How SaaS companies and startups should approach VAPT: when to run the first test, what to scope, multi-tenant risks, and how to use the report in enterprise sales and SOC 2.
When to run your first VAPT
For most SaaS startups the first VAPT is triggered by a deal: an enterprise prospect sends a security questionnaire asking for a recent penetration test report. It is better to run the test before that moment, ideally once your core product is stable and before a major launch, fundraising due diligence or SOC 2 audit window. Testing a product that changes daily is still useful, but freeze the main flows during the test so results stay valid.
What to scope
Start with what customers and auditors care about: the main web application, the public and internal APIs it depends on, authentication including SSO and password reset, admin panels and any mobile apps. Include your cloud configuration review if you run on AWS, Azure or GCP, since misconfigured storage, identity policies and exposed services are common sources of real incidents. Marketing sites usually matter less unless they share authentication or infrastructure with the product.
Multi-tenant risks testers should focus on
The highest-impact SaaS issues are usually authorisation flaws: one customer reading or changing another customer's data by altering an ID, privilege escalation from a regular user to an admin, and insecure invite or role-change flows. These are classified under broken access control in the OWASP Top 10 and broken object level authorisation in the OWASP API Security Top 10. Scanners rarely find them, so make sure your scope includes manual testing with at least two tenants and every user role.
Using the VAPT report in enterprise sales
Prospects want to see that testing was independent, recent and that serious issues were fixed. Keep a short attestation or executive summary ready to share under NDA, alongside your remediation status. Avoid sharing raw technical details publicly. Being able to answer security questionnaires quickly with a recent report shortens procurement cycles.
Budgeting for VAPT
Cost depends on the number of applications, APIs, roles and environments, and on whether retesting is included. Rather than buying the cheapest scan, define the decisions the report must support: closing a specific deal, passing an audit or meeting a regulator's expectations. That makes scoping clearer and avoids paying for testing that does not meet the requirement. Ask vendors for a fixed-scope quote in INR or USD with deliverables spelled out.
Ongoing cadence
A common pattern is a full VAPT once a year plus targeted tests after significant changes such as new modules, a new API, an authentication rework or a cloud migration. Fast-moving teams may prefer continuous or on-demand testing aligned to releases. Track findings in your normal engineering backlog so security fixes ship like any other work.
