A pentest your enterprise customers accept.
We test your app and API the way an attacker would, focused on what breaks multi-tenant SaaS: one customer seeing another customer's data.
Who it's for
- A prospect's security team asked for a recent pentest report
- You are preparing for SOC 2 or ISO 27001 and need pentest evidence
- You are about to launch and you handle sensitive data
- You grew fast and nobody has ever tested the app properly
What's covered
Tenant isolation
Can Company A reach Company B's records, files or admin functions?
Authorization
IDOR and BOLA, horizontal and vertical privilege escalation, role bypass.
Authentication
Login, password reset, MFA, sessions, tokens and SSO.
API security
Every endpoint against the OWASP API Security Top 10, including direct calls that skip the UI.
Business logic
Duplicate submissions, payment and credit abuse, workflow bypass.
Injection and input
SQL injection, XSS, SSRF, file upload and CSRF.
Exposure
Leaked secrets, verbose errors and sensitive data in responses.
External surface
Exposed services, misconfigured cloud resources, DNS and TLS.
What you get
Timeline5 to 15 working days of testing, report within 3 days after.
PriceFrom USD 3,500, fixed
- Executive summary you can share with customers under NDA
- Technical report: severity (CVSS), evidence, reproduction steps, impact and fix for every finding
- A clear list of what was tested and what was not
- Walkthrough call with your engineers
- Retest included, plus a closure letter for your auditor or customer
Not included
- Social engineering and phishing (on request)
- Load or DDoS testing
- Fixing the findings (add a fix sprint)
Related services
01 App Security Review + FixFor apps built with Cursor, Lovable or Bolt. We review, fix in your repo and retest. 02 Cloud & Infrastructure SecuritySafe deploys, locked-down cloud, real backups and monitoring. 03 SOC 2 & ISO 27001 ReadinessImplement controls once, map them to both frameworks, pass the audit. 04 Incident ResponseThink you've been hacked? Fast triage, evidence and containment.