// SaaS

Penetration testing for SaaS companies

Enterprise procurement will ask for 'the pentest'. We produce the document that closes that row: multi-tenant testing, a plain-English summary, and an attestation after retest.

Illustration of a web application login screen protected by a shield

Australian SaaS companies hit a wall around the first enterprise deal: a security questionnaire, a SOC 2 request, an ISO 27001 auditor, or a bank that will not sign until someone independent has tried to break the product. A vulnerability scan does not satisfy that counterparty. A 40-page finding dump with no executive summary does not either.

We test multi-tenant web applications and APIs the way a neighbouring customer, a disgruntled user or a motivated researcher would: logged in, swapping IDs, reading the GraphQL schema, walking forgotten v1 routes. The report is written so your engineers can patch this sprint and your customer can tick a box this quarter.

If you are mid-SOC 2 Type II or an ISO 27001 stage 2, tell us the control IDs during scoping. We will make the report speak to them. Background: ISO 27001 penetration testing in Australia.

Multi-tenant isolation

The finding that ends a Series B conversation if you get it wrong.

Customer admin vs staff admin

Vertical privilege, impersonation, 'view as user' that views too much.

Public API and webhooks

Signed payloads, replay, the debug endpoint from 2023.

SSO and SCIM

SAML/OIDC misconfiguration, account linking, the invite flow.

Talk to a tester, not a form-letter

Send the framework, the target and the date of the next audit. We will quote a test that produces evidence for that date.

Get a fixed quote