SaaS tenant isolation review
Anonymised pattern: multi-tenant B2B SaaS preparing for enterprise security questionnaires.
Context
A product team needed web+API testing before a set of enterprise deals. Primary concern: whether users in one workspace could read or modify another tenant’s data through IDOR-style and workflow abuses.
Approach
Scoped authenticated testing across standard and admin roles on staging that mirrored production authorisation. Emphasised object-level authorisation, invitation flows and export features rather than only injection classes.
Outcomes (qualitative)
- Several high-impact authorisation issues validated with evidence and clear reproduction steps
- Engineering received prioritised fixes tied to concrete code owners
- Retest confirmed closure of the agreed critical/high items before customer review
No confidential payloads or client identifiers are published here.
Related services
Web application penetration testing · API security testing · VAPT India
Need a scope-based estimate?
Share your application, infrastructure or security requirement and PocForge will help define the right assessment.
