Offensive security for SaaS and digital products.
In SaaS, security stopped being an infrastructure topic and became a contract item. Enterprise customers audit before they sign, and investors ask during due diligence. We test the product with both lenses.
The flaw that costs you the contract
In a multi-tenant product one question decides everything: can a customer see another customer's data? If the answer is yes on any path, little else matters much. Pressure for delivery speed, combined with permission models that grow by addition and are never reviewed as a whole, makes this class of flaw appear far more often than anyone expects.
- Tenant isolation is the requirement that admits no exception.
- The permission model grows by addition and is rarely reviewed end to end.
- Integrations, webhooks and API tokens widen the surface with every release.
- Enterprise sales stall without evidence of independent testing.
What we test in a SaaS product
We attack the product as a malicious customer who has already paid for a subscription — because that is the most likely scenario.
Systematic attempts to reach another tenant's data via identifiers, parameters, exports, search and cache. This is the central test.
Login, SSO, second factor, session expiry, user invitations and what access remains after someone is removed from the team.
Roles, scopes and inheritance: whether a restricted user reaches administrative functions through a direct API call.
Token scope, revocation, rate limiting and data exposed beyond what is necessary in responses.
Signature verification, replay protection and requests your backend makes to destinations supplied by the customer.
Files submitted by users: type handling, storage, processing isolation and content access through predictable URLs.
Evidence that unblocks sales and rounds
The material is prepared for the two audiences that will ask for it: your customer's security team and the investor's diligence team.
- Vendor questionnaires
- The attestation letter answers the independent penetration testing question that appears in practically every corporate security questionnaire.
- ISO 27001 and SOC 2
- Both programmes require periodic testing as a control. The report serves as evidence within that cycle, without replacing the audit itself.
- Data processing agreements
- As a processor of your customers' data, you answer contractually. We document exposure per tenant, which is the cut the contract asks about.
- Technical due diligence
- In a funding round or acquisition, recent testing with an executed remediation plan counts in your favour and avoids a risk discount.
How we run alongside a lean team
Staging first
Whenever a replica exists we start there. It frees us to test more aggressively and keeps real customer data out of the path.
Controlled tenant accounts
We create at least two test tenants with distinct data. Isolation is proven by trying to cross that boundary in every way available.
Critical findings reported immediately
An isolation or authentication failure does not wait for the report: it goes through a direct channel as soon as it is confirmed, so you can fix it the same day.
Remediation inside your release cycle
The plan is organised to fit a sprint, and the retest happens after the fix ships, without requiring a roadmap freeze.
What you receive
- Executive report for board and customers
- Reproducible technical report
- Dedicated multi-tenant isolation testing
- Permission model review
- Justified CVSS scoring
- Immediate notification of critical findings
- Retest after the fix ships
- Attestation letter for due diligence
Sector FAQ
Can you test without touching real customer data?
+
In most cases, yes. We prefer a staging environment with synthetic data, where we can be more aggressive without risk. When testing must happen in production, we create our own tenants and restrict activity to them, within agreed volume limits.
How long does a SaaS engagement take?
+
It depends on the size of the surface: number of roles, extent of the API and quantity of integrations. Scope is set after a short technical conversation mapping those three axes. What does not vary is the method: manual exploitation with every finding validated before it enters the report.
Does the report answer a customer security questionnaire?
+
It does, and that is one of the most common uses. The attestation letter confirms independent testing took place, with scope and period, without revealing exploitable detail — exactly what the questionnaire asks. You share the full technical report only if you choose to, under agreement.
What if you find a critical flaw mid-engagement?
+
You are notified immediately through a direct channel, with enough detail to fix it the same day. We do not hold critical findings until the end of a project. After remediation we retest and record the closed cycle in the final report.
Services applied to this sector
Ready to uncover your flaws?
First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.