Skip to main content
Back to case studiesCyber Security

API Security Assessment: JWT and Authorization Gaps

The organization operated at Microservices on Kubernetes with fragmented tooling and unclear ownership between security, platform, and application teams. Incide…

Client profile

Sector
FinTech
Scale
Microservices on Kubernetes

Challenge

The organization operated at Microservices on Kubernetes with fragmented tooling and unclear ownership between security, platform, and application teams. Incidents were detected late; changes lacked measurable acceptance criteria.

Engineering approach

Arekan mapped trust boundaries, data flows, and failure modes before writing code or rules. We ran staged pilots with rollback plans, defined SLOs for detection or retrieval quality, and aligned deliverables to audit evidence requirements.

Solution

We implemented production-ready components using Burp Suite, Postman, JWT tooling with infrastructure-as-code, monitored rollouts, and handover runbooks. Customer identities remain confidential; this case reflects a composite of anonymized enterprise engagements.

Implementation process

  1. 1.Discovery and asset inventory
  2. 2.Architecture design and threat modeling
  3. 3.Pilot implementation in staging
  4. 4.Production rollout with canary validation
  5. 5.Handover, training, and continuous improvement roadmap

Results

-62% average reduction
Detection / response MTTR
-41% in first 90 days
False positive triage volume
-55% manual effort
Audit evidence preparation time
99.97% maintained
Platform availability during migration

Technologies

Burp SuitePostmanJWT toolingK8s

Stack selected for interoperability, operability, and audit evidence.

Customer identities are confidential. Metrics represent anonymized composite outcomes from Arekan delivery work.

AI, Cybersecurity & Enterprise Software Engineering

Secure. Scale. Innovate.

We build secure, AI-powered digital platforms for ambitious companies across Europe, the Middle East and the Gulf region.