Skip to content
Services
How it works Scope & safety Findings Review desk Blog Write to us
HomeServicesWeb & API security
Web & API security

Your app has roles.
Do its boundaries hold?

An assessment for teams shipping authenticated applications, APIs and multi-tenant services. We scope the business workflows and trust boundaries that matter to your product.

INSIDE THE ASSESSMENT
Same application. Separate authority.Two tenant boundaries connect to a shared API. Each user’s authority must remain scoped to the intended tenant.TENANT ATENANT BMember ATenant-scoped accessMember BTenant-scoped accessApplication APIAuthorization boundary
Same application. Separate authority.
IdentityRolesTenant boundaries
01 / Where this helps

Start with a change.
Ask the right security question.

Three illustrative assessment scenarios. These explain the service—not customer findings or promised outcomes.

Workspace AWorkspace BSAME PRODUCT · SEPARATE DATA
MULTI-TENANT SAAS

New workspace.
Same isolation promise.

You are introducing shared workspaces, invitations or a new tenant model.

The question
Do the agreed roles and workflows preserve the intended separation between customers?
Assessment focus
Selected tenant boundaries, role transitions and API authorization using designated test accounts.
Useful output
Reviewed observations tied to roles, affected workflows and demonstrated impact—not just endpoint counts.
MemberAdminA ROLE CHANGE IS A TRUST CHANGE
IDENTITY & PERMISSIONS

More permissions.
Clearer boundaries.

You are changing account recovery, team administration or privileged access.

The question
Does the application enforce the authority intended for each account state and role?
Assessment focus
Agreed registration, session, recovery and permission-change flows, including relevant API operations.
Useful output
Reproduction context and access assumptions that help engineering understand the affected boundary.
AppAPIServiceCONNECTED SYSTEMS · EXPLICIT TRUST
RELEASES & INTEGRATIONS

A new connection.
A new set of assumptions.

You are launching a sensitive workflow or connecting another service.

The question
Are identity, state and permission assumptions consistent across the scoped workflow?
Assessment focus
Selected state transitions and integration boundaries, within the operations explicitly authorized.
Useful output
Evidence and limitations explained in the context of the release decision your team needs to make.
02 / Define the boundaries

Know what is included.
Know what needs agreement.

Web & API engagement scoping guide
AreaCandidate scopeConfirm before testing
Applications & APIsNamed URLs, APIs, versions and selected workflows.Ownership or testing authorization; third-party exclusions.
Accounts & rolesDedicated accounts representing relevant users and tenants.Available roles, test data and permitted account actions.
EnvironmentAgreed staging or other designated environments.Production checks require explicit agreement on actions and limits.
Operational limitsDefined testing windows and an escalation contact.Disruptive checks, real-user messaging and destructive operations are not assumed to be authorized.
Delivery & follow-upScope summary and human-validated findings.Timing, reporting requirements, retest scope and commercial terms.

Coverage depends on agreed scope and available access. Untestable or excluded areas are identified; they are not treated as evidence that a system is secure.

03 / Controlled testing infrastructure

Test the workflow.
Keep the resources deliberate.

Our AI agent model can use designated research resources for approved scenarios. These capabilities do not grant unrestricted access to your systems.

OWNED DOMAINS

Assigned DNS records

Designated records on our domains support agreed validation scenarios without depending on unrelated third-party infrastructure.

TEST SERVERS

Designated environments

Assigned servers support controlled test components. Resource access and permitted actions stay within the engagement boundaries.

TEST IDENTITIES

Account journeys

Dedicated test email accounts enable registration, email verification and sign-in flows using the accounts agreed for testing.

04 / The human approval gate

Research can be autonomous.
Delivery has an owner.

Our AI agent model supports investigation and evidence collection. Our team owns final technical validation, impact judgment and approval before findings reach you.

  1. 01

    Investigate

    Explore within scope and collect supporting observations.

    AI-SUPPORTED RESEARCH
  2. 02

    Validate & approve

    Review the mechanism, reproducibility, impact and unresolved uncertainty.

    OUR RESEARCHERS
  3. 03

    Deliver

    Explain reviewed findings, remediation guidance and assessment limits.

    CUSTOMER HANDOFF

Insufficient evidence stays an open question—not a confirmed finding. A test limitation is not a clean bill of health.

05 / Your deliverable

Built for prioritization.
Ready for engineering.

The report connects technical behavior to the decision your team needs to make. A reader should be able to distinguish what was observed from what remains uncertain.

  • LeadershipScope, material observations and relevant business context.
  • EngineeringAffected components, reproduction context and practical remediation guidance.
  • Follow-upCoverage limitations and the result of retesting, where agreed.
Ask for a shareable sample report ↗
ILLUSTRATIVE STRUCTURE · NOT A CUSTOMER REPORT
TECHNICAL FINDING

One boundary.
A clear explanation.

01

Context & affected scope

Environment, component, roles and preconditions.

02

Supporting evidence

Expected versus observed behavior, with reproduction context.

03

Impact & uncertainty

Demonstrated consequences and limits of the assessment.

04

Remediation & retest

Guidance for the fix and follow-up status where agreed.

06 / Before we start

Practical questions.
Clear expectations.

Have a specific buyer requirement or operational constraint? Bring it to the scoping conversation.

What do you need from our team?

A short product description, proposed assets and workflows, relevant account roles, available test environment and target timeline. We then agree on access and authorization. Do not send credentials in an initial inquiry.

Can you assess production?

Only where explicitly authorized and appropriate for the agreed checks. Environment, permitted actions, operational limits and escalation arrangements are discussed before testing.

How is sensitive data handled?

We define permitted test data, access boundaries and evidence-handling requirements before the engagement. If you need specific retention, deletion, residency or contractual commitments, share those requirements so we can confirm whether we can meet them.

What determines price and timing?

Asset and workflow scope, available roles and access, environment complexity, reporting needs and follow-up requirements. We confirm a proposal after scoping; this page does not promise a fixed turnaround or price.

How do we stay in touch during testing?

We agree on technical contacts, communication channels and escalation arrangements at kickoff. Tell us about time-sensitive concerns so the engagement can be scoped appropriately.

Will you verify our fixes?

Retesting can be agreed as part of the engagement. The scope, timing and terms should be explicit; a retest result applies to the tested fix and conditions, not to the entire application.

Is this a compliance certification?

No. An assessment is bounded by scope, access and time; it does not certify compliance or guarantee an absence of vulnerabilities. Share any buyer-specific assessor or report requirements before engaging us.

LET’S DEFINE YOUR ENGAGEMENT

Bring us your scope.
We’ll discuss the next step.

Share your system, priorities and target date.
Please do not include credentials or sensitive findings.