Bayanat audit by 7ASecurity

7ASecurity is proud to share the results of our penetration test and whitebox security review of Bayanat. Bayanat is a professional-grade platform designed for human rights documentation, helping organizations collect, secure, catalog, and analyze sensitive records according to human rights standards. The engagement was solicited by Bayanat Maintainers (SJAC) and executed by 7ASecurity.

This publication reflects the kind of security collaboration we value: deep technical review, clear remediation guidance, responsive maintainers, and coordinated disclosure after fixes have been prepared for operators. The Bayanat team was helpful and responsive throughout the audit, and its decision to align publication with patched deployments and a tagged public release is a strong signal of accountability to users and stakeholders.

Audit Process:

In April and May 2026, a team of 6 senior auditors from 7ASecurity carried out this engagement, dedicating 32 working days to the assessment. The methodology was whitebox: 7ASecurity was provided with access to a staging environment, documentation, test users, and source code. Coordination took place through email and a shared Slack channel, allowing the teams to move quickly while keeping findings and remediation work aligned.

The scope was organized across seven work packages:

  • WP1: Bayanat Web Application & API Audit
  • WP2: Bayanat Authentication, Authorization & Workflow Audit
  • WP3: Bayanat Evidence Ingestion, Import/Export & Background Tasks Audit
  • WP4: Bayanat Deployment Hardening Audit
  • WP5: Bayanat Parser Fuzzing & Regression Corpus
  • WP6: Bayanat Supply Chain & Release Process Review
  • WP7: Bayanat Lightweight Threat Model (Review & Update)

Audit Results:

  • 22 Findings with Security Impact
  • 21 Hardening Recommendations
  • 43 Total Issues
  • Supply-chain and release process review
  • Lightweight threat model review/update
  • All 43 report items include retest notes marked resolved by Bayanat and confirmed by 7ASecurity

The report also highlights several positive impressions. Bayanat defended itself well against a broad range of attack vectors, and the platform already contained meaningful security and accountability mechanisms around access control, workflows, revision tracking, exports, peer review, asynchronous processing, and operator-oriented deployment practices.

  • Robust behavior against many traditional web application attack vectors, with no SQL Injection (SQLi) or Remote Code Execution (RCE) issue identified during this assignment.
  • No unrestricted arbitrary file-upload path leading directly to code execution was identified.
  • Role-based and group-based access-control concepts were present across the platform.
  • Approval workflows, revision tracking, export workflows, and peer-review mechanisms showed attention to operational integrity and accountability.
  • Asynchronous worker pipelines were present for OCR, exports, media handling, and imports, reducing direct exposure of expensive processing paths to the web request lifecycle.
  • The native installer and related documentation were structured and operator-friendly.

Bayanat has rolled fixes through its deployment process and is publishing a tagged public release so other operators can update from a clear release point. Please update to the latest Bayanat release to take advantage of the hardening work performed during this engagement.

Acknowledgements:

Thank you to the individuals and groups that made this engagement possible:

  • Bayanat Maintainers (SJAC), especially Ahmad Kareem, Ahmad, Nidal, and the rest of the Bayanat team
  • 7ASecurity: Abraham Aranguren, Daniel Ortiz, Dheeraj Joshi, Nabih Benazzouz, Patrick Ventuzelo, and Szymon Grzybowski
  • Bayanat users, operators, and stakeholders supporting transparent security work

Read the report:

You can read the full Bayanat audit report HERE

You can read Bayanat's announcement HERE

If your organization maintains software that handles sensitive records, workflows, or evidence, talk to 7ASecurity about a practical security review that goes beyond automated scanning.