Standard Web Application & API Penetration Test
Comprehensive pen test for multi-tenant SaaS. REST API testing, cross-tenant isolation, IDOR/BOLA testing. Remediation retest included as standard.
Quick Answer
Comprehensive penetration test for multi-tenant SaaS platforms. Includes authenticated and unauthenticated web app testing, REST API security testing aligned with OWASP API Security Top 10 (2023), cross-tenant isolation testing, authorisation matrix construction across multiple roles and tenants, IDOR and BOLA testing across the API surface, business logic flaws, and session security deep-dive. Remediation retest included as standard within 60 days. 8–12 person-days, delivered in approximately 3 weeks. From €4,500.
Why You Need This
This is our most-requested tier — the sweet spot for growing B2B SaaS platforms that have moved beyond a simple single-page application. If your platform has any of these characteristics, this is the right tier: multi-tenant architecture (subdomain-per-tenant, path-based, or header-based); REST APIs serving mobile apps, partner integrations, or webhooks; role-based access control with multiple permission levels; customer-uploaded files or documents; integration with third-party SaaS (Stripe, SendGrid, OAuth providers); or you are subject to ISO 27001, SOC 2, or enterprise vendor security review.
Who Requires This From You
- ISO/IEC 27001:2022 Annex A.8.29 + A.8.8 — Full audit evidence
- SOC 2 Trust Services Criteria — CC4.1, CC6.1, CC7.1, CC7.2, A1.2
- Enterprise vendor security reviews for B2B SaaS in regulated industries
- GDPR Article 32 — For B2B platforms processing personal data of EU citizens
- Cyber insurance underwriters at SMB+ tier — full coverage application
- PCI DSS 4.0 Requirement 11.4 — For payment processing platforms
What You Get
REST API security testing (OWASP API Security Top 10:2023)
- API1: Broken Object Level Authorization (BOLA / IDOR)
- API2: Broken Authentication
- API3: Broken Object Property Level Authorization
- API5: Broken Function Level Authorization
- API7: Server Side Request Forgery
- Mass assignment vulnerabilities
- Rate limiting and resource consumption
- JWT, OAuth, API key authentication mechanisms
Multi-tenant isolation testing
- Authorisation matrix construction (roles × endpoints × tenants)
- Cross-tenant data access attempts (IDOR / BOLA across tenant boundaries)
- Subdomain-based, path-based, and header-based tenancy testing
- File storage and retrieval tenant isolation
- Search and indexing tenant scoping
Deliverables (includes everything in Tier 2 plus)
- Full penetration test report (typically 30–60 pages) with dedicated API and multi-tenant sections
- Compliance mapping section (ISO 27001 / SOC 2 / GDPR Art. 32)
- Prioritised remediation roadmap with effort estimates
- Signed Attestation Letter (extractable for vendor security file)
- Remediation retest included as standard (scheduled 30–60 days after report)
- Delta retest report documenting remediation status of each finding
- Auditor handover session (60 minutes, by Zoom)
- Follow-up Q&A with end-customer's security team
What Happens If You Don't
Our Process
Is This the Right Penetration Test for You?
You should choose this tier if…
- You have a multi-tenant SaaS platform
- Your platform includes REST APIs as part of the product
- You need SOC 2 Type II evidence for CC4.1, CC7.1
- Your ISO 27001 ISMS scope covers the whole SaaS platform
- You're facing enterprise procurement teams who read pen test reports carefully
- You need remediation retest included as standard
Common scenarios
"Every enterprise deal now includes a SIG Lite or CAIQ questionnaire asking about our pen test. We need a report that stands up to security team scrutiny."
"Our CPA audit firm wants pentest evidence covering the audit period. We need something scoped to our whole production environment."
"Our REST API is exposed to customers, partners, and third-party integrations. We need proper API security testing per OWASP API Security Top 10."
"We're SAQ D scope. PCI DSS Requirement 11.4 external and application layer testing needed."
What buyers search for that leads here
Buyers reaching this page typically searched: "SaaS penetration testing", "multi-tenant security testing", "REST API pentest", "SOC 2 penetration testing", "PCI DSS penetration testing", or "enterprise SaaS pen test".
Our €4,500 Standard Pentest matches all of these scenarios. If your platform is bigger (Series-C+ with cloud infrastructure, integrations, async processing), consider our Enterprise SaaS Pentest (from €8,000).
UK CREST-accredited equivalent scope costs £8,000–18,000 with mid-size firms. Our €4,500 (~£3,910) delivers equivalent scope at 60–75% saving.
When to choose a different tier instead
| Signal | Recommended service |
|---|---|
| Single web app, no REST API | Focused Pentest (€1,800) |
| Enterprise with cloud + integrations | Enterprise Pentest (€8,000) |
| AI/LLM application security | AI Red Team ($990) |
| Pre-IPO comprehensive audit | Enterprise Pentest (€8,000) |
Frequently asked questions about this tier
What makes this different from the Focused Pentest?
Standard adds REST API testing (OWASP API Security Top 10:2023), complete multi-tenant isolation testing with authorisation matrix, deeper business logic analysis, and remediation retest included as standard. It's 8–12 person-days vs 3–5 for Focused.
Is SOC 2 audit evidence sufficient here?
Yes. The report and Attestation Letter cover SOC 2 Trust Services Criteria CC4.1, CC6.1, CC7.1, CC7.2, and A1.2. We include a SOC 2 compliance mapping section in every report.
What API authentication types do you test?
JWT, OAuth 2.0, API keys, Basic Auth, mTLS, and session-based APIs. We test token handling, expiry, revocation, privilege escalation, and scope misconfigurations.
Can this cover mobile app testing?
This tier covers web app and REST API. Mobile app testing is available as an add-on module. Contact us during scoping.
What cloud providers do you cover?
Surface-level cloud exposure (public endpoints, exposed storage buckets, public IAM issues) is included. Full cloud infrastructure assessment is part of the Enterprise tier.
Pricing & Delivery
From €4,500 for moderate-complexity multi-tenant SaaS with REST APIs. Up to €6,500 for higher-complexity platforms with multiple distinct user types, extensive API surface, or complex business logic. Add-on modules: OWASP LLM Top 10 (+€2,000–3,000), source code review (+€2,500–4,000), mobile app (+€3,500–5,500), cloud infrastructure check (+€1,500–3,000).
Frequently Asked Questions
How is "multi-tenant" defined for this tier?
Multi-tenant means your platform serves multiple distinct customers (tenants) with logical or physical isolation between their data. Tenancy can be implemented via separate subdomains (customer1.yourapp.com), URL paths (/customer1/), or HTTP headers. All three approaches are covered.
Will this satisfy SOC 2 Type II audit?
Yes — our deliverables align with the evidence requirements under CC4.1, CC6.1, CC7.1, CC7.2, and A1.2. The Attestation Letter is structured for direct inclusion in SOC 2 evidence files. We recommend a brief alignment call with your SOC 2 auditor before engagement to confirm specific control coverage.
Do you include OWASP LLM Top 10 testing?
Not as standard at this tier. LLM Top 10 testing requires specialist competency and dedicated effort — it's available as an add-on module (+€2,000–3,000). If your platform has significant AI/LLM features, we strongly recommend including this module.
What about cloud infrastructure (AWS / GCP / Azure)?
Cloud infrastructure surface is not included in the standard scope. It's available as an add-on (+€1,500–3,000) or fully covered in our Enterprise Tier 4 (€8,000+).
How does remediation retest work?
After delivering the initial report, you have up to 60 days to remediate findings. When ready, you notify us; we re-test only the remediated findings and produce a delta report documenting the status of each (Fixed / Partially Fixed / Not Fixed). This delta report is suitable for audit evidence. Additional retest rounds are +€500 each.
