Security for turnstiles, biometrics, member apps, recurring billing and corporate benefit integrations.
Why now
Gyms hold biometrics, recurring bank data, photos, weight and measurements — in cheap, multi-tenant systems integrated with Gympass, TotalPass and corporate benefits. Biometric leaks are unrecoverable. And attackers map gyms as entry points into large corporations via enrolled employees.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Fingerprint bypass, card cloning, entry fraud, template replay.
Isolation between franchisees, unauthorized cross-unit access, data segregation.
IDOR on workouts, progress, before/after photos, trainer conversations.
Improper charges, cancellation, card tokenization security.
Eligibility validation, check-in fraud, corporate plan abuse.
Health data privacy, measurement integrity, history custody.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
SmartFit (market reference). Sector prioritized in our expansion strategy across southern Brazil, Portugal and Italy.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Both. We recommend a combination: deep pentest on the franchisor + sample pentest on representative units.
Yes. LGPD art. 5, II. Leaks trigger ANPD notification duty and near-automatic collective moral damages.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.