SaaS Penetration Testing
SaaS penetration testing is a manual security assessment of a multi-tenant software product: its tenant isolation, role-based access control, subscription and billing logic, API layer, and SSO and SCIM provisioning. Testers attempt to cross tenant boundaries, read another customer's data, and escalate privileges the way a real attacker or malicious tenant would. Precursor delivers CREST-accredited SaaS pen tests from £3,750 for a small single-product SaaS with one or two roles. A mid-sized SaaS application with multiple roles, an API and SSO typically costs £6,250 to £8,750. Fixed-price, UK-based testers, aligned to OWASP ASVS and the OWASP API Security Top 10.
Whether you are closing an enterprise deal, preparing for SOC 2, or answering a customer security questionnaire, our CREST-accredited consultants test the risks unique to multi-tenant software: cross-tenant data access, role-based access control across organisations, API abuse, and SSO provisioning flaws. We prove your tenant isolation holds before an attacker or a curious customer finds out it does not.
What is SaaS
penetration testing?
A manual security assessment of a multi-tenant software product, focused on the risks a generic web app test does not reach: tenant isolation, role-based access control across organisations, subscription logic, and the API and identity layers that hold it all together.
SaaS penetration testing is a manual security assessment of a multi-tenant software product. The defining question is whether one tenant can cross into another's data or privileges. Testers attack the platform as a malicious tenant, a compromised low-privilege user, and an external attacker in turn. For the broader picture across every test type, our guide explains what penetration testing is.
Methodology is aligned to the OWASP Application Security Verification Standard (ASVS) and the OWASP API Security Top 10. Every finding carries a CVSS v3.1 score, an OWASP category mapping, and a CWE reference. The report is structured to satisfy SOC 2 CC7.1, ISO 27001 A.8.8, and GDPR Article 32, and to attach directly to enterprise security questionnaires.
Six test areas, led by tenant isolation
A generic web app test covers the OWASP Top 10. A SaaS test adds the multi-tenant product lens: the isolation, identity and business-logic risks that only exist because thousands of customers share one platform. It sits within our broader penetration testing services, and pairs with cloud penetration testing when your platform runs on AWS or Azure.
Multi-tenancy and tenant isolation
The defining SaaS risk: can tenant A read, alter, or delete tenant B's data? We attack tenant boundaries directly, tampering with tenant_id and organisation identifiers, probing shared-infrastructure blast radius, and checking whether isolation holds at the database, cache, object-storage and background-job layers, not just the UI.
RBAC and privilege escalation
Role explosion across organisation, workspace and user tiers is where SaaS access control breaks. We test horizontal and vertical escalation, from standard user to workspace admin to platform owner.
Multi-tenant API security
Aligned to the OWASP API Security Top 10: BOLA and IDOR across tenant boundaries, mass assignment, and rate-limit bypass on the REST and GraphQL endpoints your product exposes.
SSO, SAML and SCIM provisioning
Enterprise SaaS lives or dies on its identity layer. We test SAML assertion handling, just-in-time provisioning abuse, orphaned access after de-provisioning, and MFA bypass across your SSO and SCIM flows.
Subscription and billing logic
The abuse paths scanners never see: plan and quota bypass, entitlement and feature-flag manipulation, seat count tampering, trial abuse, and downgrade-to-retain-features flaws that quietly erode revenue.
Data segregation and secrets isolation
Per-tenant secrets, encryption boundaries, and export and backup paths. We confirm one tenant cannot reach another's keys, and that data export and reporting features do not leak across the boundary.
How a SaaS penetration test runs
Fixed-price, scoped around your tenancy model, with criticals surfaced live.
Scope and tenant mapping
A free scoping call maps your tenancy model, role tiers, API surface, and SSO configuration. We agree test tenants, rules of engagement, and a fixed price before any work begins.
Threat recon
We model how a malicious tenant, a compromised low-privilege user, and an external attacker would each approach your platform, then map the tenant-boundary and privilege paths worth attacking.
Manual exploitation
CREST-accredited testers manually exploit tenant isolation, RBAC, API, SSO and billing logic. Critical findings are surfaced live in the portal as they are confirmed, so your team can start remediation immediately.
Report and retest
You receive a developer-ready report with CVSS scores, reproduction steps, and remediation guidance, plus an executive summary for enterprise buyers and auditors. A retest of fixed findings is included.
Fixed-price by product size
Small single-product SaaS
1 to 2 roles
Mid-sized SaaS
Most commonMultiple roles, an API and SSO
Multi-app SaaS suite
Customer portal, admin portal and mobile backend
Fixed-price at approximately £1,200 per CREST-accredited consultant day. Retest of fixed findings included. Quoted within 24 hours. For the full breakdown, see our penetration testing cost guide.
Get a fixed-price quoteThe triggers that bring you here
SOC 2 and ISO 27001
An annual, independent penetration test is expected evidence for SOC 2 CC7.1 and ISO 27001 A.8.8.
Enterprise procurement
Large customers require accredited test evidence before they sign. A CREST report unblocks the security questionnaire and the deal.
Funding and growth
Investors and acquirers expect a clean, recent test. Many SaaS vendors test ahead of a Series A raise or enterprise expansion.
Related services
Where SaaS testing meets the rest of the offensive programme.
Web application penetration testing
The OWASP Top 10 methodology parent, for any single web application.
API security testing
Dedicated OWASP API Security Top 10 assessment of your REST and GraphQL endpoints.
Penetration testing cost
The full 2026 UK rate card by test type, scope and duration.
The best time to test your defences is now.
Join the high-growth companies relying on Precursor for continuous offensive and defensive security.
Frequently Asked Questions
Common questions about this service, methodologies, and deliverables.
A mid-sized SaaS application, meaning multiple user roles, an API, and single sign-on, typically costs between £6,250 and £8,750 for 5 to 7 days of testing. A small single-product SaaS with one or two roles starts at £3,750. A multi-application suite covering a customer portal, admin portal, and mobile backend ranges £8,750 to £13,750 or more. The main cost drivers are the number of roles and the size of the API surface, not the number of tenants. All engagements are fixed-price at approximately £1,200 per CREST-accredited consultant day, quoted within 24 hours of a scoping call.
SaaS penetration testing is a manual security assessment of a multi-tenant software product: its tenant isolation, role-based access control, subscription and billing logic, API layer, and SSO and SCIM provisioning. Testers attempt to cross tenant boundaries, read another customer's data, and escalate privileges the way a malicious tenant or external attacker would. It is aligned to OWASP ASVS and the OWASP API Security Top 10, and every finding carries a CVSS v3.1 score with reproduction steps.
Web application penetration testing assesses any single web application against the OWASP Top 10, covering broad surfaces like marketing sites, portals, and e-commerce. SaaS penetration testing applies that methodology through a multi-tenant product lens: tenant isolation, cross-tenant data leakage, RBAC across organisations, and subscription and entitlement logic, plus the commercial drivers a SaaS vendor faces such as SOC 2 and enterprise procurement. If you have a single web application to test, our web application penetration testing service is the right starting point. If you run a multi-tenant SaaS product, this page covers the additional tenant and identity risks.
Yes. A CREST-accredited SaaS penetration test provides the independent security testing evidence relevant to SOC 2 Trust Services Criterion CC7.1, and the report is structured for direct submission to your auditor. It also maps to ISO 27001:2022 Annex A.8.8, GDPR Article 32, and the security questionnaires enterprise customers send during procurement. We can provide a Letter of Attestation confirming testing scope and accreditation status if your auditor requires it.
We test against dedicated test tenants populated with dummy data, provisioned specifically for the engagement. To prove a cross-tenant isolation flaw, we demonstrate that tenant A can reach tenant B using two test tenants we control, never real customer records. All activity is logged for a full audit trail, and findings are delivered through an encrypted portal with role-based access controls.
Testing takes 3 to 7 working days depending on the number of roles and the API surface, with the full engagement from scoping to report delivery usually completed within 10 to 15 business days. A small single-product SaaS takes around 3 days; a mid-sized platform with multiple roles, an API, and SSO typically takes 5 to 7 days. Urgent pre-procurement testing can often be accommodated in a compressed window.
Yes. The API and identity layers are central to a SaaS test, not optional extras. We test your REST and GraphQL endpoints against the OWASP API Security Top 10, including broken object-level authorisation across tenant boundaries, and we assess SAML assertion handling, SCIM provisioning and de-provisioning, and MFA enforcement across your SSO configuration.
Yes. Enterprise buyers increasingly require evidence of independent, accredited penetration testing before they will sign. Our CREST-accredited report includes an executive summary written for non-technical reviewers and a compliance mapping section, so you can attach it directly to security questionnaires and procurement reviews. Many SaaS vendors commission a test specifically to unblock an enterprise deal or a Series A raise.
We recommend testing a staging environment that mirrors production to avoid any risk to live tenants. Where production testing is required, we use dedicated test tenants, non-destructive techniques, and coordinated timing to minimise impact. We never exfiltrate customer data or access records beyond what is needed to demonstrate a vulnerability, and all testing runs under a signed agreement defining scope and rules of engagement.
At least annually, and after any major release that changes the tenancy model, adds a role tier, or alters authentication. SOC 2 and enterprise customers generally expect an annual test as a baseline. SaaS products ship continuously, so many vendors pair the annual assessment with retesting around significant feature launches to keep their assurance evidence current.



