Case study · Cybersecurity · SaaS security posture management
Finding and fixing security misconfigurations across 100+ SaaS apps
Decoupled connectors and a rule-driven scanner that identify, report and automatically fix risky settings across more than 100 SaaS applications from one platform.
The problem
Companies run on dozens of SaaS tools, each with its own security settings. A single weak setting can expose data, and checking every app by hand does not scale.
Security teams need one place to see misconfigurations across all their apps, measured against a clear ruleset, with a fast way to fix them.
What I owned
- Developed core SSPM modules in Node.js with TypeScript
- Built decoupled connectors for more than 100 SaaS applications
- Worked on the rule evaluation, reporting and auto-remediation flow
Architecture
From setting to fix
- A connector collects the security settings of one SaaS application through its API.
- The scanner evaluates those settings against the defined ruleset.
- Every misconfiguration is reported in one central place, whichever app it came from.
- Supported findings are fixed automatically through auto-remediation.
Key decisions
One decoupled connector per application
Adding the next SaaS app means writing one connector; the scanner and reports stay untouched, which is how coverage could grow past 100 apps.
Rules kept separate from scanning code
Security checks change often; a defined ruleset lets them evolve without rewriting how settings are collected.
Report and remediate in the same flow
Teams go from seeing a problem to fixing it in one platform, instead of exporting findings and patching each app by hand.
Results
- Connectors for 100+ SaaS applications
- Modular scanning with centralized reporting from a single platform
- Misconfigurations identified, reported and auto-remediated against a defined ruleset
- Node.js
- TypeScript
- SaaS vendor APIs
Client names and results are taken from my résumé. Architecture is simplified and shared without confidential details.