Skip to content
kubepath Book a call
Menu

A pentest your enterprise customers accept.

We test your app and API the way an attacker would, focused on what breaks multi-tenant SaaS: one customer seeing another customer's data.

Who it's for

  • A prospect's security team asked for a recent pentest report
  • You are preparing for SOC 2 or ISO 27001 and need pentest evidence
  • You are about to launch and you handle sensitive data
  • You grew fast and nobody has ever tested the app properly

What's covered

Tenant isolation

Can Company A reach Company B's records, files or admin functions?

Authorization

IDOR and BOLA, horizontal and vertical privilege escalation, role bypass.

Authentication

Login, password reset, MFA, sessions, tokens and SSO.

API security

Every endpoint against the OWASP API Security Top 10, including direct calls that skip the UI.

Business logic

Duplicate submissions, payment and credit abuse, workflow bypass.

Injection and input

SQL injection, XSS, SSRF, file upload and CSRF.

Exposure

Leaked secrets, verbose errors and sensitive data in responses.

External surface

Exposed services, misconfigured cloud resources, DNS and TLS.

What you get

Timeline5 to 15 working days of testing, report within 3 days after.
PriceFrom USD 3,500, fixed
  • Executive summary you can share with customers under NDA
  • Technical report: severity (CVSS), evidence, reproduction steps, impact and fix for every finding
  • A clear list of what was tested and what was not
  • Walkthrough call with your engineers
  • Retest included, plus a closure letter for your auditor or customer

Not included

  • Social engineering and phishing (on request)
  • Load or DDoS testing
  • Fixing the findings (add a fix sprint)