Vendor-conducted · 29 August 2026 · ASA-RWC-FED-2026-08-29
Application security assessment — not a 3PAO pentest.
This is the evidence an ISSO can file with a $14,500 Scale (290-seat) micro-purchase. It is an internal, defensive review of the live authorization boundary. It is not a FedRAMP 3PAO penetration test, not a SOC 2 report, and not an authorization. No exploit payloads were written or run against production.
1. Rules of engagement
| Item | Statement |
|---|---|
| Target | realworldcareers.com, APIs on Cloudflare Workers (/api/score, /api/report, checkout entitlement), public assessment banks |
| Date | 29 August 2026 (America/New_York evidence window) |
| Assessor | Advanced Learning Academy LLC (vendor). Not an independent firm. |
| Methods | TLS handshake, response-header review, authenticated vs unauthenticated API probes, public-path secret scan, CORS preflight, report-ID lookup, unpaid vs paid scoring, source review of Workers and Pages. No exploit development. No destructive testing. No credential stuffing. |
| Out of scope | Stripe and Mailgun interiors, Cloudflare control plane, agency networks, social engineering, physical, 3PAO red team |
2. Boundary (same as the SSP-lite)
Browser → TLS 1.3 → Cloudflare Pages (HTML) and Workers (score, jobs, entitlement) → D1 (credentials, scores) and R2 (files). Cards go only to Stripe. Transactional mail is Mailgun. No agency on-prem agent. No camera, microphone, or geolocation. Participants authenticate with a unique seat link, not PIV/SSO, in this SKU.
3. Encryption and transport (walked)
- TLS 1.3, AES-256, SHA-384. Certificate CN=
realworldcareers.com, not after 30 Oct 2026 (Cloudflare-managed). - HSTS:
max-age=31536000; includeSubDomains. - HTTP→HTTPS and www→apex 301.
- In transit: TLS on the public origin and Worker APIs.
- At rest: Cloudflare D1 and R2 are encrypted at rest by the platform. ALA does not hold customer-managed (CMK) keys. This is a platform statement, not a separate SOC 2 letter.
- No PAN on ALA servers. Stripe is the card processor.
4. Findings
| ID | Sev | Finding | Evidence (29 Aug 2026) | Disposition |
|---|---|---|---|---|
| P-01 | Pass | Security headers present | CSP (frame-ancestors none), X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy camera/mic/geo empty | Keep. Do not strip unsafe-inline from CSP without a full smoke — historical outage class. |
| P-02 | Pass | Unpaid full scoring blocked | POST /api/score with 50 items and no credential → 402 ENTITLEMENT_REQUIRED | Keep. |
| P-03 | Pass | Answer keys not in the public bank | /assets/assessment/*.public.json has stems and options only. No answer_index. Keys stay in the Worker. | Keep. Do not ship keys in Pages. |
| P-04 | Pass | Report IDOR on unknown IDs | GET /api/report?id=RWC-RPT-001 → 404. Public sample RWC-RPT-086 is intentional and stores no name. | Keep sample public. Production cohort reports stay behind the agency seat wallet. |
| P-05 | Pass | Paid scoring rate cap | Worker enforces 20 full scores / hour / credential (demo code 8). | Keep. |
| P-06 | Pass | Secret paths not published | /.git/config, /.env, /wrangler.toml not served as secrets. /api/_keys.json is the engine health JSON, not the key file. | Keep. |
| P-07 | Low | CORS Access-Control-Allow-Origin: * on Pages and score API | Public origin sets ACAO *. Score API same. No session cookies on the federal HTML origin. | Accept for this SKU (no cookie session). Do not add credentialed CORS without a named origin allow-list. |
| P-08 | Low | Preview scoring is a 3-item oracle | 1-item and 3-item unpaid POSTs return 200 with preview:true. Full 50 remains 402. | Accept. Preview is not an official result. Brute-forcing 3 items does not unlock a paid composite. |
| P-09 | Low | Federal bank freeze vs scorer stamp | Public Federal Fit bank freeze 2026.08-B-keybalance-v2. Scorer JSON stamps form_version: 2026.08-C (Career Fit freeze). Hiring/Federal banks were not rebuilt to C. | Documented on methodology. Not a data leak. Do not mix keys across forms. |
| P-10 | Medium | Seat links are bearer tokens | This SKU has no PIV/SSO/SAML. Possession of the unique link is access to that seat. | Residual. Agency sends links in its own mail. Treat like a one-time exam URL. SSO is a different product. |
| P-11 | Medium | No independent 3PAO pentest | This file is vendor-conducted. No SOC 2 Type II letter. No FedRAMP SAR. | Residual. Sufficient for many ISSO reviews of a Low-impact, ID-only, <$15,000 commercial item. Not sufficient for an ATO. |
| P-12 | Medium | Multi-tenant isolation is not a proven production portal | /employer-portal is a labeled browser demo. Paid seats load at /org-access. Do not treat the demo as tenant isolation evidence. | Residual for anyone buying “agency-wide HR cloud.” In-scope for Scale as sold: numbered seats + IDs the agency types. |
| P-13 | Low | security.txt was missing at start of this assessment | /.well-known/security.txt 404 on first probe | Closed in this drop — see that path after publish. |
5. What we did not find (and did not claim)
- No public answer-key file.
- No public EIN on the invoice HTML (removed earlier; W-9 on request).
- No camera/mic/geo permission prompts on public pages.
- No evidence that cards touch ALA logs.
- We did not run authenticated admin-console abuse, Cloudflare dashboard tests, or Mailgun account tests.
6. POA&M (open)
| Item | Owner | Target | Blocks $14,500? |
|---|---|---|---|
| Independent 3PAO web application test | ALA, when a deal requires it | On contract demand, not speculative spend | No for exploration SKU under MPT. Yes for ATO / agency-wide production HR cloud. |
| PIV/SSO | Product | Not in this SKU | No — disclosed. Agency that needs PIV should not buy this SKU as the login system. |
| Customer-managed encryption keys | — | Not offered | No. Platform at-rest encryption only. |
| Tighten ACAO * if cookies are ever added | Engineering | Before any cookie session | No today. |
| Federal bank freeze label aligned to scorer stamp | Psychometrics | Next Federal Fit freeze rebuild | No. Scoring still uses the Federal Fit key set, not Career Fit items. |
7. Residual risk statement (for the authorizing official)
FIPS 199 posture for this SKU is Low / Low / Low if the agency stores only Employer Worker IDs (not SSN, not classified, not CUI). Data volume for Scale is 290 profiles. Breach notice is 72 hours to the named contact. The realistic residual risks are (1) a stolen invite URL, (2) Cloudflare or Stripe as inherited platforms, and (3) the absence of an independent pentest letter. Those are the risks the agency accepts if it buys Federal Fit as exploration / mobility / development decision support — not as a qualification determination and not as an authorized information system.
If the agency needs to process CUI, require PIV, or issue an ATO, this SKU is the wrong buy. Companion files: SSP-lite · DPA · architecture.
Security contact: team@advancedlearning.academy · 1-317-751-5444. After hours: same number, Carol Roberts office path. Preferred disclosure: /.well-known/security.txt.