Request choreography

One request.
Every boundary.

Travel with a request. A valid token should never be a passport to someone else’s data.

Interactive path view

The scenario and controls work without 3D.
Interactive simulation
YOUR NEXT MOVE

Change the conditions. Change the outcome.

Break it.
Then make it hold.

An external user requests another tenant’s invoice using a guessed object ID. Explore object-level authorisation, not just authentication.

How this simulation works

Each run follows one deterministic path. An enabled control stops this particular scenario at its boundary. Results are educational, not a security assessment or a guarantee against other attacks.

Set the defences

0 of 3 enabled

For this private API, reject requests outside the allowed network.

Check that the authenticated subject can access this invoice.

Bind the database lookup to the authenticated tenant.

Ready when you are
BRIEFING

Run once without controls. Then activate a defence and compare what happens.

From an experiment to your environment.

Let’s find your
real attack paths.

Talk to Arica

Keep exploring

Return to the service universe