Prismware Logo
Stan Stokes

Closing Critical Security Gaps Without Disrupting Production

The Challenge

GuestX connects call activity to real business outcomes for its customers, which means uptime and security aren't optional; they're the product. An audit of the platform's web infrastructure surfaced meaningful exposure: subdomains were not routed through a security proxy, SSL configuration allowed downgrade paths instead of enforcing strict encryption end to end, and front-end code contained a wildcard postMessage origin alongside a CORS configuration that was too permissive for a production environment.

Our Solution

Prismware ran a full security audit of GuestX's web infrastructure and moved every subdomain behind a Cloudflare proxy, correcting SSL mode to Full (Strict) to eliminate the downgrade path. The wildcard postMessage origin and permissive CORS configuration were identified precisely and flagged to the internal development team with concrete fixes rather than vague recommendations, so the changes could be shipped without guesswork or unnecessary downtime.

Results

Cloudflare proxy was enabled across all subdomains, giving GuestX a consistent security and performance layer at the edge. SSL mode was corrected to Full (Strict), closing the downgrade exposure entirely. The wildcard postMessage origin and the CORS-in-production issue were documented and handed to the development team with specific remediation guidance, and Prismware negotiated ongoing managed services pricing to keep the environment monitored going forward.

“Prismware successfully delivered on Dynamics 365 and Microsoft 365 with Azure to power our unique business needs.”

Stan Stokes, Founder & CEO — GuestX

Services Used