Location · Penetration Testing in San Francisco, California

Penetration testing in San Francisco for multi-tenant SaaS teams with a deal on hold.

CyberFortify tests the software San Francisco companies sell, not just the infrastructure they rent - tenant isolation, authentication and SSO, API authorisation and cloud IAM. We write the report the way an enterprise buyer's security team reads it, so the questionnaire gets answered and the review moves forward.

Aligned with: SOC 2 · CCPA/CPRA · PCI DSS 4.0 · NIST CSF · ISO 27001 · GDPR · OWASP · PTES
SOC 2
Evidence-grade reports
BOLA
Tenancy-first testing
100%
Manual testing
Free retest
Serving San Francisco: multi-tenant SaaS · B2B platforms · fintech & payments · AI product teams · developer tooling · marketplaces · digital health · professional services · venture-backed scale-ups Serving San Francisco: multi-tenant SaaS · B2B platforms · fintech & payments · AI product teams · developer tooling · marketplaces · digital health · professional services · venture-backed scale-ups
// Executive summary

In San Francisco, a penetration test is usually bought by the sales team, not the security team. An enterprise prospect's vendor review has stalled, the questionnaire asks for a recent independent test and a SOC 2 report, and the deal waits. CyberFortify runs manual web, API and cloud tests built around the risk that actually matters in a multi-tenant product: one customer reaching another's data. Fixed price, evidence-grade reporting, free retest.

// 01 Why San Francisco businesses need penetration testing

Ask a San Francisco engineering leader why they are commissioning a penetration test and the honest answer is rarely fear. It is a stalled deal. An enterprise prospect's security questionnaire asks for a recent independent penetration test and a SOC 2 Type II report, and procurement will not move until both exist. The test is a commercial unblocker before it is a security exercise, which changes what it has to produce: scanner output gets rejected by any competent reviewer, while a report naming scope, dates, methodology and confirmed exploitation does not.

Underneath the paperwork sits a technical risk that generic testing consistently misses. San Francisco builds multi-tenant software: one codebase, one database cluster, thousands of customers separated by an authorisation check rather than a wall. The catastrophic failure there is not a crashed server. It is a broken object-level authorisation check that lets one tenant enumerate another's records, a scoped token narrower in the interface than on the server, or a cache key that omits the tenant identifier and serves one organisation's response to the next requester. None of those appear in a scan. Testing has to run from inside the product, with real tenants, real roles and a tester who knows where the boundary is meant to sit.

// 02 Compliance and regulatory drivers in San Francisco

California companies face a stack mixing contractual pressure with statutory duty. These are the obligations we most often map evidence against here.

R.01 · Contractual

SOC 2 Type II

The dominant driver here. Auditors and enterprise buyers expect independent testing evidence for the common criteria on vulnerability management and change control. Type II covers a period, so the test must sit inside the window.

R.02 · State law

CCPA / CPRA

The CPRA extends the CCPA with duties enforced by the CPPA, including annual cybersecurity audits and risk assessments where processing presents significant risk. Independent testing is what makes those assessments rest on something measured.

R.03 · Payments

PCI DSS 4.0

Requirement 11.4 mandates internal and external penetration testing at least annually and after significant change, with explicit segmentation testing. Any platform touching cardholder data inherits it.

R.04 · Framework

NIST CSF

The shared vocabulary of enterprise vendor reviews. Mapping findings to Identify, Protect and Detect lets a buyer's security team place your results inside their own programme.

R.05 · Certification

ISO 27001 A.8.29

Companies selling into European and Asian enterprises are asked for ISO 27001 alongside SOC 2. Control A.8.29 requires security testing in development and acceptance.

R.06 · Cross-border

GDPR & HIPAA

Products serving EU users fall under Article 32, which requires regular testing of technical measures. Where a platform genuinely handles protected health information, HIPAA's Security Rule evaluation standard applies alongside it.

// 03 Penetration testing services for San Francisco

Scope follows architecture. For a SaaS company the application and its API carry most of the risk; for fintech, payment flows and segmentation come first; for teams shipping AI features fast, the model boundary is the least-tested surface.

A.01

Web application pen testing

Authenticated, multi-role testing of your product - tenant isolation, BOLA and IDOR, business-logic abuse, and the privilege model behind admin and impersonation features.

A.05

API pen testing

Object and function-level authorisation, scoped token enforcement, mass assignment, rate limiting, and the webhook and export paths that skip the usual checks.

A.04

Cloud pen testing

AWS, Azure and Google Cloud review focused on IAM least privilege, role assumption chains, metadata exposure and secrets handling.

A.06

AI & LLM pen testing

Prompt injection, tool and function-call abuse, retrieval pipelines crossing tenant boundaries, and context data leaking between customers.

A.02

Network pen testing

External perimeter and internal testing where a corporate estate or hybrid identity still exists, including the segmentation evidence PCI DSS names.

A.08

Compliance consulting

Control mapping, evidence preparation and questionnaire support, so your audit window and sales cycle stop fighting.

// 04 How we deliver to San Francisco

We will be direct about geography, because a vendor who is vague about it is one you should not trust with your source code. CyberFortify is based in the Gulf at UTC+3, roughly ten to eleven hours ahead of San Francisco. We have no California office, no US phone number and no local staff, and we would rather say so here than in a procurement call. Most testing that matters for a SaaS product is remote anyway; where an engagement genuinely needs physical presence, we travel and say so in the scope.

The overlap window

A fixed daily window where our late afternoon and evening meets your morning: stand-ups, live escalations and engineer walkthroughs. Critical findings go out the moment they are confirmed, whatever the hour.

Work that follows the sun

Testing continues through your night, so questions raised at the end of your day usually have answers waiting next morning - turning the time-zone gap into an extra feedback cycle rather than a delay.

Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. No hourly meters, no scope creep, and a free retest once fixes ship.

// 05 Industries we secure in San Francisco

These sectors share one trait: they hold other organisations' data inside a shared platform.

Multi-tenant SaaSB2B platforms · workflow tools · data products
Fintech & paymentsPayment flows · ledgers · embedded finance
AI & ML productsAgents · retrieval pipelines · model APIs
Developer toolingCI/CD · infrastructure · supply chain
Digital healthCare platforms · PHI handling · integrations
MarketplacesTwo-sided platforms · commerce · logistics

// 06 Our methodology

Every San Francisco engagement follows the audit-defensible process CyberFortify runs worldwide, weighted here toward authorisation and identity. Testing is grounded in the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, application work follows OWASP, and exploitation maps to the relevant MITRE ATT&CK tactics. As a CREST Accreditation Pathway firm we lead with manual testing: a scanner cannot tell you which record belongs to which tenant, and a human with two accounts open can.

01

Scoping & rules of engagement

Applications, APIs, cloud accounts, the tenant and role matrix, test windows and escalation paths agreed in writing first.

Fixed quote in 1h
02

Threat modelling the tenancy boundary

We map where the product decides a request belongs to a customer, then prioritise every path that could reach data across that line.

ATT&CK aligned
03

Manual exploitation

Confirmed weaknesses are exploited under controlled conditions and chained toward real impact, with false positives removed by hand.

Controlled exploit
04

Reporting & free retest

Attestation letter, executive summary, CVSS-scored detail and SOC 2 control mapping - then a free retest once fixes ship.

Audit-ready

// 07 Why CyberFortify for San Francisco

A scan-and-report vendor

Automated output rebadged as a pen test, unauthenticated so it never sees the tenancy model, and delivered as a PDF your prospect's reviewer sends straight back for lacking scope, methodology and exploitation evidence.

CyberFortify

A CREST-pathway team that provisions multiple tenants, tests authorisation from the inside, and reports in the language a buyer's security team and your auditor both accept. Manual exploitation, honest scoping, fixed pricing and a free retest.

Engagements here most often pair web application testing with an API assessment - one authorisation model, two surfaces.

// 08 Frequently asked questions

Will your report satisfy an enterprise security review or vendor questionnaire?

That is what it is built for. Every engagement produces an attestation letter you can hand to a prospect, an executive summary for a non-technical reviewer, and a CVSS-scored technical report with reproduction steps. Buyer-side reviewers look for scope, dates, methodology, independence and evidence of remediation, so we make all five explicit - and the free retest gives you a closing statement showing the findings were fixed.

How do you test tenant isolation in a multi-tenant SaaS platform?

We provision at least two tenants and several roles within each, then work laterally rather than downward. Object identifiers from one tenant are replayed against another to find broken object-level authorisation, scoped tokens are checked for server-side enforcement, and cache keys are probed for cross-tenant leakage. Background jobs, exports and webhooks get the same attention, because they often bypass the authorisation the API enforces.

Does a penetration test give us SOC 2 certification?

No, and any vendor claiming otherwise is misleading you. SOC 2 is an attestation issued by a licensed CPA firm after an audit period. A penetration test is one piece of technical evidence supporting the common criteria on vulnerability management and change control - the piece auditors and enterprise buyers ask for by name. We produce that evidence, and our compliance consulting service helps you prepare the surrounding controls before the Type II window opens.

You are based in the Gulf - how does that work across ten time zones?

We are honest about it: our team works from the Gulf at UTC+3, roughly ten to eleven hours ahead of California, and we have no San Francisco office. We hold a fixed daily overlap window - our late afternoon and evening is your morning - for stand-ups, live escalation and walkthroughs with your engineers. Testing continues through your night, so most mornings begin with fresh progress waiting, and critical findings are escalated the moment we confirm them.

Which testing scope should a Series-stage SaaS company start with?

For most San Francisco SaaS companies the first engagement should cover the customer-facing web application, its authenticated API, and the identity layer including SSO and session handling, with tenant isolation treated as a first-class objective. Add a cloud configuration review if your IAM model has grown organically, and payment-flow testing if you handle cardholder data. We scope it on a free call and quote a fixed price.

Ready for a pen test in San Francisco?

Book a free 30-minute scoping call. We will recommend the right scope for your architecture and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →