CASE STUDY / SAAS

SaaS tenant isolation review

Anonymised pattern: multi-tenant B2B SaaS preparing for enterprise security questionnaires.

Context

A product team needed web+API testing before a set of enterprise deals. Primary concern: whether users in one workspace could read or modify another tenant’s data through IDOR-style and workflow abuses.

Approach

Scoped authenticated testing across standard and admin roles on staging that mirrored production authorisation. Emphasised object-level authorisation, invitation flows and export features rather than only injection classes.

Outcomes (qualitative)

  • Several high-impact authorisation issues validated with evidence and clear reproduction steps
  • Engineering received prioritised fixes tied to concrete code owners
  • Retest confirmed closure of the agreed critical/high items before customer review

No confidential payloads or client identifiers are published here.

Related services

Web application penetration testing · API security testing · VAPT India

Need a scope-based estimate?

Share your application, infrastructure or security requirement and PocForge will help define the right assessment.

Request a Quote →