All case studies
SaaS & Platforms
Web Application Penetration Testing
Multi-tenant isolation review for a B2B SaaS ahead of enterprise onboarding
Authenticated testing across four tenant personas confirmed strong perimeter controls but revealed cross-tenant data leakage through an export job and a background webhook worker.
- Client
- Series B workflow automation SaaS with 900 business customers
- Duration
- 2 weeks (2 testers)
- Headline issue
- Cross-tenant export leakage in asynchronous job processing
- Sector
- SaaS & Platforms
The challenge
An enterprise prospect required independent proof that tenant data could not cross boundaries, including in asynchronous processing paths that most scanners never reach.
Our approach
- Provisioned four tenants with overlapping identifiers to make leakage observable.
- Tested synchronous APIs, background jobs, exports, webhooks and search indexing separately.
- Reviewed row-level authorisation in the data layer alongside black-box testing.
Outcome
- Two cross-tenant leakage paths closed before enterprise onboarding.
- Tenant scoping added to the background job framework as a default.
- Attestation letter issued and used in the client's security questionnaire responses.
More case studies
Financial Services
Payments platform API penetration test uncovers account takeover chain
A grey-box API assessment across 180 endpoints exposed a broken object-level authorisation chain that allowed full merchant account takeover without user interaction.
Healthcare
Internal network assessment for a hospital group with legacy medical systems
A carefully constrained internal assessment achieved domain administrator access in under two days through legacy credential reuse, without disrupting a single clinical system.