In-depth penetration testing for SaaS that needs to pass SOC 2, ISO 27001 and enterprise due diligence.

Offensive security assessments built for B2B SaaS. Full coverage of multi-tenant isolation, SSO/SAML, OAuth/OIDC, BOLA/BFLA/BOPLA, webhooks and billing flows. Reports formatted for SOC 2 Type II and ISO 27001 audits.

  • Mutual NDA within 24h
  • Retest included
  • Direct contact with the researcher

Why SaaS

The bug that sinks a SaaS is not the bug that takes down a brochure site

Every B2B SaaS shares the same risk pattern: one customer being able to see another customer's data. That's catastrophic — it breaches your contracts, violates data protection law (such as Brazil's LGPD) and kills the renewal. This type of bug is called BOLA (Broken Object Level Authorization), and it sits at #1 on the OWASP API Top 10.

BOLA doesn't show up in a scanner. It shows up when a researcher:

  • Creates two accounts in different tenants
  • Exhaustively maps every endpoint
  • Tries swapping IDs across tenants
  • Tests every endpoint with every combination of roles
  • Looks for mass assignment in every form

That's the work No Vuln does. At scale. With a proprietary Auth Matrix that maps roles × endpoints × verbs automatically, and human review of every combination.

Scope

What our SaaS penetration testing covers

Multi-tenant isolation

  • Cross-tenant BOLA on every endpoint (REST, GraphQL, WebSocket)
  • Cross-tenant access via indirect parameters (cookies, headers, JWT claims)
  • Leaks through search/filter endpoints
  • Upload isolation (S3/GCS prefixes, CDN)
  • Isolation in background jobs and queues
  • Isolation in outbound webhooks
  • Cross-tenant cache poisoning (CDN, Redis)

Single Sign-On (SSO)

  • SAML — XML Signature Wrapping (XSW), assertion replay, IdP confusion
  • OIDC — state confusion, redirect URI fuzzing, token swap
  • SCIM — provisioning across IdPs, escalation via group membership
  • Just-in-Time provisioning — tenant guessing via email domain
  • Linking an SSO account to a password account — potential takeovers

OAuth 2.0 / OIDC (your APIs as the provider)

  • Authorization Code flow — PKCE bypass, code injection
  • Implicit / Hybrid flows — token leakage
  • State fuzzing, redirect URI fuzzing, scope escalation
  • Refresh token theft, rotation issues
  • Confused deputy when your SaaS is an OAuth client of third parties

API hardening (OWASP API Top 10)

  • BOLA (Broken Object Level Authorization)
  • BFLA (Broken Function Level Authorization)
  • BOPLA (Broken Object Property Level Authorization) + mass assignment
  • Excessive data exposure
  • Rate limit bypass via headers, IP rotation, batch attacks
  • GraphQL: introspection abuse, alias overload, query depth bombs

Webhooks (outbound and inbound)

  • SSRF via the webhook callback URL configured by the customer
  • Replay attacks on the webhooks you send
  • Signature bypass (timing attacks on HMAC, length extension)
  • Race conditions in callbacks (a duplicate callback causing double processing)
  • Webhook forgery (forging a callback that looks legitimate)

Billing and plan management

  • Limit bypass through payload manipulation
  • Race conditions on plan upgrades/downgrades
  • Paywall bypass via direct API calls
  • Coupon/discount manipulation
  • Stripe/Adyen webhook signature bypass

Storage and exports

  • S3/GCS bucket isolation
  • Pre-signed URL leakage and long-TTL abuse
  • Export endpoints — CSV/PDF injection, formula injection
  • Path traversal in attachment downloads

Compliance

Reports formatted for SOC 2 and ISO 27001 audits

Our reports can be delivered in the format required by the leading compliance frameworks:

  • SOC 2 Type II — Common Criteria CC7.1 (vulnerability scanning + pentest), CC4.1 (monitoring activities)
  • ISO/IEC 27001:2022 — Annex A control 8.29 (security testing in development and acceptance) and 8.8 (management of technical vulnerabilities)
  • LGPD Art. 46 (Brazil's data protection law) — technical measures to protect customer data, for companies serving Brazilian users
  • PCI DSS 4.0 — for SaaS that processes card data (requirements 11.4.x)

Your auditor wants a written pentest? Our report covers it. An enterprise customer asks for evidence? We send an executive summary formatted for the C-suite.

Pricing

SaaS penetration testing pricing

ScenarioPrice rangeCoverage
Early-stage SaaS (MVP, PMF stage)Sprint (25h): US$ 3,750 to US$ 6,250Multi-tenant web + API, black box
Production SaaS, pre-SOC 2Deep Dive (50h): US$ 7,500 to US$ 12,500+ SSO + OAuth + webhooks + billing
Enterprise SaaS / ISO 27001 readinessFull Scope (100h+): from US$ 15,000Full white box + mobile + cloud + integrations
Recurring, for growing SaaSPTaaS: on requestMonthly focused pentests + monitoring + alerts

Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.

FAQ

Frequently asked questions

  • Why does B2B SaaS need a dedicated penetration test?

    Because the bugs that sink a SaaS company are different: cross-tenant BOLA, data leaking between customers, privilege escalation through a misconfigured SSO. These bugs don't show up in a scanner — they're found by a researcher who creates two accounts in different tenants and tests cross-access by hand.

  • Do you deliver reports formatted for SOC 2 and ISO 27001?

    Yes. Reports address Common Criteria CC7.1 (SOC 2) and Annex A 8.29 + 8.8 (ISO 27001:2022). You get an executive summary formatted for the auditor, a technical report for the engineering team and a compliance statement.

  • How much does SaaS penetration testing cost?

    Early-stage SaaS: Sprint (25h), US$ 3,750 to US$ 6,250. Production SaaS preparing for SOC 2: Deep Dive (50h), US$ 7,500 to US$ 12,500. Enterprise SaaS / ISO 27001 readiness: Full Scope (100h+), from US$ 15,000. PTaaS (recurring): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.

  • What is BOLA and why is it critical for SaaS?

    BOLA (Broken Object Level Authorization) is #1 on the OWASP API Top 10. It happens when an API endpoint receives an ID and returns the object without checking whether the user is allowed to access it. In a multi-tenant SaaS, it lets one customer see another customer's data — a breach of contract and of data protection laws such as Brazil's LGPD.

Next step

Ready to test your SaaS?

Send us your scope. Mutual NDA within 24h, formal proposal within 3 business days after the technical call.

Talk to a researcher