Skip to content
Solvex Space
Cloud / DevSecOpsB2B SaaS / HR technology2-week focused assessment

Finding a cross-tenant data flaw in a B2B SaaS before a customer did

Series C HR platform, ~350 staff, multi-tenant on Kubernetes

An HR platform holding payroll and personal data for hundreds of customers had passed generic pentests for years — but nobody had ever attacked its tenant boundaries specifically. A dedicated isolation assessment proved that a background export job could be steered across tenants, a bug class its previous tests had no time to reach. It was fixed and retested before any customer, regulator or attacker ever saw it.

Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.

Cross-tenant paths proven exploitable
1 critical, 3 medium
seeded test tenants only — no real customer data touched
Findings closed and retested clean
100%
within the engagement window
Isolation regression tests specified for CI
22
run on every build since
Customer data exposed
0
found by assessment, not by an attacker

The challenge

  • Multi-tenant architecture carrying payroll-grade data, where a single isolation failure would be a reportable breach for every affected customer.
  • Previous annual pentests sampled broadly and had never systematically attacked tenant boundaries, async jobs or shared caches.
  • Enterprise prospects were starting to ask pointed questions about tenant isolation in security review.

What we did

  • Seeded multiple test tenants on both sides of every boundary and attacked application, API, data and infrastructure layers role by role.
  • Chased tenant context through the unglamorous paths — background jobs, exports, webhooks and caching — where isolation bugs hide.
  • Reviewed the Kubernetes layer for shared-infrastructure leakage between tenant workloads.
  • Turned every confirmed finding class into a specified regression test for the client's CI pipeline.
  • Retested all fixes and confirmed the export-job flaw was closed at the architectural level, not patched around.

The outcome

  • The cross-tenant export flaw was proven with seeded tenants only, fixed at the tenant-context layer, and confirmed closed on retest.
  • The client's CI now runs isolation regression tests on every build, so the bug class is continuously verified rather than annually sampled.
  • Security review answers about tenant isolation moved from assertion to evidence.
Every pentest we'd bought before treated tenant isolation as one line item among fifty. This one treated it as the whole job — and found the thing that would have ended customer relationships.
VP Engineering, Series C HR platformIllustrative — composed to show the kind of feedback this work draws, not a quotation from a named client.
SaaS Tenant Isolation Assessment | Case Study — Solvex Space