Industry

SAAS
security audit.

B2B SaaS lives or dies on the security questionnaire. SOC 2 Type II, ISO 27001, multi-tenant isolation, OAuth posture, sub-processor audits — we’ve scoped this exact work for hundreds of SaaS companies from seed to scale.

SAAS

The SaaS security checklist.

Enterprise buyers evaluate SaaS vendors against a security questionnaire (CAIQ-Lite, SIG, custom). The same patterns repeat: SOC 2 / ISO 27001 attestation, recent pen test report, multi-tenant isolation evidence, encryption details, incident response policies, sub-processor list, data residency. Our work is scoped to make every cell in that questionnaire defensible.

What we test.

Multi-tenant isolation

The #1 SaaS-specific bug class. Every multi-tenant boundary is tested: row-level data isolation, tenant-scoped API access, file storage isolation, async job context, queue routing, log isolation. We attempt cross-tenant access with every available role.

OAuth & SSO

SaaS authentication is almost always OAuth / OIDC against Okta, Azure AD, Auth0, Google Workspace. We test for PKCE bypass, scope escalation, refresh token replay, SCIM provisioning gaps, and the “Just-in-Time” user creation patterns that grant unintended access.

API surface

SaaS APIs are usually the largest attack surface. We test against the OWASP API Top 10 with deep focus on BOLA across tenant boundaries, BFLA on admin endpoints, and rate-limit abuse (which often correlates to billing).

Webhooks & integrations

Outbound webhooks introduce SSRF risk; inbound webhooks introduce authentication and replay risk. We test signature validation, idempotency, and timestamp drift.

Compliance alignment.

  • SOC 2 Type II — trust services criteria mapping (CC6, CC7, CC8)
  • ISO/IEC 27001:2022 — Annex A controls
  • SOC 3 public report support
  • GDPR Article 32 — technical measures evidence
  • UK Cyber Essentials Plus
  • HIPAA business associate agreement workloads
  • PCI-DSS for SaaS handling cardholder data

Built for velocity.

SaaS ships fast; pen tests can’t take three months. Our standard engagement timeline:

  • Scoping call — same week
  • Engagement start — within 2 weeks of SoW signature
  • Manual testing — 5–10 days
  • Report delivered — 3 days after testing ends
  • Customer-ready letter of attestation — same day as report
  • Free retest — within 30 days
Stop losing deals to security review

BOOK YOUR
SaaS audit.

Free 30-minute scoping call. Customer-ready letter of attestation included with every engagement.