New at Horizon3
Happy Returns customer story about using NodeZero WebApp to validate exploitable application risk and give developers actionable security evidence.

From Scanner Findings to Verifiable Web Application Risk

Web application scanners can surface potential vulnerabilities. They don’t always prove what attackers can actually exploit or give developers the evidence they need to act.

Happy Returns needed a better way to continuously validate application risk across its AWS-heavy environment while helping security and engineering teams reach the same conclusions faster.

This customer story explores how Happy Returns expanded its use of NodeZero® from infrastructure validation into continuous autonomous WebApp pentesting, creating a shared, evidence-driven view of exploitable risk.

Key Insight

Traditional scanners and periodic pentests generated findings, but Happy Returns needed stronger proof of what was truly exploitable and a better way to communicate that risk to developers.

By adopting NodeZero and NodeZero WebApp, Happy Returns gained:

  • Continuous validation across cloud infrastructure and web applications
  • Clearer visibility into exploitable application risk
  • Evidence developers and security teams could evaluate together
  • Greater insight into how credentials and cloud assets compound risk
  • Scalable WebApp testing across a growing application portfolio
  • Less reliance on abstract severity ratings and static reports

What You’ll Learn

  • Why traditional scanner findings can create friction between security and development teams
  • How autonomous WebApp pentesting validates what is actually exploitable
  • How attack-path evidence helps teams understand compounded cloud risk
  • Why route-level proof can make application security findings easier for developers to act on
  • How continuous testing fits an AWS-heavy, cloud-native operating model
  • How security teams can move from interpreting scanner noise to reviewing verifiable evidence
  • Why autonomous pentesting can create a shared view of risk across security and engineering

Why It Matters

Happy Returns helps merchants manage returns at scale, putting its customer-facing applications and supporting cloud workloads close to the revenue path. Its lean security team spans cloud, infrastructure, application security, privacy, and compliance across an AWS-heavy environment.

For a team operating in that environment, identifying another potential vulnerability isn’t enough. Security needs to know whether it can actually be exploited and give developers evidence that makes the path to remediation clear.

Happy Returns moved beyond periodic reports toward continuous, evidence-driven validation. After about a dozen early NodeZero tests, the team expanded to nearly 30 autonomous WebApp pentesting campaigns and identified more than 20 applications for early testing. In one AWS pentest, NodeZero also mapped roughly 2,000 credential access relationships across 10 credentials and 50 hosts.

As Phillip Walsh, Head of Information Security at Happy Returns, put it:

“Instead of just looking at a report, you can actually show what matters.”

Download the customer story to see how Happy Returns uses NodeZero WebApp to continuously validate exploitable risk and give developers verifiable evidence they can act on.

How can NodeZero help you?
Let our experts walk you through a demonstration of NodeZero®, so you can see how to put it to work for your organization.
Get a Demo
Share: