API and mobile penetration testing for IPO security readiness
Information technology I Japan I Penetration Testing I One-month engagement

The Clients
- Industry:
- Information technology
- Location:
- Japan
- Duration:
- 1 month
- Support areas:
-
Penetration testing and application security - Platform context:
-
A Tokyo-based technology company that develops and operates multiple online matching and marketplace platforms.
The challenge
C2C Platform needed to assess the security of one of its production-grade products as part of its preparation for an IPO security audit.
• Identify vulnerabilities across the web application and API
• Test both the iOS and Android mobile applications
• Rate findings clearly by severity
• Prioritize the issues requiring remediation
• Produce reporting suitable for the upcoming security audit
Dealing with a similar setup? Let’s discuss your requirements.
What the client needed
C2C Platform needed a penetration testing partner that could assess its product across multiple layers and turn the findings into clear remediation and audit-ready evidence.
Multi-layer testing
Assess security across web, API, iOS, and Android applications.
OWASP-aligned assessment
Evaluate relevant risks against OWASP Top 10 and API Top 10.
Clear prioritization
Rate findings by severity so the team knew what to address first.
Reproducible findings
Provide clear steps so developers could verify each identified issue.
Remediation guidance
Give practical recommendations the engineering team could act on directly.
IPO audit support
Structure findings and documentation to support IPO security audit preparation.
What Sunbytes Delivered
Sunbytes conducted a focused penetration testing engagement in a dedicated test environment, covering C2C Platform’s web, API, iOS, and Android applications.
Web application and API security testing
Tested the web application and API layer to identify exploitable weaknesses across key application flows and interfaces.iOS and Android application testing
Assessed both mobile applications for security issues across authentication, data handling, and application behavior.OWASP-aligned security assessment
Evaluated findings against relevant OWASP Top 10 and OWASP API Security Top 10 risk categories.Reproducible findings & evidence
Documented each identified vulnerability with clear severity ratings and reproduction steps for the engineering team.Prioritized remediation guidance
Provided practical recommendations and clear priorities to help developers address the identified findings efficiently.IPO audit reporting support
Adapted the reporting format and delivery coordination to support C2C Platform’s IPO security audit preparation.
Want to see if the fit is right for your team?
Why teams choose Sunbytes
A Netherlands-led partner that connects security evidence, delivery capability, and operational follow-through
ISO 27001-certified ISMS
Sunbytes operates an ISO 27001-certified ISMS, so information handling and access control have documented governance behind them.
Evidence-first security work
Security recommendations are mapped to evidence, ownership, and next actions so buyers and auditors can review what changed.
Dutch-led communication
European stakeholders get direct scope alignment, clear escalation paths, and accountable follow-up from a Dutch-led team.
Delivery-aware remediation
Security findings can be translated into software, infrastructure, and process changes through Sunbytes delivery capability.
Continuous security route
Baseline, readiness, specialist services, and CyberCare can connect without restarting context at every new request.
One operating partner
Secure work can align with delivery teams and people operations when access, onboarding, or governance affects the control environment.
What the team covered
The penetration testing engagement covered the full assessment cycle, from application testing and vulnerability validation to remediation guidance and audit support.
Web application & API security
Assessed the web and API layers for exploitable vulnerabilities across key application flows, interfaces, and exposed functionality.iOS & Android application security
Tested both mobile applications for security weaknesses affecting authentication, data handling, and application behavior.OWASP Top 10 and API Top 10 risk assessment
Mapped testing and identified risks against relevant OWASP Top 10 and OWASP API Security Top 10 categories.Vulnerability validation and severity classification
Validated each identified issue and assigned a severity rating to help the client understand impact and remediation priority.Reproduction instructions for identified findings
Documented clear reproduction steps so C2C’s engineering team could verify and investigate each vulnerability.Prioritized remediation guidance
Provided practical recommendations for each finding, helping the team address the most important security issues first.Audit-oriented reporting and clarification support
Structured the findings for IPO security audit preparation and supported the client with clarification of technical issues and reporting needs.
Outcomes
The engagement moved C2C Platform from vulnerability detection through remediation, with both project KPIs fully achieved.
In their words
“They provided practical, prioritized remediation guidance that our team could act on immediately.”
Yoshiyuki Saigusa
CTO, C2C Platform Co., Ltd.
See also
Download the full case study!
Get the complete story—challenge, delivery setup, scope, outcomes, and the full testimonial.



















