Scope and authorize
We agree the environment, the plan tiers in scope and the test window in writing.
A multi-tenant test built around the question your own customers ask in their security reviews: can anyone using your product reach data that belongs to someone else? We sign up as two tenants and try.
Everything in a standard web application test applies to a SaaS product — and then tenancy sits underneath all of it. Isolation has to hold in the database, in the cache, in background jobs, in file storage, in exports and in every integration you offer.
We test with two live tenants side by side, which is the only way to prove separation rather than assume it. The report is written so you can hand it straight to a customer or an auditor.
Typically one to three weeks, depending on role matrix, integrations and plan tiers.
We agree the environment, the plan tiers in scope and the test window in writing.
We work from two separate tenants with the full role matrix in each, so isolation is tested rather than assumed.
Identifiers, tokens, exports, uploads, integrations and background jobs are all tested for leakage between tenants.
We check whether paid features, quotas and seat limits hold when the client stops cooperating.
You get a report suitable for customer security reviews, a readout and a retest of your fixes.
Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.
A tenant identifier accepted from the client and trusted by the server
Exports, reports or search indexes that were never scoped to one tenant
SSO configurations that let an attacker-controlled domain assert your users
De-provisioned users keeping access through an old token or API key
Plan limits enforced only in the interface
Missing something on this list? Bring it to the call — we scope around what you have.
Find and prove the weaknesses in your web applications before attackers do.
Read moreKeep the APIs that connect your products, partners and data from becoming the way in.
Read moreKeep your iOS and Android apps — and the services behind them — out of attackers’ hands.
Read moreMake sure your desktop apps, thick clients, browser extensions and agents don’t open a back door.
Read moreNot sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.