Basilisk
BASILISK
[setor_saas]SAAS & STARTUPS

Offensive security for SaaS and digital products.

In SaaS, security stopped being an infrastructure topic and became a contract item. Enterprise customers audit before they sign, and investors ask during due diligence. We test the product with both lenses.

The flaw that costs you the contract

In a multi-tenant product one question decides everything: can a customer see another customer's data? If the answer is yes on any path, little else matters much. Pressure for delivery speed, combined with permission models that grow by addition and are never reviewed as a whole, makes this class of flaw appear far more often than anyone expects.

  • Tenant isolation is the requirement that admits no exception.
  • The permission model grows by addition and is rarely reviewed end to end.
  • Integrations, webhooks and API tokens widen the surface with every release.
  • Enterprise sales stall without evidence of independent testing.

What we test in a SaaS product

We attack the product as a malicious customer who has already paid for a subscription — because that is the most likely scenario.

// multi-tenant isolation

Systematic attempts to reach another tenant's data via identifiers, parameters, exports, search and cache. This is the central test.

// authentication and sessions

Login, SSO, second factor, session expiry, user invitations and what access remains after someone is removed from the team.

// permission model

Roles, scopes and inheritance: whether a restricted user reaches administrative functions through a direct API call.

// public API and tokens

Token scope, revocation, rate limiting and data exposed beyond what is necessary in responses.

// webhooks and integrations

Signature verification, replay protection and requests your backend makes to destinations supplied by the customer.

// upload and processing

Files submitted by users: type handling, storage, processing isolation and content access through predictable URLs.

Evidence that unblocks sales and rounds

The material is prepared for the two audiences that will ask for it: your customer's security team and the investor's diligence team.

Vendor questionnaires
The attestation letter answers the independent penetration testing question that appears in practically every corporate security questionnaire.
ISO 27001 and SOC 2
Both programmes require periodic testing as a control. The report serves as evidence within that cycle, without replacing the audit itself.
Data processing agreements
As a processor of your customers' data, you answer contractually. We document exposure per tenant, which is the cut the contract asks about.
Technical due diligence
In a funding round or acquisition, recent testing with an executed remediation plan counts in your favour and avoids a risk discount.

How we run alongside a lean team

01

Staging first

Whenever a replica exists we start there. It frees us to test more aggressively and keeps real customer data out of the path.

02

Controlled tenant accounts

We create at least two test tenants with distinct data. Isolation is proven by trying to cross that boundary in every way available.

03

Critical findings reported immediately

An isolation or authentication failure does not wait for the report: it goes through a direct channel as soon as it is confirmed, so you can fix it the same day.

04

Remediation inside your release cycle

The plan is organised to fit a sprint, and the retest happens after the fix ships, without requiring a roadmap freeze.

What you receive

  • Executive report for board and customers
  • Reproducible technical report
  • Dedicated multi-tenant isolation testing
  • Permission model review
  • Justified CVSS scoring
  • Immediate notification of critical findings
  • Retest after the fix ships
  • Attestation letter for due diligence

Sector FAQ

Can you test without touching real customer data?

+

In most cases, yes. We prefer a staging environment with synthetic data, where we can be more aggressive without risk. When testing must happen in production, we create our own tenants and restrict activity to them, within agreed volume limits.

How long does a SaaS engagement take?

+

It depends on the size of the surface: number of roles, extent of the API and quantity of integrations. Scope is set after a short technical conversation mapping those three axes. What does not vary is the method: manual exploitation with every finding validated before it enters the report.

Does the report answer a customer security questionnaire?

+

It does, and that is one of the most common uses. The attestation letter confirms independent testing took place, with scope and period, without revealing exploitable detail — exactly what the questionnaire asks. You share the full technical report only if you choose to, under agreement.

What if you find a critical flaw mid-engagement?

+

You are notified immediately through a direct channel, with enough detail to fix it the same day. We do not hold critical findings until the end of a project. After remediation we retest and record the closed cycle in the final report.

Services applied to this sector

// contact

Ready to uncover your flaws?

First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.