All case studies
SaaS & Platforms
Web Application Penetration Testing

Multi-tenant isolation review for a B2B SaaS ahead of enterprise onboarding

Authenticated testing across four tenant personas confirmed strong perimeter controls but revealed cross-tenant data leakage through an export job and a background webhook worker.

Client
Series B workflow automation SaaS with 900 business customers
Duration
2 weeks (2 testers)
Headline issue
Cross-tenant export leakage in asynchronous job processing
Sector
SaaS & Platforms

The challenge

An enterprise prospect required independent proof that tenant data could not cross boundaries, including in asynchronous processing paths that most scanners never reach.

Our approach

  • Provisioned four tenants with overlapping identifiers to make leakage observable.
  • Tested synchronous APIs, background jobs, exports, webhooks and search indexing separately.
  • Reviewed row-level authorisation in the data layer alongside black-box testing.

Outcome

  • Two cross-tenant leakage paths closed before enterprise onboarding.
  • Tenant scoping added to the background job framework as a default.
  • Attestation letter issued and used in the client's security questionnaire responses.