A four-person engineering team passing enterprise security review without a security hire
Security questionnaires were stalling every enterprise deal. Automated testing plus SOC 2 evidence turned the security review from a blocker into a differentiator.
- Customer
- B2B SaaS workflow-automation company
- Industry
- B2B SaaS
- Published
- March 24, 2026
At a glance
Customer profile
- Industry
- B2B SaaS / workflow automation
- Company size
- 22 employees, 4 engineers
- Environment
- GCP, single-tenant per customer
- Engagement
- Continuous, self-serve
Challenge
What was not working
The product was winning technical evaluations and losing security reviews. Every enterprise prospect asked for a recent penetration test report, a SOC 2 attestation and answers to a 300-line questionnaire, and a four-engineer team had none of those things.
Deals stalled at the security review, not the demo
Three six-figure opportunities sat in procurement for over a quarter waiting on security documentation, and one was lost outright to a competitor who had it ready.
A pentest quote exceeded the quarter's tooling budget
The cheapest credible manual assessment came in at $28,000 for a single point-in-time test, which would have been out of date before the next deal cycle.
No security specialist to interpret findings
Free scanners produced output nobody on the team could rank. Without a way to tell an exploitable flaw from a header warning, everything looked equally urgent and nothing got fixed first.
Single-tenant isolation was assumed, not proven
The architecture separated customers by design. Nothing had ever tested whether an authenticated user in one tenant could reach another, which is precisely the question every enterprise buyer asks.
Solution
What AIPTx did about it
The goal was not a security team. It was a repeatable way to produce the three artefacts enterprise buyers ask for, and to be honest about what they say.
- 1
Tenant isolation testing first
Week 1Authenticated sessions in one tenant were used to attempt access to another across every endpoint: identifier substitution, path traversal on tenant-scoped storage and JWT claim manipulation. Two cross-tenant read paths were found and closed in the first week.
- 2
SOC 2 control mapping from day one
ContinuousFindings map to Trust Services Criteria as they are created, so the evidence for the Type II observation window accumulated as a by-product of normal testing rather than as a project.
- 3
SAST in the pull request
~3 min per PRNinety-plus rules across the TypeScript and Python codebases run on the diff and comment inline. For a team with no security reviewer, the review comment is the security review.
- 4
Ranked, not listed
Per findingContextual scoring meant the queue arrived in the order it should be worked. Two engineers with no security background could clear it without deciding what mattered.
- 5
Shareable report for prospects
On demandAn executive summary suitable for sending to a prospect's security team is generated per assessment, current, dated and specific, rather than an annual PDF from eleven months ago.
Results
What changed
Across the eighteen months following adoption, through the SOC 2 Type II observation window and into the enterprise motion.
- SOC 2
- Type II achievedNo exceptions on the technical testing controls
- 10x
- Faster deal cyclesSecurity review from ~11 weeks to under a week
- 2
- Cross-tenant paths closedFound in week one; both authenticated read access
- $0
- Additional security headcountSame four engineers throughout
- 1 day
- Questionnaire turnaroundDown from two to three weeks per prospect
Pentest evidence
BeforeNone
AfterCurrent assessment, dated within days
Security review duration
Before~11 weeks
AfterUnder 1 week
Tenant isolation
BeforeAssumed from architecture
AfterTested continuously, evidenced
Finding triage
BeforeUnranked scanner output
AfterRanked queue, worked top-down
Key takeaways
The part that transfers
Every environment differs. These are the conclusions that hold outside this one.
For small teams, ranking matters more than detection
Free tools already found most of it. What four engineers with no security specialist lacked was any basis for deciding what to fix first, and that is what changed the outcome.
Test the claim your buyers care about
Every enterprise questionnaire asks about tenant isolation. Testing it explicitly, and being able to say when it was last tested, answered the single question that stalled deals.
Recency is the property of a pentest report that sells
A prospect's security team treats a report from last week very differently from one from last year, regardless of what either contains.
Compliance evidence is cheap if it accrues
Mapping findings to criteria as they occur costs nothing. Reconstructing a year of evidence at audit time costs a quarter of an engineer.
Related
Other programmes, other starting points
Eleven attack paths to domain admin, closed by four changes
A 40-site Active Directory estate had accumulated a decade of delegation. Attack chain analysis reduced 11 domain-admin paths to zero without a migration project.
ReadManufacturingFinding the dependency risk that a vulnerability count kept hiding
A 4,100-package dependency tree produced 900 CVE alerts. Reachability analysis showed 23 were exploitable, and one was in a build tool nobody had inventoried.
ReadFinancial ServicesHow a financial services platform went from two pentests a year to one on every release
Six-to-eight week manual assessments at $50,000 each were gating releases. Continuous AI pentesting cut testing time 85% and moved security left of the deploy.
ReadSee Your Attack Surface in Real-Time
Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.