🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Penetration Testing — Tier 3
⭐ Most Popular

Standard Web Application & API Penetration Test

Comprehensive pen test for multi-tenant SaaS. REST API testing, cross-tenant isolation, IDOR/BOLA testing. Remediation retest included as standard.

from€4,500
3 weeks

Quick Answer

Comprehensive penetration test for multi-tenant SaaS platforms. Includes authenticated and unauthenticated web app testing, REST API security testing aligned with OWASP API Security Top 10 (2023), cross-tenant isolation testing, authorisation matrix construction across multiple roles and tenants, IDOR and BOLA testing across the API surface, business logic flaws, and session security deep-dive. Remediation retest included as standard within 60 days. 8–12 person-days, delivered in approximately 3 weeks. From €4,500.

PayPal · SSL Senior only 14-day warranty SEC-PENT-03

Why You Need This

This is our most-requested tier — the sweet spot for growing B2B SaaS platforms that have moved beyond a simple single-page application. If your platform has any of these characteristics, this is the right tier: multi-tenant architecture (subdomain-per-tenant, path-based, or header-based); REST APIs serving mobile apps, partner integrations, or webhooks; role-based access control with multiple permission levels; customer-uploaded files or documents; integration with third-party SaaS (Stripe, SendGrid, OAuth providers); or you are subject to ISO 27001, SOC 2, or enterprise vendor security review.

Who Requires This From You

  • ISO/IEC 27001:2022 Annex A.8.29 + A.8.8 — Full audit evidence
  • SOC 2 Trust Services Criteria — CC4.1, CC6.1, CC7.1, CC7.2, A1.2
  • Enterprise vendor security reviews for B2B SaaS in regulated industries
  • GDPR Article 32 — For B2B platforms processing personal data of EU citizens
  • Cyber insurance underwriters at SMB+ tier — full coverage application
  • PCI DSS 4.0 Requirement 11.4 — For payment processing platforms

What You Get

REST API security testing (OWASP API Security Top 10:2023)

  • API1: Broken Object Level Authorization (BOLA / IDOR)
  • API2: Broken Authentication
  • API3: Broken Object Property Level Authorization
  • API5: Broken Function Level Authorization
  • API7: Server Side Request Forgery
  • Mass assignment vulnerabilities
  • Rate limiting and resource consumption
  • JWT, OAuth, API key authentication mechanisms

Multi-tenant isolation testing

  • Authorisation matrix construction (roles × endpoints × tenants)
  • Cross-tenant data access attempts (IDOR / BOLA across tenant boundaries)
  • Subdomain-based, path-based, and header-based tenancy testing
  • File storage and retrieval tenant isolation
  • Search and indexing tenant scoping

Deliverables (includes everything in Tier 2 plus)

  • Full penetration test report (typically 30–60 pages) with dedicated API and multi-tenant sections
  • Compliance mapping section (ISO 27001 / SOC 2 / GDPR Art. 32)
  • Prioritised remediation roadmap with effort estimates
  • Signed Attestation Letter (extractable for vendor security file)
  • Remediation retest included as standard (scheduled 30–60 days after report)
  • Delta retest report documenting remediation status of each finding
  • Auditor handover session (60 minutes, by Zoom)
  • Follow-up Q&A with end-customer's security team

What Happens If You Don't

Data breach across tenants — single IDOR finding becomes a customer-wide exposure event
Mandatory GDPR breach notification within 72 hours under Article 33
Regulatory investigation — Data Protection Authority inquiry
Cyber insurance claim denial if testing inadequacy is identified post-incident
SOC 2 audit qualification under CC6.1, CC7.2
Loss of enterprise contracts that mandate annual pentest evidence

Our Process

1
Scoping call (60 minutes)
Confirm target assets, tenant model, API endpoints, user roles, blackout periods.
2
Pre-engagement documentation
Mutual NDA, Statement of Work, Rules of Engagement, and DPA where personal data is in scope — all signed.
3
Test environment access provisioned
Multiple test accounts across roles and tenants.
4
Active testing (8–12 person-days over 2–3 weeks)
Daily updates via secure channel. Critical findings escalated within 4 hours.
5
Report and Attestation Letter delivered
Encrypted archive + auditor handover session (60 min Zoom).
6
Remediation retest (30–60 days after report)
Delta report confirms remediation status of each finding.

Is This the Right Penetration Test for You?

You should choose this tier if…

  • You have a multi-tenant SaaS platform
  • Your platform includes REST APIs as part of the product
  • You need SOC 2 Type II evidence for CC4.1, CC7.1
  • Your ISO 27001 ISMS scope covers the whole SaaS platform
  • You're facing enterprise procurement teams who read pen test reports carefully
  • You need remediation retest included as standard

Common scenarios

Series-A B2B SaaS entering enterprise sales

"Every enterprise deal now includes a SIG Lite or CAIQ questionnaire asking about our pen test. We need a report that stands up to security team scrutiny."

Multi-tenant SaaS preparing SOC 2 Type II

"Our CPA audit firm wants pentest evidence covering the audit period. We need something scoped to our whole production environment."

REST API-first product

"Our REST API is exposed to customers, partners, and third-party integrations. We need proper API security testing per OWASP API Security Top 10."

Fintech with payment flows

"We're SAQ D scope. PCI DSS Requirement 11.4 external and application layer testing needed."

What buyers search for that leads here

Buyers reaching this page typically searched: "SaaS penetration testing", "multi-tenant security testing", "REST API pentest", "SOC 2 penetration testing", "PCI DSS penetration testing", or "enterprise SaaS pen test".

Our €4,500 Standard Pentest matches all of these scenarios. If your platform is bigger (Series-C+ with cloud infrastructure, integrations, async processing), consider our Enterprise SaaS Pentest (from €8,000).

UK CREST-accredited equivalent scope costs £8,000–18,000 with mid-size firms. Our €4,500 (~£3,910) delivers equivalent scope at 60–75% saving.

When to choose a different tier instead

SignalRecommended service
Single web app, no REST APIFocused Pentest (€1,800)
Enterprise with cloud + integrationsEnterprise Pentest (€8,000)
AI/LLM application securityAI Red Team ($990)
Pre-IPO comprehensive auditEnterprise Pentest (€8,000)

Frequently asked questions about this tier

What makes this different from the Focused Pentest?

Standard adds REST API testing (OWASP API Security Top 10:2023), complete multi-tenant isolation testing with authorisation matrix, deeper business logic analysis, and remediation retest included as standard. It's 8–12 person-days vs 3–5 for Focused.

Is SOC 2 audit evidence sufficient here?

Yes. The report and Attestation Letter cover SOC 2 Trust Services Criteria CC4.1, CC6.1, CC7.1, CC7.2, and A1.2. We include a SOC 2 compliance mapping section in every report.

What API authentication types do you test?

JWT, OAuth 2.0, API keys, Basic Auth, mTLS, and session-based APIs. We test token handling, expiry, revocation, privilege escalation, and scope misconfigurations.

Can this cover mobile app testing?

This tier covers web app and REST API. Mobile app testing is available as an add-on module. Contact us during scoping.

What cloud providers do you cover?

Surface-level cloud exposure (public endpoints, exposed storage buckets, public IAM issues) is included. Full cloud infrastructure assessment is part of the Enterprise tier.

Pricing & Delivery

from€4,500
3 weeks

From €4,500 for moderate-complexity multi-tenant SaaS with REST APIs. Up to €6,500 for higher-complexity platforms with multiple distinct user types, extensive API surface, or complex business logic. Add-on modules: OWASP LLM Top 10 (+€2,000–3,000), source code review (+€2,500–4,000), mobile app (+€3,500–5,500), cloud infrastructure check (+€1,500–3,000).

PayPal · SSL Senior only 14-day warranty SEC-PENT-03

Frequently Asked Questions

How is "multi-tenant" defined for this tier?

Multi-tenant means your platform serves multiple distinct customers (tenants) with logical or physical isolation between their data. Tenancy can be implemented via separate subdomains (customer1.yourapp.com), URL paths (/customer1/), or HTTP headers. All three approaches are covered.

Will this satisfy SOC 2 Type II audit?

Yes — our deliverables align with the evidence requirements under CC4.1, CC6.1, CC7.1, CC7.2, and A1.2. The Attestation Letter is structured for direct inclusion in SOC 2 evidence files. We recommend a brief alignment call with your SOC 2 auditor before engagement to confirm specific control coverage.

Do you include OWASP LLM Top 10 testing?

Not as standard at this tier. LLM Top 10 testing requires specialist competency and dedicated effort — it's available as an add-on module (+€2,000–3,000). If your platform has significant AI/LLM features, we strongly recommend including this module.

What about cloud infrastructure (AWS / GCP / Azure)?

Cloud infrastructure surface is not included in the standard scope. It's available as an add-on (+€1,500–3,000) or fully covered in our Enterprise Tier 4 (€8,000+).

How does remediation retest work?

After delivering the initial report, you have up to 60 days to remediate findings. When ready, you notify us; we re-test only the remediated findings and produce a delta report documenting the status of each (Fixed / Partially Fixed / Not Fixed). This delta report is suitable for audit evidence. Additional retest rounds are +€500 each.