03 / ClearanceSAAS + AI FEATURE

SaaS penetration testing, including your AI feature.

SaaS penetration testing is an authorized attack on your platform, its web app, APIs, identity and tenant isolation, by people who confirm what is exploitable. Launch Clearance puts your AI feature in the same scope: one test, one report, and the cross-layer findings that only appear when the chatbot, RAG search or agent and the platform under it are tested together.

For SaaS teams shipping AI to enterprise customers, for the release where both layers have to pass a security review.

Package
SAAS + AI FEATURE
Range, excl. VAT
EUR 10,000 to 20,000
Testing days
8 to 14

SCOPE / LAUNCH CLEARANCE / ONE ENGAGEMENT04 ROWS READ / 1 FOUNDSAMPLE

ONE SCOPE, BOTH LAYERSWHAT ONE TEST COVERS

  1. MODEL LAYERThe AI feature: the assistant, its retrieval and its tools
  2. STACK LAYERThe platform: web app, APIs, identity and tenants
  3. THE LINEPaths that cross it, tested as one
  4. REPORTOne report and one letter, a chain rated where it ends

X-01 / ONE PATH ACROSS THE LINE / RATED WHERE IT ENDS

Both layers in one scope, so a path that starts in a conversation and ends in another tenant’s data is one finding, not two halves in two reports. The reach below walks one.

How does one weak spot reach the other layer?

Follow one line nobody reviewed, hop by hop: from the knowledge base through retrieval and the agent, over a third-party MCP server, into the API gateway and another tenant’s record. Each hop maps to its own framework id. Together they are one path, and one finding in our report.

MODEL LAYER

STACK LAYER

  • KNOWLEDGE BASE
  • RETRIEVAL
  • AGENT
  • TOOLS
    EMAIL / CRM / REFUNDS
  • MCP SERVER
  • WEB APP
  • API GATEWAY
  • IDENTITY
  • TENANT DATA
  • OBJECT STORAGE
  • CLOUD ACCOUNT
  1. 01 UNREVIEWED TEXT
    STORED AS POLICY LLM01:2026 / PROMPT
    INJECTION
  2. 02 RETRIEVED AS TRUSTED
    CONTEXT ASI06 / MEMORY AND
    CONTEXT POISONING
  3. 03 INSTRUCTION FOLLOWED LLM03:2026 / EXCESSIVE
    AGENCY
  4. 04 THIRD-PARTY TOOL,
    NEVER REVIEWED ASI04 / AGENTIC SUPPLY
    CHAIN
  5. 05 TOKEN SCOPED WIDER
    THAN THE TASK API1:2023 / BROKEN
    OBJECT LEVEL
    AUTHORIZATION
    GET /claims/48213 / 200
  6. 06 ANOTHER TENANT’S
    RECORD WSTG-ATHZ / TENANT
    ISOLATION
FIG. 2 / THE REACH. Six hops across two layers, each mapped to its framework id: the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, the OWASP API Security Top 10 and the WSTG.

What does Launch Clearance test?

Both layers, scoped together. The rows below are where an AI feature meets the platform under it; the scoping call adds or removes rows, and the coverage matrix in the report shows every one.

Every row is a category in our test catalogue. Ids link to the framework that defines them.
No.CategoryWhat we checkMapped to
01Prompt injection resistance, direct and indirectWhether content the AI feature reads can give it instructions, and what those instructions could reach in your platform.
02Vector store and embedding isolation between users and tenantsWhether AI search and retrieval respect the same tenant boundaries as the rest of the platform.
03Sensitive information disclosure in answers and rendered outputWhether the AI feature can disclose one customer’s data to another, in its answers or in rendered output.
04Tool and function calls kept within the task's intended scopeWhether the agent’s tool calls stay inside the task and inside the requesting customer’s data.
05Agentic supply chain: MCP servers, plugins and tool definitionsWhich MCP servers and plugins the feature depends on, and what a change upstream would reach.
06Validation of model output before it reaches code, browsers or databasesWhether AI output is checked before the platform renders it, stores it or acts on it.
07Object level authorization on every endpointWhether every endpoint the AI feature calls checks object ownership against the end user, not against the agent.
08Authorization and tenant isolationAuthorization and tenant isolation across the platform, with and without the AI feature in the path.
09Business logic and multi-step workflow integrityWhether workflows the AI can start, such as refunds or exports, keep their business rules when an agent runs them.
10API authentication and token handlingThe tokens the AI feature holds: whose they are, what they open, and how long they last.

Out of scope Model training, the model provider’s own infrastructure, and third-party services your platform calls without their owner’s written permission.

What does a cross-layer finding look like?

One card for the whole chain, with every hop named. This one comes from the fictional engagement in our sample report, and it is the path the plate above walks.

SAMPLE / FICTIONAL CLIENT / REAL FORMAT

SAMPLE-01 / X-01

CRITICALCVSS-B 9.3BOTH LAYERSAPI1:2023

From an unreviewed page to another customer’s claim

Business impact
Tested one layer at a time, these read as two high findings and one critical one in different reports. Together they are one path from a partner upload account to another customer’s claim, walked through someone else’s conversation.
The path
  1. 01 / F-03 A page enters the knowledge base through the partner portal, unreviewed.
  2. 02 / F-03 A customer’s question retrieves it, and the assistant follows it.
  3. 03 / F-02 The assistant calls a tool on a claim outside the conversation.
  4. 04 / F-01 Its token reaches every tenant’s claims.
  5. 05 / F-01 The API returns and updates another customer’s claim.
Findings joined
F-03 / F-02 / F-01 Rated by where the chain ends: Critical, as F-01.
CVSS v4.0 vector
Rated where it ends: F-01CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Fix principle
Fixing F-01 alone breaks the chain. Fixing all three removes it, which is what the retest confirmed.
Retest
FIXED 2026-09-24 F-01, F-02 and F-03 are fixed, so no step of the path holds.
The format every finding takes in our report. The client and the finding are fiction; the fields are not. Read X-01 in the sample report.

How does Launch Clearance run?

One tester, one scope, one report. Three things make it more than two tests booked back to back.

  1. 01One threat model

    We model the platform and the feature together.

    What an attacker can reach through the AI feature is decided by your platform’s authorization model, and the reverse. One threat model covers both, so the test plan follows paths across the line instead of stopping at it.

  2. 02Same tester

    The person who tests the model tests the API it calls.

    A model finding that reaches a tool, and an API finding that an agent can trigger, are tested by the same people in the same window. Nothing gets lost in a hand-over between two suppliers, and nobody has to argue whose half a finding belongs to.

  3. 03Cross-layer findings

    We report paths, not only points.

    When a manipulated answer leads to a tool call that leads to another tenant’s record, the report shows the chain as one finding, with every hop mapped to its own framework id and the one fix that breaks the chain earliest.

  4. 04Evidence

    One report for your customers’ security review.

    The report and the attestation letter answer the questions enterprise security teams send, for the platform and the AI feature at once. SOC 2 lists penetration testing among the evaluation methods under CC4.1, and ISO 27001:2022 controls A.8.8 and A.8.29 are commonly evidenced with a pentest report.123

    If your customers fall under the Dutch Cyberbeveiligingswet, its duty of care covers the security of their supply chain, which is why their questionnaires now reach you.4

  5. 05Before launch

    We plan backwards from your launch date.

    Book the test so the report and the retest land before customers see the feature. The test window itself is 8 to 14 testing days.

The engagement, in short.

8 to 14 testing days on staging where we can, under the rules of engagement you sign first. Then the report and a one-page letter, and the retest once you have fixed. Every step, from the scoping call to the regression pack, is in the method.

What does Launch Clearance cost?

Launch Clearance is one package for both layers, excluding VAT. Its value is one scope, one kickoff, one report and the cross-layer findings, not a discount on two separate tests.

03 / Launch Clearance

SAAS + AI FEATURE

EUR 10,000 to 20,000

TYPICALLY 8 TO 14 TESTING DAYS

What moves the price

  • The AI feature’s tools, sources and tenants
  • Roles, tenants and workflows on the platform
  • Third-party MCP servers and APIs in the path
  • Staging with realistic data, or production windows

See all prices

Report
Scope, method, dates, findings with evidence, severity in CVSS v4.0, framework ids, fix guidance and retest status.
Attestation letter
One page that confirms scope, dates and retest status, for customers who need the result without the findings.
Coverage matrix
Every category in scope marked tested, not applicable or out of scope, so the gaps are written down too.
Evidence
A cross-layer section that shows every path from the AI feature into the stack, hop by hop.

Questions about Launch Clearance.

What is Launch Clearance?

Launch Clearance is our SaaS penetration test with your AI feature in the same scope. One tester tests the platform and the chatbot, RAG search or agent together, in one window, and delivers one report with the cross-layer findings that separate tests miss. It is priced at EUR 10,000 to 20,000, excluding VAT.

Why test the AI feature and the platform together?

Because the expensive findings cross the line. A prompt injection matters when the agent can call an API, and an authorization flaw matters more when an agent can reach it on anyone’s behalf. Two separate tests each see half of that path; one test sees the whole path and the fix that breaks it earliest.

What is a cross-layer finding?

A cross-layer finding is a path that starts in the AI layer and ends in the stack, or the reverse, such as an instruction in a retrieved document that leads an agent to an API call that reads another tenant’s data. We report the path as one finding, with every hop mapped to its framework id.

Which SOC 2 and ISO 27001 controls does the report support?

For SOC 2, a point of focus under CC4.1 lists penetration testing among evaluation methods. For ISO 27001:2022, a pentest report is commonly used as evidence for A.8.8, management of technical vulnerabilities, and A.8.29, security testing in development and acceptance. Your auditor decides what it covers.

When should we book it, relative to the launch?

Early enough that the report and the retest land before customers see the feature. Count back from the launch date: a testing window of 8 to 14 testing days, the report, your fixes and the retest. If the date cannot move, a smaller scope tested properly beats a larger one tested in a rush.