Skip to content
· 6 min read

SaaS web app pentest: one tenant and one fixed price

A SaaS web app pentest of one tenant app is $2,400 one-time, $1,200 to start. Written in 48 hours. A second product is a second quote, not a subscription.

Two marble med-spa stations with one curtain pulled open into the other, a wax-sealed envelope, and a brass key in the wrong bowl, for a SaaS web app pentest.
Article language

Showing original language

Founders type SaaS web app pentest when a customer, an investor, or a security questionnaire asks whether one company can see another company’s records.

That is a tenant question. It is not a six-week red team, and it is not two products on one invoice.

Short answer: A SaaS web app pentest, the way I sell it, is an authorized review of one application: frontend, login, and the APIs the UI already calls, including whether tenant A can open tenant B. It is $2,400 one-time, $1,200 to start, on the web application security review. The report is due 48 hours after access works. A second product is a second quote. There is no subscription.

What does a SaaS web app pentest actually check?

It checks whether a user in a tenant you own can reach another tenant’s records, plus login and the APIs that page already calls. I am not selling a cloud audit, a mobile binary review, or a letter written for a procurement portal.

You provision two test tenants in the app I am allowed to touch. I use a normal user and an admin in tenant A. I look at the same kinds of records from tenant B. If a request that belongs to A comes back with B’s invoice, file, or member list, that is the finding. I describe the break in the PDF. I do not include a recipe for replaying it.

Also in the same pass:

  • Invite, password reset, and what a role can do after login
  • Exports, downloads, and uploads the UI already offers
  • An endpoint the page calls that forgets the session
  • A record that ignores which company it belongs to

Shops that sell a longer SaaS engagement price this higher once roles and APIs multiply. The table in the next section has the published ranges. I am selling one URL, written in 48 hours after login works.

What should a SaaS web app pentest cost?

One application is $2,400 once. $1,200 starts the work. $1,200 is due when the PDF is delivered. Two products means two quotes. I do not add a monthly seat, and I do not fold a second product in for free.

What you are buyingPublished 2026 rangeThis offer
One small SaaS web app$4,000–$12,000 (SecureLeap)$2,400 once, one app
Authenticated web app, one target$5,000–$15,000 (SecurityWall)Same $2,400 if it is one app
Early SaaS with a cloud overview$8,000–$13,000 (DSecured)Not this. I do not review your cloud account
Enterprise SaaS, many roles, source review$16,000–$55,000 (DSecured)Out of scope
Scanner-heavy or thin validation$100–$3,000 (WardenBit)Not this. A human writes the PDF

Synack’s 2026 table puts web application tests at $5,000–$30,000, with multi-tenant SaaS at the high end. If you need that letter, buy that engagement. My number is on security review pricing: $2,400 per app, half to start.

There is no subscription across 24 or 36 months. The same URL next year is another $2,400. Two passes are $4,800. Two small-SaaS engagements at SecureLeap’s low end are $8,000. That comparison holds only for one web app. It does not hold if you wanted the $16,000–$55,000 program.

One free retest of the same URL sits inside the original price, within 14 days of the report. After that window, or on a feature the first PDF never saw, it is a new quote.

How does the pass run from login to the PDF?

The trigger is written authorization plus tenants you own. The action is a signed-in walk of the UI and the APIs it calls. The system of record is the ranked PDF. You decide the fixes. I retest that URL once.

  1. You name one hostname and send written permission to test it.
  2. You create two test tenants and the users inside them. No live customer data.
  3. I confirm I can sign in. The 48-hour clock starts then, not when the first email landed.
  4. I write severity, which role, which kind of record, and the fix. No payloads.
  5. You patch. I retest the same URL once, free, within 14 days.
SituationHow I quote it
One app, two test tenants you own$2,400 once
Admin console that is a separate applicationA second $2,400
Web app plus a mobile binaryWeb is this quote. Mobile is not included
You want every role, the cloud account, and sourceNot this offer
A customer’s production tenantRefused. I only touch tenants you own

Booking from ChatGPT into a CRM is a Business MCP, not this review. A repeating invoice chase is One Lane at $3,500 once. Neither one answers whether tenant A can read tenant B.

What is not in the $2,400?

A second product, a customer’s production tenant, source code, mobile apps, phishing, your cloud account, and any exploit recipe. The PDF will not name other clients, and it will not include payloads.

If admin is a different application from the product your customers log into, say so before I sign in. I will quote it on its own. A second hostname is a scope line you settle before the clock starts. I will tell you if it is still one pass or a second quote. I will not discover a second product halfway through and treat it as a free extra.

I will not test a tenant you do not own. “Try a real customer, they will not notice” is a no.

The format, with names removed, is the sample pentest report. You can ask for it from the sample request before you pay the $1,200.

When this isn’t the right move yet

Wait if you cannot mint a test tenant, you need a SOC 2 or CREST letter, the app has no login yet, or you are trying to cover two products with one invoice.

Also wait if the only artifact you want is a scanner export. WardenBit puts that band at $100–$3,000. That file will not answer whether company A can open company B.

Buy this when you have one production or staging URL, you can grant a test user this week, and a customer or a questionnaire is asking about isolation now. If the questionnaire wants a multi-week program, a cloud review, and source, this pass will not satisfy it. Pay for the engagement that matches the letter.

What do you send before I log in?

Send the URL, written scope, two test tenants, one normal user, one admin, and a note listing anything I must not touch. Do not send a customer’s password. Login has to work the day I start.

  • The hostname in scope, and the hostnames that are out
  • How to reset a test user if a login locks
  • Whether billing or webhooks hit a live processor — point those at a test mode
  • The role names that matter (owner, member, billing, support)
  • A person who can fix a broken login the same day

Start when that list is real. $1,200 starts the review. The rest is due when the report lands. Use start the review. It is a short form. I reply with what is in and what is out. I do not book a call to explain the price.

FAQ

How much does a SaaS web app pentest cost? +

A SaaS web app pentest of one application is $2,400 one-time. $1,200 starts the review and $1,200 is due when the report is delivered. A second product, a separate admin app, or a customer's live tenant is a new quote. There is no monthly fee and no subscription.

What does one tenant mean in the scope? +

I test tenants you own: one normal user, one admin, and a second test tenant so I can see whether tenant A can open tenant B. Frontend, login, and the APIs the UI already calls are inside the $2,400. I do not open a stranger's production data or a tenant you do not control.

How fast is the written report? +

The written report is due 48 hours after I can sign in. The clock does not start on the sales email. One free retest of that same URL is included within 14 days of the report. A new feature, a new hostname, or a second app is a new $2,400 quote.

Will the PDF include exploit steps? +

No. The PDF names the path, the role, the severity, and the fix. It does not include payloads, live credentials, or client names. If you want the format before you send access, ask for the redacted sample. I will not put a reproduction recipe in a file you will forward.

Related operator notes

Keep reading

No-pressure first step

Not sure which one fits?
Get a free 20-min audit.

Bring one workflow you'd want automated. I'll tell you which deployment fits — and which doesn't — in twenty minutes. No pitch deck, no follow-up sequence. Useful even if you don't buy.

  • A real plan, not a sales call

    Which surface (Telegram, Discord, Slack, phone) fits your team, and which one doesn't.

  • Honest "don't buy this" if it applies

    If a $99/month SaaS solves it, I'll tell you which one and how.

  • A timeline + price range

    When I could deploy, what it'd cost, and what you'd own at the end.