For growing SaaS companies

Pentesting for growing SaaS companies

Once you run several apps and APIs and sell to enterprises, one annual pentest stops being enough. Customers ask for a recent report, auditors ask how findings were closed, and every release changes what's exposed. With Barrion, pentests rerun on a schedule, and deeper tests come with a report signed off by a security engineer.

Signs you've outgrown it

When does a SaaS company outgrow the annual pentest?

Usually when two or more of these are true. None of them is a legal trigger. They're the points where a yearly report stops answering the questions people ask you.

Surface

Three or more apps, or a public API

Each app and API has its own logins, roles and endpoints. A test of the main app says little about the admin panel or the API partners call.
Release pace

You ship every week

A report from March doesn't cover the billing API you shipped in May. With weekly releases, most of your code was never in last year's test.
Sales

Enterprise deals come with a security review

Procurement asks for a recent pentest of the product they're buying, plus what happened to the findings. Auditors don't always require a pentest. Customers do.
Compliance

SOC 2, ISO 27001 or NIS2 on the calendar

Auditors want to see how you find and fix technical vulnerabilities across the whole period, not only the week before the audit.
Cadence by app tier

What should a pentest program for several apps look like?

Match the depth to the risk and the frequency to how often each app changes. Treat this as a starting point, not a rule.

Evidence

What do customers, auditors and regulators each ask for?

Different people read the same pentest for different reasons. Barrion doesn't make you compliant. It produces evidence that supports the testing and vulnerability-handling parts of each review.

How Barrion runs it

One program across your apps and APIs.

AI agents test each app the way an attacker would, on the schedule you set. A security engineer reviews the findings from Standard up.

How it runs

As often as you ship

Save a pentest and it reruns daily, weekly, monthly or on your own rhythm, or only when your app has changed. You can also start one from your CI/CD pipeline via the Barrion API, or on demand from the dashboard.
What's tested

Your web app and API

Specialist agents work in parallel on injection, access control, authentication and business logic, mapped to the OWASP WSTG test cases, the OWASP Top 10 and the OWASP API Security Top 10.
Checked

Findings checked against the live app

Confirmed findings come with the request and response behind them. Anything unconfirmed is clearly marked, so you know which is which.
Run over run

New, open, resolved or regressed

Each run is compared with the last one, so you see what's new, what's still open, what you fixed and what came back.
Retests

Free retests of found issues

Fixed something? Retest it at no charge. The retest reuses the scope and test accounts from the original run.
Engineer review

A security engineer looks first

From Standard up a security engineer reviews the findings, and deeper tests come with a report signed off by that engineer.

Tests are rate-limited and non-destructive, and you approve the scope before any traffic goes out. Continuous programs are scoped to your apps, cadence and depth, so talk to us and we'll price it for your setup.

The details a CTO asks about

  • ✓Schedules run daily, weekly, monthly, quarterly, every six months, yearly or on a custom rhythm, and one app can have several
  • ✓From Standard up, reports are released within one working day, after the engineer review
  • ✓Staging environments are supported, so deep runs don't have to touch production
  • ✓Customer data is stored and hosted in Sweden, and AI processing runs in the EU
  • ✓Not tested: internal networks, Active Directory, mobile apps, physical security, social engineering and TLPT under DORA
Business plan

What the plan includes.

Continuous pentesting comes with it. It's the plan for teams with several apps, and it's priced to what you run.

  • ✓Continuous AI pentesting
  • ✓Volume discounts on pentest credits
  • ✓A pentest program scoped to your apps
  • ✓Teams & organizations
  • ✓API access
  • ✓Daily passive scans, 10 domains
  • ✓Slack & Teams alerts
  • ✓Priority support, dedicated contact
Cost

What drives the cost of a program?

FAQ

Pentesting for SaaS companies, answered.

Do SaaS companies need a pentest if no law requires one?
Usually, yes, because customers ask for one. SOC 2 doesn't require a pentest. Many auditors accept one as evidence for CC4.1 and CC7.1, and enterprise customers usually ask for the report. Their security reviews ask when your product was last tested and what happened to the findings.
How often should a SaaS company pentest its apps?
Frameworks set the floor. PCI DSS 11.4 asks for a pentest at least every 12 months and after significant changes, and SOC 2 and ISO 27001 set no interval. If you ship every week, test often: a fast daily run, plus a deeper run every month or quarter.
Can one program cover several apps and APIs with different cadences?
Yes. Each app or API can have its own saved pentests, and one target can have several schedules, for example a daily Light run plus a monthly Deep run. Each schedule has its own scope and depth, and can run every time or only when the app has changed.
Will our customers accept an AI pentest report?
That depends on the customer, and we won't promise it. A Barrion report shows the scope, a methodology mapped to OWASP WSTG, the request and response for each confirmed finding, and fix status. From Standard up a security engineer reviews the findings, and deeper tests come with a report signed off by that engineer. Send the sample report to your customer's reviewer early and ask.
Can we test staging instead of production?
Yes. You can point a pentest or a schedule at a staging environment. Tests are rate-limited and non-destructive either way, and you approve the scope before any traffic goes out. Many teams run the deep tests on staging and a lighter schedule on production.
Where is our test data stored and processed?
Customer data is stored and hosted in Sweden, and AI processing runs in the EU. Every subprocessor is listed on our trust page. Barrion AB is a Swedish company, so an EU buyer's data-processing review deals with an EU vendor.
How is a continuous program priced?
Continuous programs are scoped to your apps, cadence and depth, so talk to us and we'll price it for your setup. The main cost drivers are the number of apps and APIs, the depth of each run, how often they run and how many authenticated roles need testing. Per-run prices for single pentests are public on the pricing page.

Scope a continuous program.

Tell us which apps and APIs you run and who asks for the report. One reply within a working day, with a scope and a price.