Map every role against every object
We built a matrix of the platform’s five roles against its forty-odd object types, then tested every cell — including cross-tenant access, which the scanner had no way to reason about.
Penspy is an independent security firm, testing web applications and auditing against the frameworks you answer to.
A Series B invoicing platform needed a penetration test to close its first enterprise customer. The headline finding would have ended the deal had the customer found it first.
Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.
A multi-tenant invoicing platform.
The platform served around four thousand small businesses from a single shared database, separated by a tenant ID on every row. Its largest prospect, a national distributor, required a third-party penetration test less than twelve months old before procurement would sign.
The engineering team had run an automated scanner and fixed what it reported. They expected a clean result.
We built a matrix of the platform’s five roles against its forty-odd object types, then tested every cell — including cross-tenant access, which the scanner had no way to reason about.
The mobile app called a version of the API not listed in the documentation. It reused the web session but skipped the tenant check on four endpoints.
The executive summary was written so the client could share the summary letter with the prospect’s security team without exposing a single request.
| Severity | Finding | Maps to | Status at retest |
|---|---|---|---|
| Critical | Invoice IDs were sequential and the v2 invoice endpoint checked authentication but not tenant ownership. | API1:2023 · ASVS V8 · CWE-639 | Closed |
| High | Users removed from a tenant kept a valid refresh token for 30 days. | ASVS V7 · A07:2025 | Closed |
| High | The “import logo from URL” feature fetched internal addresses, including cloud metadata. | A01:2025 · CWE-918 | Closed |
| High | CSV export of customer lists was vulnerable to formula injection. | ASVS V1 · CWE-1236 | Closed |
| Medium | No rate limit on login or password reset. | API4:2023 · ASVS V6 | Closed |
What changed.
The tenant-isolation flaw was patched within 48 hours of the same-day escalation, and the fix was extended to a shared authorisation layer rather than patched endpoint by endpoint. Every critical and high finding was verified closed at retest.
The summary letter went to the prospect’s security team, and the same report became evidence for the client’s SOC 2 Type II audit the following quarter.
Tell us what you ship and who is asking for proof. We will come back with a scope and a range.