C2C Platform
Web, API and mobile penetration testing for IPO security readiness
Information technology I Japan I Penetration Testing I One-month engagement
The Clients
- Industry:
- Information technology
- Location:
- Japan
- Duration:
- 1 month
- Support areas:
- Penetration testing and application security
- Platform context:
- A Tokyo-based technology company that develops and operates multiple online matching and marketplace platforms.
The challenge
C2C Platform needed to assess the security of one of its production-grade products as part of its preparation for an IPO security audit.
• Identify vulnerabilities across the web application and API
• Test both the iOS and Android mobile applications
• Rate findings clearly by severity
• Prioritize the issues requiring remediation
• Produce reporting suitable for the upcoming security audit
Dealing with a similar setup? Let’s discuss your requirements.
What the client needed
C2C Platform required a penetration testing partner that could provide:
End-to-end testing across web, API, iOS and Android
Assessment mapped to OWASP Top 10 and API Top 10 risks
Clear severity ratings for every identified finding
Reproducible steps that its engineering team could follow
Practical remediation guidance, prioritized by urgency
Reporting structured to support its IPO security audit
What Sunbytes Delivered
Sunbytes conducted penetration testing in a dedicated test environment covering the product’s web, API and mobile layers.
Web application and API security testing
iOS and Android application testing
Assessment against OWASP Top 10 and API Top 10 risks
A detailed report covering all identified vulnerabilities
Severity ratings and remediation priorities for each finding
Adjustments to the reporting format and delivery timing to support the IPO audit
Want to see if the fit is right for your team?
Why teams choose Sunbytes
A Netherlands-led partner that connects security evidence, delivery capability, and operational follow-through
ISO 27001-certified ISMS
Sunbytes operates an ISO 27001-certified ISMS, so information handling and access control have documented governance behind them.
Evidence-first security work
Security recommendations are mapped to evidence, ownership, and next actions so buyers and auditors can review what changed.
Dutch-led communication
European stakeholders get direct scope alignment, clear escalation paths, and accountable follow-up from a Dutch-led team.
Delivery-aware remediation
Security findings can be translated into software, infrastructure, and process changes through Sunbytes delivery capability.
Continuous security route
Baseline, readiness, specialist services, and CyberCare can connect without restarting context at every new request.
One operating partner
Secure work can align with delivery teams and people operations when access, onboarding, or governance affects the control environment.
What the team covered
The penetration testing engagement covered:
Web application & API security
iOS & Android application security
OWASP Top 10 and API Top 10 risk assessment
Vulnerability validation and severity classification
Reproduction instructions for identified findings
Prioritized remediation guidance
Audit-oriented reporting and clarification support
Outcomes
The engagement gave C2C Platform a clear path from vulnerability detection to remediation:
In their words
“They provided practical, prioritized remediation guidance that our team could act on immediately.”
Yoshiyuki Saigusa
CTO, C2C Platform Co., Ltd.
See also
Download the full case study!
Get the complete story—challenge, delivery setup, scope, outcomes, and the full testimonial.



















