Case Study

Strengthening Third-Party Application Security

Written by UltraViolet Cyber | Sep 21, 2026, 8:12:43 PM

For a global financial software company, every third-party application in its marketplace carries a measure of its reputation. Customers see those integrations as part of the company’s ecosystem, even though another developer builds the software. A vulnerability in that code can put both customer data and trust at risk.

The marketplace hosts hundreds of integrations, built by developers ranging from two-person shops to established software firms. Some applications handle basic data processing. Others work with Social Security numbers and sensitive financial information. Each brings different risks, but by promoting them, the company puts its name behind software it does not build.

 

The Challenge

Before an application can enter the marketplace, it must pass a penetration test. Once listed, it must undergo testing again every year. Premium listings generate revenue for the company, but the testing requirement applies to every tier.

As the marketplace grows, keeping up means managing hundreds of assessments for developers with very different levels of security experience. Many are going through a penetration test for the first time. Each application needs to be scoped, compliance documentation collected, and findings explained so developers can work through remediation. Moving that work forward takes practitioner judgment and regular, direct conversations.

When the company first turned to UltraViolet Cyber, its internal security team was already working beyond capacity. The red team focused on black-box testing of live production systems. The pre-production testing needed to approve marketplace listings required separate support.

Today, that work runs through an ongoing assessment program, with UltraViolet supporting both the testing and the developer coordination needed to keep it moving.

 

The Operational Requirements

The company needs additional testing capacity that meets specific staffing and reporting requirements. Anyone who could access U.S. tax data must be based in the United States, which rules out offshore delivery for those engagements.

Every assessor must also hold recognized security certifications. For money-movement products that process billions of dollars, the company has historically reviewed assessors’ resumes and interviewed them before approving their participation.

The reporting requirements are equally specific. The company needs formal, well-documented external testing reports that meet its expectations for rigor and support internal reviews.

UltraViolet continues to meet these requirements year after year. As the company pursues ISO/IEC 27001 certification, independent third-party testing also gives the team evidence it can use in its compliance and certification work.

 

The Engagement

The work begins with understanding the application: how critical it is, what data it handles, what has changed since its last review, and how technically complex it is. UltraViolet and the customer use those factors to scope each review. Applications that handle sensitive data, such as Social Security numbers, receive a full, in-depth assessment, while simpler, lower-risk applications receive a narrower, focused assessment.

As one assessment concludes, the next begins. With roughly 60 priority tests active at any time, that steady cadence supports testing throughout the year.

Much of the work happens in direct conversations with developers. UltraViolet handles most of that communication, from onboarding and collecting SOC 2 documentation and other artifacts to following up with the hundreds of development teams moving through the security gate.

The company previously brought this coordination in-house, but found that it took time the security team needed for other work. Today, UltraViolet helps developers understand what to expect, work through findings, and complete the steps needed to move forward. That guidance is a substantial part of the engagement, particularly for teams unfamiliar with security testing.

Most applications in the marketplace are mobile, making hands-on testing especially important. UltraViolet provides manual mobile testing in a program where much of the other assessment coverage is automated. That work has been particularly useful in identifying mobile application vulnerabilities, with reports that help developers understand what the assessors found. 

 

The Results

One of the program’s most consequential improvements is how the company verifies that vulnerabilities have been addressed.

Over 10+ years, the relationship has grown from individual assessments to quarterly engagements and then to an annual program. Today, it gives the company a repeatable way to manage third-party application risk as its marketplace grows.

The same findings support weekly risk reporting to leadership. The company tracks remediation SLAs by severity, from seven days for critical third-party findings to 90 days for low-severity findings. Adherence is reported weekly to a CISO who reports directly to the CEO. UltraViolet’s structured reports support that tracking and provide evidence for audit reviews.

Assessment data also feeds the company’s operational dashboards. Its data analysts use UltraViolet’s APIs to bring findings into dashboards that track risk across the marketplace and help inform leadership decisions.

The testing process helps the company keep its developer requirements current, too. When developers challenged findings by pointing to the company’s published security requirements, UltraViolet identified places where those requirements had fallen behind current industry standards. That input helped the company update its developer-facing policies, bringing what developers are asked to follow into closer alignment with how their applications are assessed.

Through reorganizations, changes in program ownership, and acquisition transitions on the partner side, the program has maintained its capacity. Established relationships and trust help the teams preserve continuity through those changes.

That continuity is part of the day-to-day working relationship. Weekly meetings give the company regular access to information and time to discuss questions, priorities, and improvements. The security operations manager values the team’s approachability and communication enough to maintain a weekly meeting cadence they do not have with any other vendor.

 

Continuing the Partnership

That perspective continues to shape the program. Findings guide remediation and retesting, strengthen developer requirements, and give leadership evidence to guide risk decisions.

Third-party developers are starting to ask that AI components be included in their reviews as they build more AI-driven features into their applications. The company already sets clear requirements for assessor location, security certifications, and formal reporting. It brings that same emphasis on rigor to AI testing tools, which undergo internal review before being adopted into the program.

As testing needs expand, the partnership builds on the team’s understanding of those requirements and its working relationships with developers, providing continuity in the people and processes that keep the program moving.

 

Build Capacity for Your Application Security Program

Support your team with dedicated practitioners who manage ongoing testing and developer coordination, helping you keep pace as your application portfolio grows.