Case Study

Embedding Continuous Security into a Salesforce-Based SDLC

How Protas achieved 70% fewer missed risks with intelligent, sprint-aligned security testing

5 min

Case Study

Embedding Continuous Security into a Salesforce-Based SDLC

How Protas achieved 70% fewer missed risks with intelligent, sprint-aligned security testing

5 min

Case Study

Embedding Continuous Security into a Salesforce-Based SDLC

How Protas achieved 70% fewer missed risks with intelligent, sprint-aligned security testing

5 min

In this article

No headings found on page
No headings found on page

Join our newsletter

Receive the latest advancements, playbooks, and industry insights in software change security understanding.

Join our newsletter

Receive the latest advancements, playbooks, and industry insights in software change security understanding.

Achievements

  • 244 Processed Change Tickets

  • 37 Intelligent Testing Sequences

  • 5 Vulnerabilities Resolved

Overview

Protas is a progressive health research organisation using Cantata, a clinical trial management platform built entirely on Salesforce. With fast-moving development cycles and a customer-facing UAT process, Protas needed to embed intelligent, continuous security testing into their release pipeline, without slowing down delivery or disrupting their product teams.

The Challenge

Protas runs two-week sprints followed by a two-week UAT cycle, where external stakeholders perform critical testing. Security needed to fit seamlessly into this window, delivering fast, actionable results.

With Cantata built on Salesforce's proprietary tech, Apex and Lightning Web Components, Protas needed a partner experienced in Salesforce's unique security model, from SOQL injection risks to object and field-level access controls.

Approach with Cytix

Cytix integrated at the start of each UAT cycle, scanning Jira tickets to identify security-relevant changes and auto-generate tailored threat models and tests. Testing kicked off within days and typically finished in a week, allowing time for fixes, retests, and stakeholder sign-off.

By integrating Cytix, Protas moved from traditional, point-in-time penetration testing to an embedded, sprint-aligned testing model.

Salesforce-Specific Risk Coverage

  • SOQL injection

  • Missing field-level authorisation

  • Sensitive record field exposure

  • Misconfigured object permissions

  • Salesforce-specific access control flaws

What the Team Says

"Cytix's continuous testing uncovered gaps our processes missed. I now fully advocate year-round testing over annual penetration tests."

Scott Wilson, Head of Information Security

"Cytix integrated smoothly, provided clear reports, and kept our platform secure without disrupting development. Efficient, insightful, and professional service."

Kevin Hollingworth, Head of Platform Development and Operations

"Cytix embedded seamlessly into our workflow, required minimal onboarding, and delivered clear, collaborative security testing with excellent communication."

Tom Cameron, IT Test and Validation Lead

Conclusion

Cytix enabled their team to focus on what mattered most, ensured every change was reviewed with relevant context, and helped catch issues early, all while supporting the unique needs of a Salesforce-built platform.

Cytix continues to be a valued extension of the Protas security and engineering team, helping to ensure secure, high-quality releases without compromise.

Get started

Ready to transform your security process?

Eagle House, 64 Cross Street, Manchester, M2 4JQ, United Kingdom

© 2026 Cytix Ltd. All rights reserved.

Eagle House, 64 Cross Street, Manchester, M2 4JQ, United Kingdom

© 2026 Cytix Ltd. All rights reserved.

Eagle House, 64 Cross Street, Manchester, M2 4JQ, United Kingdom

© 2026 Cytix Ltd. All rights reserved.