Bayanat v5.0 security audit by 7ASecurity
By Ahmad
The Syria Justice and Accountability Centre (SJAC) is pleased to publish, alongside Bayanat v5.0, the results of an independent penetration test and whitebox security review performed by 7ASecurity for Bayanat. Bayanat is SJAC’s open-source platform for preserving, structuring and analysing human rights documentation. Investigators and organizations working on Syria and beyond use it to document violations, manage media and testimony, connect actors and incidents, and build the case files that support prosecution and advocacy. This release is about making this work more secure than ever: every release is signed, updates are one command with a snapshot and automatic rollback behind them, and the deployment itself now follows least privilege by default.
We chose to publish this work because transparency matters. The review gave us a detailed external view of Bayanat across application security, evidence workflows, deployment assumptions, supply-chain practices, and threat modeling. It also provided practical remediation guidance that the team could act on before public release.
Before publication, we prioritized patching our own deployments, rolling fixes through staging and production, and preparing a tagged public release, Bayanat v5.0, so other operators can update from a clear release point.
Audit process
In April and May 2026, 7ASecurity performed the Bayanat assessment with a team of 6 senior auditors, dedicating 32 working days to the engagement. The review used a whitebox methodology with access to a staging environment, documentation, test users, and source code. Coordination took place through email and a shared Slack channel, allowing findings, fixes, and verification work to move smoothly.
The scope was organized across seven work packages:
- WP1: Bayanat Web Application & API Audit
- WP2: Bayanat Authentication, Authorization & Workflow Audit
- WP3: Bayanat Evidence Ingestion, Import/Export & Background Tasks Audit
- WP4: Bayanat Deployment Hardening Audit
- WP5: Bayanat Parser Fuzzing & Regression Corpus
- WP6: Bayanat Supply Chain & Release Process Review
- WP7: Bayanat Lightweight Threat Model (Review & Update)
Audit results
- 22 Findings with Security Impact
- 21 Hardening Recommendations
- 43 Total Issues
- Supply-chain and release process review
- Lightweight threat model review/update
- All 43 report items include retest notes marked resolved by Bayanat and confirmed by 7ASecurity
The report also recognized several strengths in Bayanat. 7ASecurity noted that the platform defended itself well against a broad range of attack vectors and already included meaningful controls around access-control concepts, approval workflows, revision tracking, export workflows, peer review, asynchronous processing, and operator-friendly deployment practices.
- Robust behavior against many traditional web application attack vectors, with no SQL Injection (SQLi) or Remote Code Execution (RCE) issue identified during this assignment.
- No unrestricted arbitrary file-upload path leading directly to code execution was identified.
- Role-based and group-based access-control concepts were present across the platform.
- Approval workflows, revision tracking, export workflows, and peer-review mechanisms showed attention to operational integrity and accountability.
- Asynchronous worker pipelines were present for OCR, exports, media handling, and imports, reducing direct exposure of expensive processing paths to the web request lifecycle.
- The native installer and related documentation were structured and operator-friendly.
We appreciate the depth and professionalism of the 7ASecurity review. The report gives Bayanat a stronger baseline for continued hardening, future testing, and secure operation by organizations that rely on the platform for sensitive documentation workflows.
Acknowledgements
Thank you to the individuals and groups that made this engagement possible:
- 7ASecurity: Abraham Aranguren, Daniel Ortiz, Dheeraj Joshi, Nabih Benazzouz, Patrick Ventuzelo, and Szymon Grzybowski
- Bayanat users, operators, maintainers, stakeholders, and funders who value transparent security work
Read the report
You can read the full Bayanat audit report here.
You can read 7ASecurity’s announcement here.
You can learn more about Bayanat and update to the latest tagged release.