B2B SaaS · penetration testing, API security & vulnerability management

Penetration Testing & API Security for SaaS Providers: the report your customers ask for

Every enterprise customer wants to see a recent, independent pentest report of your web app, API and cloud before they buy. We test manually to OWASP and PTES, deliver a free re-test after remediation and a clean report you can share in any vendor security review.

OWASP · PTES · OSCP/CEH testers free re-test after remediation shareable customer report
Penetration testing and API security for B2B SaaS providers

For SaaS engineering and security leads, from start-up to established ISV

Manually tested OWASP · PTES
Certified testers OSCP · CEH
ISO 27001 A.8.8 vulnerability management
Shareable report for vendor reviews
Independent no in-house SOC
Philipp Staiger

Responsible for this mandate

Philipp Staiger

M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)

Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.

LinkedIn

The pentest report is part of every vendor security review

Before an enterprise customer buys your SaaS, their procurement vets you as a vendor. A recent, independent penetration test is among the most frequently requested pieces of evidence.

Security questionnaires such as CAIQ and SIG, plus ISO 27001 and SOC 2, expect a recent, independent penetration test of your web application, your API and your cloud environment. Without the report, the deal stalls in procurement, often for weeks.

It is not only the one-off test that gets checked. Customers and certifications expect an ongoing vulnerability-management process: regular scans, traceable remediation of prioritised findings and a repeatable routine, not a one-time snapshot.

On top of that comes coordinated vulnerability disclosure (CVD): a policy with security.txt through which security researchers and customers can responsibly report vulnerabilities to you. Enterprise procurement and ISO 27001 read this as a sign of maturity.

How SIDD tests and makes you ready to answer

We deliver the test, the evidence and the process, so your engineering remediates fast and your sales can answer fast.

We run manual penetration tests of your web application and your API, to OWASP and PTES, performed by certified testers holding OSCP and CEH. Manual testing finds logic flaws, broken object-level authorization and tenant-isolation gaps that automated scanners miss.

We also set up repeatable vulnerability scans that satisfy the requirements of ISO 27001 Annex A.8.8 (management of technical vulnerabilities). After you remediate your findings, we run a free re-test, so the final report shows the cleaned-up state.

You receive a clean, professional report with a management summary, technical detail and CVSS scoring, which you can hand straight into your vendor security reviews and your trust center. On request we design your CVD policy with security.txt and define the triage and response path.

We anchor the secure SDLC as governance through our vCISO and an ISMS: secure-development requirements, code-review gates, dependency and vulnerability routines. To be clear: SIDD advises and tests, SIDD does not build your CI/CD pipeline itself and does not run managed monitoring.

Why SIDD for your SaaS pentest

A pentest should be more than a list. It should unblock deals. We aim the test, the report and the process at exactly that.

Manual, not just a scanner

Our OSCP and CEH testers work to OWASP and PTES and go beyond automated scans. This is how we find tenant-isolation and authorization flaws in your API that are especially critical for multi-tenant SaaS.

A report built to share

You get a clean report with a management summary and CVSS scoring that you can pass to customers without rework and place in your trust center. This is exactly the document procurement asks for.

Free re-test

After you remediate your findings, we re-test at no charge. The final report shows the cleaned-up state, which lands much stronger in vendor reviews and for ISO 27001 than an open list of findings.

Process, not a snapshot

We set up repeatable scans and a vulnerability-management process to ISO 27001 A.8.8. So you answer the question about ongoing vulnerability management with a real procedure, not an old report.

Independent and confidential

Because we sell neither an in-house SOC nor a pipeline, our report carries no vested interest. We test under confidentiality, and our independence makes the report more credible to your customers.

Connects to certification and AI

The pentest fits into the larger vendor-security evidence base. We connect it with ISO 27001 and SOC 2 readiness and, if your product has LLM or agent features, with dedicated AI security testing.

Pentest and vulnerability packages

Vulnerability scan & management

Fixed fee per cycle

Repeatable scans and a vulnerability-management process that satisfies ISO 27001 A.8.8.

  • Recurring scans of app and infrastructure
  • Risk-based prioritisation of findings
  • Remediation evidence for audits and customers
  • Satisfies ISO 27001 Annex A.8.8

CVD policy & secure-SDLC governance

Fixed fee or vCISO mandate

CVD policy with security.txt plus secure-SDLC governance through vCISO and ISMS.

  • Coordinated vulnerability disclosure policy
  • security.txt plus triage and response path
  • Secure-SDLC governance via vCISO and ISMS
  • Advisory and testing, no pipeline build

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your pentest, concretely: LexCommand maps the findings and the vulnerability-management process to the sourced requirements of ISO 27001 A.8.8, SOC 2 and questionnaires such as CAIQ and SIG, and drafts the CVD policy and secure-SDLC governance with citations as footnotes, every reference checkable.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Do we get a report we can share with customers?

Yes. You receive a clean, professional report with a management summary, technical detail and CVSS scoring. It is built so you can hand it straight into vendor security reviews and your trust center. The final state is shown in the report after the free re-test.

What does the free re-test cost and what does it cover?

The re-test is included in the fixed fee of the penetration test. After your team has fixed the findings, we verify that the vulnerabilities are actually closed and update the report accordingly. This way the document that goes to customers shows the cleaned-up state.

Does SIDD provide a managed SOC or incident response?

No. We test, advise and set up vulnerability management and secure-SDLC governance. We do not run a 24/7 SOC or managed monitoring, and we do not build your CI/CD pipeline ourselves. It is precisely this independence that makes our report credible to your customers.

How often should we test?

An annual penetration test plus a test after major releases or architecture changes is common. Between them, recurring vulnerability scans carry the ongoing process. Customers and ISO 27001 expect currency, so a report older than twelve months is often too old in vendor reviews.

Do you also test AI and LLM features of our SaaS?

Yes, through our dedicated AI security service. If your product contains LLM, RAG or agent features, we test these separately, for example for prompt injection and data exfiltration. These tests complement the classic web and API pentest but do not replace it.

Fits your vendor-security evidence

The pentest is one building block. These pages show the rest of the evidence your enterprise customers ask for:

Ready for the pentest report your customers demand?

We define the scope, test manually to OWASP and PTES and deliver a shareable report with a free re-test. So you answer the security questions and win the deal.