Skip to main content
B2B SaaS workflow-automation company · B2B SaaS

A four-person engineering team passing enterprise security review without a security hire

Security questionnaires were stalling every enterprise deal. Automated testing plus SOC 2 evidence turned the security review from a blocker into a differentiator.

Customer
B2B SaaS workflow-automation company
Industry
B2B SaaS
Published
March 24, 2026

At a glance

Customer profile

Industry
B2B SaaS / workflow automation
Company size
22 employees, 4 engineers
Environment
GCP, single-tenant per customer
Engagement
Continuous, self-serve

Challenge

What was not working

The product was winning technical evaluations and losing security reviews. Every enterprise prospect asked for a recent penetration test report, a SOC 2 attestation and answers to a 300-line questionnaire, and a four-engineer team had none of those things.

  • Deals stalled at the security review, not the demo

    Three six-figure opportunities sat in procurement for over a quarter waiting on security documentation, and one was lost outright to a competitor who had it ready.

  • A pentest quote exceeded the quarter's tooling budget

    The cheapest credible manual assessment came in at $28,000 for a single point-in-time test, which would have been out of date before the next deal cycle.

  • No security specialist to interpret findings

    Free scanners produced output nobody on the team could rank. Without a way to tell an exploitable flaw from a header warning, everything looked equally urgent and nothing got fixed first.

  • Single-tenant isolation was assumed, not proven

    The architecture separated customers by design. Nothing had ever tested whether an authenticated user in one tenant could reach another, which is precisely the question every enterprise buyer asks.

Solution

What AIPTx did about it

The goal was not a security team. It was a repeatable way to produce the three artefacts enterprise buyers ask for, and to be honest about what they say.

  1. 1

    Tenant isolation testing first

    Week 1

    Authenticated sessions in one tenant were used to attempt access to another across every endpoint: identifier substitution, path traversal on tenant-scoped storage and JWT claim manipulation. Two cross-tenant read paths were found and closed in the first week.

  2. 2

    SOC 2 control mapping from day one

    Continuous

    Findings map to Trust Services Criteria as they are created, so the evidence for the Type II observation window accumulated as a by-product of normal testing rather than as a project.

  3. 3

    SAST in the pull request

    ~3 min per PR

    Ninety-plus rules across the TypeScript and Python codebases run on the diff and comment inline. For a team with no security reviewer, the review comment is the security review.

  4. 4

    Ranked, not listed

    Per finding

    Contextual scoring meant the queue arrived in the order it should be worked. Two engineers with no security background could clear it without deciding what mattered.

  5. 5

    Shareable report for prospects

    On demand

    An executive summary suitable for sending to a prospect's security team is generated per assessment, current, dated and specific, rather than an annual PDF from eleven months ago.

Results

What changed

Across the eighteen months following adoption, through the SOC 2 Type II observation window and into the enterprise motion.

SOC 2
Type II achievedNo exceptions on the technical testing controls
10x
Faster deal cyclesSecurity review from ~11 weeks to under a week
2
Cross-tenant paths closedFound in week one; both authenticated read access
$0
Additional security headcountSame four engineers throughout
1 day
Questionnaire turnaroundDown from two to three weeks per prospect

Pentest evidence

BeforeNone

AfterCurrent assessment, dated within days

Security review duration

Before~11 weeks

AfterUnder 1 week

Tenant isolation

BeforeAssumed from architecture

AfterTested continuously, evidenced

Finding triage

BeforeUnranked scanner output

AfterRanked queue, worked top-down

Key takeaways

The part that transfers

Every environment differs. These are the conclusions that hold outside this one.

  • For small teams, ranking matters more than detection

    Free tools already found most of it. What four engineers with no security specialist lacked was any basis for deciding what to fix first, and that is what changed the outcome.

  • Test the claim your buyers care about

    Every enterprise questionnaire asks about tenant isolation. Testing it explicitly, and being able to say when it was last tested, answered the single question that stalled deals.

  • Recency is the property of a pentest report that sells

    A prospect's security team treats a report from last week very differently from one from last year, regardless of what either contains.

  • Compliance evidence is cheap if it accrues

    Mapping findings to criteria as they occur costs nothing. Reconstructing a year of evidence at audit time costs a quarter of an engineer.

See Your Attack Surface in Real-Time

Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.