In-depth penetration testing for SaaS that needs to pass SOC 2, ISO 27001 and enterprise due diligence.
Offensive security assessments built for B2B SaaS. Full coverage of multi-tenant isolation, SSO/SAML, OAuth/OIDC, BOLA/BFLA/BOPLA, webhooks and billing flows. Reports formatted for SOC 2 Type II and ISO 27001 audits.
- Mutual NDA within 24h
- Retest included
- Direct contact with the researcher
Why SaaS
The bug that sinks a SaaS is not the bug that takes down a brochure site
Every B2B SaaS shares the same risk pattern: one customer being able to see another customer's data. That's catastrophic — it breaches your contracts, violates data protection law (such as Brazil's LGPD) and kills the renewal. This type of bug is called BOLA (Broken Object Level Authorization), and it sits at #1 on the OWASP API Top 10.
BOLA doesn't show up in a scanner. It shows up when a researcher:
- Creates two accounts in different tenants
- Exhaustively maps every endpoint
- Tries swapping IDs across tenants
- Tests every endpoint with every combination of roles
- Looks for mass assignment in every form
That's the work No Vuln does. At scale. With a proprietary Auth Matrix that maps roles × endpoints × verbs automatically, and human review of every combination.
Scope
What our SaaS penetration testing covers
Multi-tenant isolation
- Cross-tenant BOLA on every endpoint (REST, GraphQL, WebSocket)
- Cross-tenant access via indirect parameters (cookies, headers, JWT claims)
- Leaks through search/filter endpoints
- Upload isolation (S3/GCS prefixes, CDN)
- Isolation in background jobs and queues
- Isolation in outbound webhooks
- Cross-tenant cache poisoning (CDN, Redis)
Single Sign-On (SSO)
- SAML — XML Signature Wrapping (XSW), assertion replay, IdP confusion
- OIDC — state confusion, redirect URI fuzzing, token swap
- SCIM — provisioning across IdPs, escalation via group membership
- Just-in-Time provisioning — tenant guessing via email domain
- Linking an SSO account to a password account — potential takeovers
OAuth 2.0 / OIDC (your APIs as the provider)
- Authorization Code flow — PKCE bypass, code injection
- Implicit / Hybrid flows — token leakage
- State fuzzing, redirect URI fuzzing, scope escalation
- Refresh token theft, rotation issues
- Confused deputy when your SaaS is an OAuth client of third parties
API hardening (OWASP API Top 10)
- BOLA (Broken Object Level Authorization)
- BFLA (Broken Function Level Authorization)
- BOPLA (Broken Object Property Level Authorization) + mass assignment
- Excessive data exposure
- Rate limit bypass via headers, IP rotation, batch attacks
- GraphQL: introspection abuse, alias overload, query depth bombs
Webhooks (outbound and inbound)
- SSRF via the webhook callback URL configured by the customer
- Replay attacks on the webhooks you send
- Signature bypass (timing attacks on HMAC, length extension)
- Race conditions in callbacks (a duplicate callback causing double processing)
- Webhook forgery (forging a callback that looks legitimate)
Billing and plan management
- Limit bypass through payload manipulation
- Race conditions on plan upgrades/downgrades
- Paywall bypass via direct API calls
- Coupon/discount manipulation
- Stripe/Adyen webhook signature bypass
Storage and exports
- S3/GCS bucket isolation
- Pre-signed URL leakage and long-TTL abuse
- Export endpoints — CSV/PDF injection, formula injection
- Path traversal in attachment downloads
Compliance
Reports formatted for SOC 2 and ISO 27001 audits
Our reports can be delivered in the format required by the leading compliance frameworks:
- SOC 2 Type II — Common Criteria CC7.1 (vulnerability scanning + pentest), CC4.1 (monitoring activities)
- ISO/IEC 27001:2022 — Annex A control 8.29 (security testing in development and acceptance) and 8.8 (management of technical vulnerabilities)
- LGPD Art. 46 (Brazil's data protection law) — technical measures to protect customer data, for companies serving Brazilian users
- PCI DSS 4.0 — for SaaS that processes card data (requirements 11.4.x)
Your auditor wants a written pentest? Our report covers it. An enterprise customer asks for evidence? We send an executive summary formatted for the C-suite.
Pricing
SaaS penetration testing pricing
| Scenario | Price range | Coverage |
|---|---|---|
| Early-stage SaaS (MVP, PMF stage) | Sprint (25h): US$ 3,750 to US$ 6,250 | Multi-tenant web + API, black box |
| Production SaaS, pre-SOC 2 | Deep Dive (50h): US$ 7,500 to US$ 12,500 | + SSO + OAuth + webhooks + billing |
| Enterprise SaaS / ISO 27001 readiness | Full Scope (100h+): from US$ 15,000 | Full white box + mobile + cloud + integrations |
| Recurring, for growing SaaS | PTaaS: on request | Monthly focused pentests + monitoring + alerts |
Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.
FAQ
Frequently asked questions
Why does B2B SaaS need a dedicated penetration test?
Because the bugs that sink a SaaS company are different: cross-tenant BOLA, data leaking between customers, privilege escalation through a misconfigured SSO. These bugs don't show up in a scanner — they're found by a researcher who creates two accounts in different tenants and tests cross-access by hand.
Do you deliver reports formatted for SOC 2 and ISO 27001?
Yes. Reports address Common Criteria CC7.1 (SOC 2) and Annex A 8.29 + 8.8 (ISO 27001:2022). You get an executive summary formatted for the auditor, a technical report for the engineering team and a compliance statement.
How much does SaaS penetration testing cost?
Early-stage SaaS: Sprint (25h), US$ 3,750 to US$ 6,250. Production SaaS preparing for SOC 2: Deep Dive (50h), US$ 7,500 to US$ 12,500. Enterprise SaaS / ISO 27001 readiness: Full Scope (100h+), from US$ 15,000. PTaaS (recurring): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.
What is BOLA and why is it critical for SaaS?
BOLA (Broken Object Level Authorization) is #1 on the OWASP API Top 10. It happens when an API endpoint receives an ID and returns the object without checking whether the user is allowed to access it. In a multi-tenant SaaS, it lets one customer see another customer's data — a breach of contract and of data protection laws such as Brazil's LGPD.
Next step
Ready to test your SaaS?
Send us your scope. Mutual NDA within 24h, formal proposal within 3 business days after the technical call.
Talk to a researcher