Real World Careers

Vendor-conducted · 29 August 2026 · ASA-RWC-FED-2026-08-29

Application security assessment — not a 3PAO pentest.

This is the evidence an ISSO can file with a $14,500 Scale (290-seat) micro-purchase. It is an internal, defensive review of the live authorization boundary. It is not a FedRAMP 3PAO penetration test, not a SOC 2 report, and not an authorization. No exploit payloads were written or run against production.

1. Rules of engagement

ItemStatement
Targetrealworldcareers.com, APIs on Cloudflare Workers (/api/score, /api/report, checkout entitlement), public assessment banks
Date29 August 2026 (America/New_York evidence window)
AssessorAdvanced Learning Academy LLC (vendor). Not an independent firm.
MethodsTLS handshake, response-header review, authenticated vs unauthenticated API probes, public-path secret scan, CORS preflight, report-ID lookup, unpaid vs paid scoring, source review of Workers and Pages. No exploit development. No destructive testing. No credential stuffing.
Out of scopeStripe and Mailgun interiors, Cloudflare control plane, agency networks, social engineering, physical, 3PAO red team

2. Boundary (same as the SSP-lite)

Browser → TLS 1.3 → Cloudflare Pages (HTML) and Workers (score, jobs, entitlement) → D1 (credentials, scores) and R2 (files). Cards go only to Stripe. Transactional mail is Mailgun. No agency on-prem agent. No camera, microphone, or geolocation. Participants authenticate with a unique seat link, not PIV/SSO, in this SKU.

3. Encryption and transport (walked)

  • TLS 1.3, AES-256, SHA-384. Certificate CN=realworldcareers.com, not after 30 Oct 2026 (Cloudflare-managed).
  • HSTS: max-age=31536000; includeSubDomains.
  • HTTP→HTTPS and www→apex 301.
  • In transit: TLS on the public origin and Worker APIs.
  • At rest: Cloudflare D1 and R2 are encrypted at rest by the platform. ALA does not hold customer-managed (CMK) keys. This is a platform statement, not a separate SOC 2 letter.
  • No PAN on ALA servers. Stripe is the card processor.

4. Findings

IDSevFindingEvidence (29 Aug 2026)Disposition
P-01PassSecurity headers presentCSP (frame-ancestors none), X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy camera/mic/geo emptyKeep. Do not strip unsafe-inline from CSP without a full smoke — historical outage class.
P-02PassUnpaid full scoring blockedPOST /api/score with 50 items and no credential → 402 ENTITLEMENT_REQUIREDKeep.
P-03PassAnswer keys not in the public bank/assets/assessment/*.public.json has stems and options only. No answer_index. Keys stay in the Worker.Keep. Do not ship keys in Pages.
P-04PassReport IDOR on unknown IDsGET /api/report?id=RWC-RPT-001 → 404. Public sample RWC-RPT-086 is intentional and stores no name.Keep sample public. Production cohort reports stay behind the agency seat wallet.
P-05PassPaid scoring rate capWorker enforces 20 full scores / hour / credential (demo code 8).Keep.
P-06PassSecret paths not published/.git/config, /.env, /wrangler.toml not served as secrets. /api/_keys.json is the engine health JSON, not the key file.Keep.
P-07LowCORS Access-Control-Allow-Origin: * on Pages and score APIPublic origin sets ACAO *. Score API same. No session cookies on the federal HTML origin.Accept for this SKU (no cookie session). Do not add credentialed CORS without a named origin allow-list.
P-08LowPreview scoring is a 3-item oracle1-item and 3-item unpaid POSTs return 200 with preview:true. Full 50 remains 402.Accept. Preview is not an official result. Brute-forcing 3 items does not unlock a paid composite.
P-09LowFederal bank freeze vs scorer stampPublic Federal Fit bank freeze 2026.08-B-keybalance-v2. Scorer JSON stamps form_version: 2026.08-C (Career Fit freeze). Hiring/Federal banks were not rebuilt to C.Documented on methodology. Not a data leak. Do not mix keys across forms.
P-10MediumSeat links are bearer tokensThis SKU has no PIV/SSO/SAML. Possession of the unique link is access to that seat.Residual. Agency sends links in its own mail. Treat like a one-time exam URL. SSO is a different product.
P-11MediumNo independent 3PAO pentestThis file is vendor-conducted. No SOC 2 Type II letter. No FedRAMP SAR.Residual. Sufficient for many ISSO reviews of a Low-impact, ID-only, <$15,000 commercial item. Not sufficient for an ATO.
P-12MediumMulti-tenant isolation is not a proven production portal/employer-portal is a labeled browser demo. Paid seats load at /org-access. Do not treat the demo as tenant isolation evidence.Residual for anyone buying “agency-wide HR cloud.” In-scope for Scale as sold: numbered seats + IDs the agency types.
P-13Lowsecurity.txt was missing at start of this assessment/.well-known/security.txt 404 on first probeClosed in this drop — see that path after publish.

5. What we did not find (and did not claim)

  • No public answer-key file.
  • No public EIN on the invoice HTML (removed earlier; W-9 on request).
  • No camera/mic/geo permission prompts on public pages.
  • No evidence that cards touch ALA logs.
  • We did not run authenticated admin-console abuse, Cloudflare dashboard tests, or Mailgun account tests.

6. POA&M (open)

ItemOwnerTargetBlocks $14,500?
Independent 3PAO web application testALA, when a deal requires itOn contract demand, not speculative spendNo for exploration SKU under MPT. Yes for ATO / agency-wide production HR cloud.
PIV/SSOProductNot in this SKUNo — disclosed. Agency that needs PIV should not buy this SKU as the login system.
Customer-managed encryption keysNot offeredNo. Platform at-rest encryption only.
Tighten ACAO * if cookies are ever addedEngineeringBefore any cookie sessionNo today.
Federal bank freeze label aligned to scorer stampPsychometricsNext Federal Fit freeze rebuildNo. Scoring still uses the Federal Fit key set, not Career Fit items.

7. Residual risk statement (for the authorizing official)

FIPS 199 posture for this SKU is Low / Low / Low if the agency stores only Employer Worker IDs (not SSN, not classified, not CUI). Data volume for Scale is 290 profiles. Breach notice is 72 hours to the named contact. The realistic residual risks are (1) a stolen invite URL, (2) Cloudflare or Stripe as inherited platforms, and (3) the absence of an independent pentest letter. Those are the risks the agency accepts if it buys Federal Fit as exploration / mobility / development decision support — not as a qualification determination and not as an authorized information system.

If the agency needs to process CUI, require PIV, or issue an ATO, this SKU is the wrong buy. Companion files: SSP-lite · DPA · architecture.

Security contact: team@advancedlearning.academy · 1-317-751-5444. After hours: same number, Carol Roberts office path. Preferred disclosure: /.well-known/security.txt.