E-commerce security
The question isn't whether your store has a flaw — it's who finds it first.
10+ Brazilian stores with flaws found.
What we find
The flaws every store swears it doesn't have.
Not theory. It's what shows up, again and again, in the stores we audit.
Unauthenticated API
Internal endpoints returning data without asking for login — just call the URL.
SQL Injection
A mishandled input becomes a database command: data read, changed, or wiped.
Client-side token
An API key or integration token exposed in the site bundle, in plain sight.
How it works
One week. From first access to the fix.
Most pentests stop at the PDF. We're engineers: we deliver the report and fix what matters.
Investment
One price. One result.
From URL to a fixed report, in one week.
Scope agreed before we start. No downtime.
starting at
US$ 4,000
No High or Critical Finding = Don't Pay
- Offensive audit focused on e-commerce
- Executive + technical report, with proof of every flaw
- Critical flaws fixed by our team
- Retest to confirm they're closed
- NDA and full confidentiality over the findings
Straight questions
The questions everyone asks
We fix it. A traditional pentest hands over a PDF and leaves — the problem stays in your store. deco is engineering: critical flaws come back fixed within the same week, with a retest to confirm.
No. We test in production carefully (or on staging, if you prefer), without disrupting the operation and without touching real customer data. Scope is agreed before we start.
We start as an external attacker, with just the URL — that's the real scenario. With access to code and infra, we go deeper (grey/white box) and find even more. You choose the level.
It's never happened in e-commerce — but if it does, you get a report attesting your security maturity and a hardening roadmap. You walk away knowing where you stand.
NDA signed before the first access. Findings, proof, and the report stay between your team and ours. Nothing is published, shared, or used as a case without your authorization.
Yes, because the scope is focused on e-commerce — it's not a generic audit of everything. We know where stores break and go straight for it.


