Skip to content

Application

SaaS Penetration
Testing Services

Web application from $5,200, API from $4,000, fixed scope, free retest included. See all pricing →

Get a Fixed Quote

Three fields. A senior tester reads it and replies within one business day.

Prefer the full scoping questionnaire? 
OSCP & OSCE3 certified testers150+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When a SaaS company needs a penetration test

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • Your SOC 2 auditor, or Vanta, Drata, or Secureframe, is showing the penetration testing control as unmet.
  • An enterprise prospect sent a security questionnaire that asks for a recent third-party test and a report they can read.
  • You are multi-tenant and nobody outside the team has tried to cross from one customer’s data into another’s.
  • You just shipped SSO, a public API, a new admin role, or an integration marketplace, and the authorization model changed with it.
  • An investor, an acquirer, or a cyber insurer asked when the product was last tested by an outside firm.

Definitions

SaaS security assessment vs SaaS penetration test

Buyers and auditors use both terms. Here is what each one means and which you are getting.

SaaS security assessment

The broad term: any evaluation of how secure a SaaS product is, from a questionnaire to a configuration review. Enterprise security teams often say assessment when they want independent evidence, and a penetration test is the strongest form of it.

SaaS penetration test

The manual, attacker-driven test of the product, its API, and its cloud perimeter, run with real accounts in real tenants. This is what we sell, and it satisfies a request for either term because the report covers the questions an assessment would ask.

Multi-tenant products need the second one. A questionnaire cannot tell you whether tenant A can read tenant B, only a tester with two tenants can.

What we look for

SaaS vulnerabilities we hunt for

A SaaS product concentrates every customer behind one codebase and one login page. The findings that matter are the ones that let one tenant, one role, or one integration reach further than it should.

Tenant isolation failures

The finding a SaaS buyer fears most: one customer reading, changing, or inferring another customer’s data through an identifier, a search, an export, or a report.

We test for

  • Cross-tenant object access through IDs, slugs, and file paths
  • Search, filter, export, and reporting features that leak across tenants
  • Shared caches, background jobs, and webhooks that mix tenant context
  • Subdomain, custom-domain, and branding features that cross boundaries
  • Data left reachable after a user or tenant is removed

Role and permission abuse

Members reaching administrator functions, invited users keeping access they should have lost, and workspace roles that were never enforced on the API.

We test for

  • Vertical escalation from member to admin and owner
  • Invitation, seat, and role-change flows
  • Function-level authorization on every endpoint the interface calls
  • Billing, plan, and quota enforcement
  • Audit-log gaps that hide the abuse

Authentication, SSO, and sessions

The single login page that protects every customer, and the SSO, MFA, and recovery flows around it.

We test for

  • SAML and OIDC misconfiguration and assertion handling
  • MFA enrollment, bypass, and recovery paths
  • Session lifetime, revocation, and token storage
  • Password reset and magic-link abuse
  • Brute-force and credential-stuffing exposure

API surface and integrations

The API your front end, your mobile app, and your customers’ integrations all call, where broken object-level authorization lives.

We test for

  • Broken object and function level authorization across roles and tenants
  • API key and OAuth scope enforcement for integrations
  • Rate limiting on expensive and sensitive endpoints
  • Webhook signature and origin validation
  • Deprecated and undocumented endpoints still alive

Cloud perimeter and configuration

The AWS, Azure, or GCP account that hosts the product, and the storage, identities, and edges around it.

We test for

  • Exposed storage, snapshots, and backups
  • IAM and service-account privilege escalation paths
  • Metadata service and secrets exposure
  • Staging and preview environments left public
  • Network and security-group misconfiguration

Data exposure in ordinary responses

Fields, files, and metadata returned to users who should never see them, invisible to scanners because every response is a valid 200.

We test for

  • Over-broad API responses and mass assignment
  • Sensitive data in logs, errors, and analytics events
  • Export and download features that skip authorization
  • Third-party SDK and analytics data flows
  • Encryption in transit and at rest for customer data

Pricing

How SaaS penetration testing is priced

SaaS scopes are built from the published prices of the tests they contain. There is no SaaS surcharge and no bundle markup.

Web application

The product and every role, from $5,200 for a single application with a couple of roles. Multi-role, multi-tenant products with an admin console and a customer portal move up the published tiers.

API

The endpoints behind the product and the integrations customers connect to, from $4,000, sized by endpoint count and role model.

Cloud

The AWS, Azure, or GCP environment that hosts the product, from $6,800, sized by accounts and identity complexity.

Recurring

Products that ship weekly run the tests on a schedule as a testing program, priced once for the year, with validated scanning between windows.

Most first SaaS engagements are the web application test plus the API test. Read what a penetration test costs for the market picture around those numbers.

The report

A report you can hand to your own customers

SaaS companies use a penetration test twice: once for the auditor and once for every prospect whose security team asks for it. The engagement produces both documents. The full report, with findings and evidence, goes to your engineers and your auditor. The attestation letter, a signed summary of scope, dates, methodology, and outcome with no technical detail, goes to prospects, partners, and insurers, and it is written so a buyer’s security team can accept it without a call.

When your SOC 2 auditor is the reason for the test, the findings are also mapped to the Trust Services Criteria and delivered as separate files so they upload cleanly into Vanta, Drata, Secureframe, or your GRC platform. Our SOC 2 penetration testing page covers the criteria in detail, and our guide to penetration testing for SaaS companies explains what enterprise buyers look for in the result.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your SaaS penetration testing runs through.

  1. 01

    Scope & threat model

    Roles, tenants, data flows, and the abuse cases that matter most to your business.

  2. 02

    Recon & mapping

    Every endpoint, parameter, and integration enumerated before a single payload is sent.

  3. 03

    Manual exploitation

    OWASP-guided manual testing with targeted tooling, chaining findings into real attack paths.

  4. 04

    Impact validation

    Each finding proven exploitable and rated by what an attacker could actually reach.

  5. 05

    Report & retest

    Executive and technical reports, then a free retest once your fixes ship.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope by tenant and role

    We count the roles, tenants, API endpoints, and cloud accounts in play, then fix one price in writing for the whole assessment.

  2. 02

    Provision access

    You provide at least two tenants with an administrator and a member in each, API credentials, and a staging environment where one exists.

  3. 03

    Test by hand, role by role

    Every endpoint and feature is exercised as each role in each tenant, with the cross-tenant and cross-role cases attempted deliberately.

  4. 04

    Chain and prove

    Findings are chained into the paths a real attacker would use, each with evidence, and critical findings are escalated the day they are confirmed.

  5. 05

    Report, letter, retest

    A report for your auditor, an attestation letter for your customers, and a free retest once your engineers have shipped the fixes.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type. The findings and outcomes are real.

All case studies →

Free

Retest on every penetration test

150+

Years combined experience

13

Senior in-house specialists

24h

Onboarding after signing

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping SaaS penetration testing services.

Still have questions? 
01What is SaaS penetration testing?

A manual, authorized attack on a software-as-a-service product by testers who are given real accounts in real tenants. It covers the web application, the API behind it, the authentication and SSO flows, and the cloud environment that hosts it, with a deliberate focus on whether one tenant, role, or integration can reach beyond what it was granted. The output is a report for your auditor and engineers, an attestation letter for your customers, and a free retest once the findings are fixed.

02How do you test multi-tenant isolation?

With at least two tenants and at least two roles in each, provisioned by you before testing starts. Every feature that touches data is exercised as tenant A trying to reach tenant B, through identifiers, search, exports, reports, file storage, webhooks, and background jobs, and again as a member trying to reach administrator functions. Isolation failures are proven with evidence, not inferred from the code.

03Does a SaaS penetration test satisfy SOC 2?

It is the test SOC 2 auditors mean when they ask for “the pentest.” Findings are mapped to the Security criteria, the report and attestation letter upload into Vanta, Drata, or Secureframe, and the retest evidence shows the control operating, which is what a Type II examination needs. Scope it inside your observation window and early enough to fix and retest before it closes.

04How much does SaaS penetration testing cost?

Scopes are built from the published prices: the web application test from $5,200, the API test from $4,000, and the cloud configuration review from $6,800, each fixed in writing before work begins and each including a free retest. A typical first engagement for a single product is the web application and API tests together. Starting prices for every service are on our pricing page.

05How long does it take?

Onboarding begins within 24 hours of a signed proposal. Testing typically takes about a week for a single product with a couple of roles, longer for products with many roles, tenants, or endpoints, followed by the report within days and the retest once your fixes ship. Tell us your audit date or the prospect’s deadline and we plan the engagement around it.

06What do we need to provide?

Two tenants with an administrator and a member account in each, API credentials or an OpenAPI specification, read access to the cloud account for the configuration review, a staging environment where one exists, and a short scoping call. Rules of engagement for production testing are agreed in writing where staging is not available.

07Can we share the results with prospects?

Yes. The attestation letter exists for exactly that: a signed one-page summary of scope, dates, methodology, and outcome with no technical findings, written so a buyer’s security team can accept it. The full report stays with you and your auditor. Many clients also share the executive summary under NDA with larger prospects.

08We ship every week. Is one test a year enough?

An annual test is what auditors expect; whether it is enough depends on how fast the authorization model changes. Products that add roles, integrations, or tenant features monthly usually move to a testing program: scheduled manual test windows, validated scanning between them, and retests on demand, priced once for the year.

Ready to test your defenses?

Talk to our team about scoping SaaS penetration testing services.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.