Document Logistix Uses SAST and DAST to Ensure Security of Sensitive Customer Data
Document Logistix invests in stringent product testing to benefit customers and in-house developers
Documen Logistix implements SAST and DAST to ensure security of customer data
Summary
Award-winning document management software firm, Document Logistix develops document management solutions that help to eliminate the use of paper, improve records management and automate business processes.
Its software powers the operations of some of the world’s most demanding, high document volume businesses, including major logistics companies like DHL and CEVA.
Customers entrust Document Logistix with the handling of their information – much of which is highly sensitive or confidential – so security is a high priority.
Seeking a higher level of confidence in its application security testing, the company turned introduced independent testing to secure its DevOps environment and automate its processes.
Document Logistix uses static application security testing (SAST) and dynamic application security testing (DAST). Document Logistix also relies security alerts from a threat research centre (TRC) for added assurance in uncovering security vulnerabilities.
Profile: Document Logistix
Since 1996, Document Logistix has supplied its innovative and scalable Document Manager software to a variety of SME and blue-chip clients around the world.
The company’s UK and EMEA operations are headquartered in Milton Keynes, UK, which is also the central point of product development, technical support and training.
The US branch of the company is headquartered in Austin, Texas, and has major contracts with the Texas Department of Public Safety, the Virginia State Police and various agencies in other states.
Document Logistix has won multiple Product of the Year awards for Document Management, Workflow, Business Process Management, Records Management and, recently, Robotic Process Automation.
Systematising product testing
“Our application is basically a portal for sharing documents.
It’s not a banking application – we don’t store credit card information – but document management can be equally if not more vulnerable to people trying to gain access to things they shouldn’t see,” said Tim Cowell, founder and CTO, Document Logistix
Document Logistix’ application, Document Manager, provides a flexible platform for completely paperless business processes and highly efficient archiving. Not designed for single market, Document Manager is highly customisable for a large range of business processes.
Document Manager can be used for something as relatively straightforward as proof of delivery, where the risk of data loss is fairly minimal. Or, for more sensitive information like HR records and personnel management, where the possibility exists for people looking at records they should not be viewing.
This has become even more important since the advent of the General Data Protection Regulation (GDPR), as there are financial penalties for non-compliance. Likewise, with HIPAA in the USA.
Another example of document sensitivity among Document Logistix customers are District Attorneys in the US using Document Manager for disclosure purposes. DAs use Document Logistix e-Discovery document management system to publish case material to ensure that prosecution and defence lawyers have full access.
Failure to protect such information could lead to a mistrial, potentially prevent the prosecution of a criminal, so stakes are high.
While protecting customers’ data has always been a priority for Document Logistix, it lacked a true solution for security testing of its application.
A number of clients performed their own penetration testing, submitting a list of issues to Document Logistix, and Document Logistix would respond by providing them a new build of its application.
Document Logistix also had its developers manually checking code for security vulnerabilities, which proved to be a time consuming and costly practice, as code had to be updated constantly to keep up with new hacker techniques and new vulnerabilities.
“The biggest problem was the huge unknown. Our customers are high profile and high risk.
We implemented a solution that gives us a better process,” said Cowell.
Static and Dynamic Application Security Testing
Document Logistix implemented SAST to scan code for errors and ensure a more secure product design.
Later, it added DAST to provide them with automatic detection and assessment of code changes with alerts for newly discovered vulnerabilities, as well as reporting and intelligence metrics.
DAST feedback
“With DAST, we have confidence in saying to our customers ‘this is what was done to make your information more secure,’ and they know that every time there’s a new build of the application, it gets a new test,” said Cowell.
Document Logistix enjoys an additional layer of protection against security vulnerabilities.
On a daily basis, any new code is uploaded to the TRC, where it is checked, and an automated report identifying any anomalies is sent back to Document Logistix, so they can take any necessary actions.
Benefits of Software Product Testing
The combination of SAST and DAST provides Document Logistix with a platform for testing its application and DevOps environment, and automating the processes required to comply with the complex rules of paper and electronic document management.
The process includes full auditability of its application, the ability to plan workflows, perform complex retention policy management, and define policies for certain classes of documents, including what documents should or should not be disclosed, and to whom.
New testing has given Document Logistix full confidence in the security of its products and its ability to protect its customers’ information.
“SAST, DAST and the TRC gives us added credibility with customers because we’ve raised the question of security first.
It becomes a non-issue, because they understand we’re serious about our duty to protect their data,” said Cowell.
Testing is also cost-effective.
“We do three to four releases a year, and testing is very expensive, so performing testing on each release isn’t reasonable.
This is a very cost-effective solution, because the testing process is ongoing. This path has had the least amount of impact on productivity,” said Cowell.
Importance of software penetration testing
Software penetration testing is crucial for ensuring the security and integrity of applications in a digital world. The involves simulating cyberattacks on software to identify vulnerabilities that could be exploited by malicious actors.
Penetration testing helps organisations proactively detect and address security flaws before they can be leveraged in real attacks, and so protect sensitive data and maintain trust with customers and stakeholders.
One of the primary benefits of penetration testing is risk mitigation. Identifying weaknesses early allows developers to patch vulnerabilities to reduce the risk of data breaches, financial loss and reputational damage.
Additionally, penetration testing helps to ensure compliance with industry regulations and standards, such as GDPR, PCI-DSS, and HIPAA, which often require regular security assessments.
Penetration testing also fosters a culture of security awareness within organisations. It highlights the importance of secure coding practices and continuous monitoring, and encourages teams to prioritise security throughout the software development lifecycle.
By understanding the potential attack vectors and the effectiveness of current security measures, organisations can make informed decisions about future security investments and strategies.
Software penetration testing is essential for safeguarding applications, protecting data, ensuring compliance, and fostering a proactive approach to cybersecurity.
Related Article

Technical Support
e: support@document-logistix.com
t: UK & Europe 01908 366 722
t: USA +1 (866)865-2476





