In San Francisco, a penetration test is usually bought by the sales team, not the security team. An enterprise prospect's vendor review has stalled, the questionnaire asks for a recent independent test and a SOC 2 report, and the deal waits. CyberFortify runs manual web, API and cloud tests built around the risk that actually matters in a multi-tenant product: one customer reaching another's data. Fixed price, evidence-grade reporting, free retest.
// 01 Why San Francisco businesses need penetration testing
Ask a San Francisco engineering leader why they are commissioning a penetration test and the honest answer is rarely fear. It is a stalled deal. An enterprise prospect's security questionnaire asks for a recent independent penetration test and a SOC 2 Type II report, and procurement will not move until both exist. The test is a commercial unblocker before it is a security exercise, which changes what it has to produce: scanner output gets rejected by any competent reviewer, while a report naming scope, dates, methodology and confirmed exploitation does not.
Underneath the paperwork sits a technical risk that generic testing consistently misses. San Francisco builds multi-tenant software: one codebase, one database cluster, thousands of customers separated by an authorisation check rather than a wall. The catastrophic failure there is not a crashed server. It is a broken object-level authorisation check that lets one tenant enumerate another's records, a scoped token narrower in the interface than on the server, or a cache key that omits the tenant identifier and serves one organisation's response to the next requester. None of those appear in a scan. Testing has to run from inside the product, with real tenants, real roles and a tester who knows where the boundary is meant to sit.
// 02 Compliance and regulatory drivers in San Francisco
California companies face a stack mixing contractual pressure with statutory duty. These are the obligations we most often map evidence against here.
SOC 2 Type II
The dominant driver here. Auditors and enterprise buyers expect independent testing evidence for the common criteria on vulnerability management and change control. Type II covers a period, so the test must sit inside the window.
CCPA / CPRA
The CPRA extends the CCPA with duties enforced by the CPPA, including annual cybersecurity audits and risk assessments where processing presents significant risk. Independent testing is what makes those assessments rest on something measured.
PCI DSS 4.0
Requirement 11.4 mandates internal and external penetration testing at least annually and after significant change, with explicit segmentation testing. Any platform touching cardholder data inherits it.
NIST CSF
The shared vocabulary of enterprise vendor reviews. Mapping findings to Identify, Protect and Detect lets a buyer's security team place your results inside their own programme.
ISO 27001 A.8.29
Companies selling into European and Asian enterprises are asked for ISO 27001 alongside SOC 2. Control A.8.29 requires security testing in development and acceptance.
// 03 Penetration testing services for San Francisco
Scope follows architecture. For a SaaS company the application and its API carry most of the risk; for fintech, payment flows and segmentation come first; for teams shipping AI features fast, the model boundary is the least-tested surface.
Web application pen testing
Authenticated, multi-role testing of your product - tenant isolation, BOLA and IDOR, business-logic abuse, and the privilege model behind admin and impersonation features.
API pen testing
Object and function-level authorisation, scoped token enforcement, mass assignment, rate limiting, and the webhook and export paths that skip the usual checks.
Cloud pen testing
AWS, Azure and Google Cloud review focused on IAM least privilege, role assumption chains, metadata exposure and secrets handling.
AI & LLM pen testing
Prompt injection, tool and function-call abuse, retrieval pipelines crossing tenant boundaries, and context data leaking between customers.
Network pen testing
External perimeter and internal testing where a corporate estate or hybrid identity still exists, including the segmentation evidence PCI DSS names.
Compliance consulting
Control mapping, evidence preparation and questionnaire support, so your audit window and sales cycle stop fighting.
// 04 How we deliver to San Francisco
We will be direct about geography, because a vendor who is vague about it is one you should not trust with your source code. CyberFortify is based in the Gulf at UTC+3, roughly ten to eleven hours ahead of San Francisco. We have no California office, no US phone number and no local staff, and we would rather say so here than in a procurement call. Most testing that matters for a SaaS product is remote anyway; where an engagement genuinely needs physical presence, we travel and say so in the scope.
The overlap window
A fixed daily window where our late afternoon and evening meets your morning: stand-ups, live escalations and engineer walkthroughs. Critical findings go out the moment they are confirmed, whatever the hour.
Work that follows the sun
Testing continues through your night, so questions raised at the end of your day usually have answers waiting next morning - turning the time-zone gap into an extra feedback cycle rather than a delay.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. No hourly meters, no scope creep, and a free retest once fixes ship.
// 05 Industries we secure in San Francisco
These sectors share one trait: they hold other organisations' data inside a shared platform.
// 06 Our methodology
Every San Francisco engagement follows the audit-defensible process CyberFortify runs worldwide, weighted here toward authorisation and identity. Testing is grounded in the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, application work follows OWASP, and exploitation maps to the relevant MITRE ATT&CK tactics. As a CREST Accreditation Pathway firm we lead with manual testing: a scanner cannot tell you which record belongs to which tenant, and a human with two accounts open can.
Scoping & rules of engagement
Applications, APIs, cloud accounts, the tenant and role matrix, test windows and escalation paths agreed in writing first.
Fixed quote in 1hThreat modelling the tenancy boundary
We map where the product decides a request belongs to a customer, then prioritise every path that could reach data across that line.
ATT&CK alignedManual exploitation
Confirmed weaknesses are exploited under controlled conditions and chained toward real impact, with false positives removed by hand.
Controlled exploitReporting & free retest
Attestation letter, executive summary, CVSS-scored detail and SOC 2 control mapping - then a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for San Francisco
A scan-and-report vendor
Automated output rebadged as a pen test, unauthenticated so it never sees the tenancy model, and delivered as a PDF your prospect's reviewer sends straight back for lacking scope, methodology and exploitation evidence.
CyberFortify
A CREST-pathway team that provisions multiple tenants, tests authorisation from the inside, and reports in the language a buyer's security team and your auditor both accept. Manual exploitation, honest scoping, fixed pricing and a free retest.
Engagements here most often pair web application testing with an API assessment - one authorisation model, two surfaces.
// 08 Frequently asked questions
Will your report satisfy an enterprise security review or vendor questionnaire?
That is what it is built for. Every engagement produces an attestation letter you can hand to a prospect, an executive summary for a non-technical reviewer, and a CVSS-scored technical report with reproduction steps. Buyer-side reviewers look for scope, dates, methodology, independence and evidence of remediation, so we make all five explicit - and the free retest gives you a closing statement showing the findings were fixed.
How do you test tenant isolation in a multi-tenant SaaS platform?
We provision at least two tenants and several roles within each, then work laterally rather than downward. Object identifiers from one tenant are replayed against another to find broken object-level authorisation, scoped tokens are checked for server-side enforcement, and cache keys are probed for cross-tenant leakage. Background jobs, exports and webhooks get the same attention, because they often bypass the authorisation the API enforces.
Does a penetration test give us SOC 2 certification?
No, and any vendor claiming otherwise is misleading you. SOC 2 is an attestation issued by a licensed CPA firm after an audit period. A penetration test is one piece of technical evidence supporting the common criteria on vulnerability management and change control - the piece auditors and enterprise buyers ask for by name. We produce that evidence, and our compliance consulting service helps you prepare the surrounding controls before the Type II window opens.
You are based in the Gulf - how does that work across ten time zones?
We are honest about it: our team works from the Gulf at UTC+3, roughly ten to eleven hours ahead of California, and we have no San Francisco office. We hold a fixed daily overlap window - our late afternoon and evening is your morning - for stand-ups, live escalation and walkthroughs with your engineers. Testing continues through your night, so most mornings begin with fresh progress waiting, and critical findings are escalated the moment we confirm them.
Which testing scope should a Series-stage SaaS company start with?
For most San Francisco SaaS companies the first engagement should cover the customer-facing web application, its authenticated API, and the identity layer including SSO and session handling, with tenant isolation treated as a first-class objective. Add a cloud configuration review if your IAM model has grown organically, and payment-flow testing if you handle cardholder data. We scope it on a free call and quote a fixed price.