Penetration testing for fintechs that need to pass BACEN scrutiny and due diligence.
In-depth penetration testing for fintechs operating in or entering Brazil, covering BACEN Resolution 4,893 (CMN 4,893) (Central Bank of Brazil), Pix flows, Open Finance, KYC bypass, transaction fraud and tenant isolation. The same methodology our researchers use in the bug bounty programs of eToro, Bitso and international banks.
- Mutual NDA within 24h
- Retest included
- Direct contact with the researcher
Why fintechs
Fintechs face different attacks. Generic scanners don't find them.
Most fintech pentests in Brazil are run with Nessus, Acunetix or Burp Pro in “automated mode.” These scanners find the obvious bugs — outdated versions, missing headers, trivial XSS. They find none of what actually takes a fintech down: BOLA on a transaction endpoint, a race condition on withdrawals, a mismatch between the cached balance and the primary source, a poorly validated JWT in a billing flow, OAuth state confusion between the app and an Open Finance partner.
Our pentest starts where the scanner stops. We attack business logic, chains between components and the developers' wrong assumptions — because that's how real bug bounty researchers attack, and that's how real adversaries attack.
Scope
What our fintech penetration testing covers
Regulatory coverage
- BACEN Resolution 4,893 — the Central Bank of Brazil's cybersecurity policy rule for regulated institutions, with mandatory cybersecurity testing for financial and payment institutions. Report formatted as regulatory evidence.
- BCB Resolution 85 — cybersecurity policy and requirements for contracting data processing and storage services.
- LGPD Art. 46 (Brazil's data protection law) — technical measures to protect customer data.
- PCI DSS 4.0 — for fintechs that process card data directly (requirements 11.4.x).
Pix flows
Pix is Brazil's instant payment system, run by the Central Bank of Brazil (BACEN).
- Dynamic QR codes — payload manipulation, amount validation bypass
- Static QR codes — deep links, multiple-payer abuse
- Billing by Pix key — phishing tests using forged keys
- Pix refunds — race conditions, double spending
- Payment initiation — initiator authentication, payload validation
Open Finance
- Consent flow — confused deputy and scope escalation testing
- FAPI auth — JWT validation, JWS detached signatures, JWE
- Data endpoints — BOLA between customers, leaks between institutions
- Event webhooks — replay, signature bypass, SSRF via callback
Transaction fraud
- Race conditions on withdrawals, transfers and Pix
- Cached balance vs. source of truth mismatches (Redis vs. Postgres)
- Limit bypass through payload modification
- Replay of signed transactions
- Currency manipulation in multi-currency accounts
KYC and onboarding
- Document validation bypass (deepfakes, OCR injection)
- Selfie reuse / liveness bypass
- SSRF via the KYC provider's webhook
- BOLA on document upload endpoints
- Race conditions on onboarding completion
Authentication and sessions
- OAuth 2.0 / OIDC — state fuzzing, redirect URI fuzzing, token theft
- JWT — algorithm confusion, kid path traversal, JKU SSRF
- MFA bypass — race conditions on OTP codes, broken recovery flows
- SAML XSW — for enterprise integrations
- Session fixation, session puzzling
Track record
Where we've reported vulnerabilities
No Vuln researchers have findings published or validated in the bug bounty programs of international fintechs and financial institutions — including:
- eToro — social trading platform with more than 30 million users
- Bitso — the largest crypto exchange in Latin America
- Hostinger — global hosting provider with millions of customers
- U.S. Department of Defense — official bug bounty program
We don't sell “ethical hackers.” We bring researchers who compete with real adversaries in programs where only new findings get paid.
Pricing
Fintech penetration testing pricing
| Scenario | Price range | Coverage |
|---|---|---|
| Early-stage fintech (MVP, pre-BACEN authorization) | Sprint (25h): US$ 3,750 to US$ 6,250 | Web + API + auth, black box |
| Authorized payment institution / fintech with an active customer base | Deep Dive (50h): US$ 7,500 to US$ 12,500 | + Pix + KYC + integrations + fraud |
| Digital bank / Open Finance | Full Scope (100h+): from US$ 15,000 | Full white box + mobile + cloud + Open Finance |
| Recurring, for active fintechs | PTaaS: on request | Sprint-aligned continuous pentesting + attack surface monitoring |
Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.
FAQ
Frequently asked questions
Is penetration testing mandatory for fintechs in Brazil?
In practice, yes. BACEN Resolution 4,893 and BCB Resolution 85 — rules from the Central Bank of Brazil (BACEN) — require cybersecurity testing for financial institutions and payment institutions.
How much does fintech penetration testing cost?
Early-stage fintech (pre-BACEN authorization): Sprint (25h), US$ 3,750 to US$ 6,250. Authorized payment institution with an active customer base: Deep Dive (50h), US$ 7,500 to US$ 12,500. Digital bank with Open Finance: Full Scope (100h+), from US$ 15,000. PTaaS (recurring): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.
Do you cover Pix and Open Finance?
Yes. Full coverage of Pix, Brazil's instant payment system (static and dynamic QR codes, refunds, billing), Open Finance Brasil (consent, FAPI auth, data endpoints, event webhooks), KYC (validation bypass, liveness, deepfakes) and transaction fraud.
Can the report be used as evidence for BACEN?
Yes. Reports are formatted to serve directly as regulatory evidence under BACEN Resolution 4,893 and BCB Resolution 85. You get an executive summary, a technical report and a formal compliance statement.
Next step
Request a proposal for your fintech.
NDA sent within 24h. Once it's signed, a 30–60 min technical call to map the scope, and a formal proposal within 3 business days.
Talk to a researcher