Blog

How CRMBonus achieved 80% vulnerability visibility in 1 week?

Discover how CRMBonus achieved 80% application vulnerability visibility in just one week, accelerating its AppSec program with rapid deployment and actionable security insights.

Rainforest Technologies·Jul 14, 2026·3 min read·Reviewed by Rainforest Technologies
Rainforest and CRMBonus logos

Transforming cybersecurity visibility in one of the world’s largest giftback ecosystems

CRM Bonus operates one of the largest giftback ecosystems in the world, impacting more than 20 million people through solutions focused on customer engagement, cashback experiences, seller incentives, and AI-driven retail intelligence.

As the company accelerated growth, product expansion, and integration with enterprise customers, cybersecurity visibility became a critical operational requirement.

When Daniel Peres joined the company as CISO, one challenge became immediately clear: the organization lacked centralized visibility into vulnerabilities, security gaps, and monitoring across its application and development environment.

To support the evolution of its security operation, CRM Bonus partnered with Rainforest Technologies.

The goal was straightforward: gain visibility, establish control, and build a scalable security monitoring foundation capable of supporting a fast-growing technology operation.

The challenge

Like many rapidly scaling technology companies, CRM Bonus faced a common but critical problem: security data existed in fragmented silos — or, in some cases, simply did not exist in an actionable way.

Without centralized visibility, the security team faced major limitations:

  • Limited understanding of existing vulnerabilities and security exposures.
  • Difficulty prioritizing remediation efforts.
  • Reduced ability to demonstrate risks internally.
  • Challenges justifying security investments and budget allocation.
  • Lack of centralized monitoring across development pipelines and applications.
  • Limited operational control over security posture evolution.

For leadership, the issue was not only technical.

Without visibility, security became reactive instead of strategic.

Building visibility at speed

Rainforest Technologies helped CRM Bonus rapidly implement a more centralized and operational approach to application security visibility.

By integrating monitoring and security analysis into the company’s technology environment, the security team quickly gained access to actionable insights across vulnerabilities, configurations, and development workflows.

The impact was immediate.

Within approximately one to two weeks, the organization evolved from virtually no centralized vulnerability visibility to approximately 80% visibility across its environment.

This rapid deployment enabled the security team to begin identifying, monitoring, and prioritizing vulnerabilities at a pace that previously was not possible.

Operational impact

The implementation fundamentally changed how the organization approached cybersecurity operations.

According to the security leadership team, Rainforest enabled CRM Bonus to establish significantly greater control over its environment, including:

  • Centralized monitoring of vulnerabilities.
  • Improved visibility into security gaps and misconfigurations.
  • Continuous monitoring across the software development pipeline.
  • Faster remediation prioritization.
  • Better operational awareness of security risks and attack vectors.
  • Increased maturity in decision-making around cybersecurity investments.

The company also gained a stronger ability to communicate risk internally.

Instead of relying on assumptions or isolated findings, the security team could now present real operational data, helping leadership better understand where investments were needed and which areas represented the highest priority.

Security as a business enabler

One of the most important shifts was cultural.

With better visibility came stronger alignment between cybersecurity, technology leadership, and business decision-making.

The organization moved from reacting to isolated security issues toward building a more measurable and strategic cybersecurity operation.

This visibility also improved the company’s ability to support secure scale — particularly important for a platform handling millions of users, integrations, and customer-facing applications.

Customer perspective

“When I arrived here, we basically had zero visibility. With Rainforest’s support, we went from 0 to 80% vulnerability visibility in about one to two weeks. The speed at which we gained visibility and started handling vulnerabilities, misconfigurations, and security issues was incredible.” — Daniel Peres, CISO at CRM Bonus

Keep reading