Pentesting for growing SaaS companies
Once you run several apps and APIs and sell to enterprises, one annual pentest stops being enough. Customers ask for a recent report, auditors ask how findings were closed, and every release changes what's exposed. With Barrion, pentests rerun on a schedule, and deeper tests come with a report signed off by a security engineer.
When does a SaaS company outgrow the annual pentest?
Usually when two or more of these are true. None of them is a legal trigger. They're the points where a yearly report stops answering the questions people ask you.
Three or more apps, or a public API
You ship every week
Enterprise deals come with a security review
SOC 2, ISO 27001 or NIS2 on the calendar
What should a pentest program for several apps look like?
Match the depth to the risk and the frequency to how often each app changes. Treat this as a starting point, not a rule.
| App tier | Fast pass | Deeper run |
|---|---|---|
| Customer-facing app with personal data | Daily Light run, set to fire only when the app has changed | Monthly Deep run |
| Public API | A run whenever the API changes | Monthly Deep run |
| Admin panels and internal tools reachable from the internet | None needed | Quarterly Standard run |
| Marketing site and docs, no login | Passive monitoring | Only if a customer or auditor asks |
Change detection compares a snapshot of the start page's links and scripts, so a backend-only release can slip past it. Keep at least one schedule that runs every time on the apps that matter most. Framework minimums (PCI DSS, SOC 2, ISO 27001, DORA) are on how often to pentest.
What do customers, auditors and regulators each ask for?
Different people read the same pentest for different reasons. Barrion doesn't make you compliant. It produces evidence that supports the testing and vulnerability-handling parts of each review.
| Who asks | What they ask for | Evidence Barrion produces |
|---|---|---|
| Enterprise customer's security review | A recent pentest of the product they're buying, its scope, and whether findings were fixed | The latest report as PDF, fix status per finding and free retests showing what was resolved. See what to send when a customer asks. |
| SOC 2 or ISO 27001 auditor | How you find, rank and fix technical vulnerabilities over the audit period | Run history across the period, reports in PDF, XLSX and JSON, and retests that show fixes held |
| Customers covered by NIS2 | Documented security testing from their suppliers, with results and fixes | A named methodology mapped to OWASP WSTG, a coverage matrix, and findings with severity and fix status. See NIS2 and penetration testing. |
| Your own engineering team | What broke since the last run, and whether an old bug came back | Every finding labelled new, still open, resolved or regressed, run over run |
Not sure what your auditor will accept? Send them the sample report before the audit window opens.
One program across your apps and APIs.
AI agents test each app the way an attacker would, on the schedule you set. A security engineer reviews the findings from Standard up.
As often as you ship
Your web app and API
Findings checked against the live app
New, open, resolved or regressed
Free retests of found issues
A security engineer looks first
Tests are rate-limited and non-destructive, and you approve the scope before any traffic goes out. Continuous programs are scoped to your apps, cadence and depth, so talk to us and we'll price it for your setup.
The details a CTO asks about
- ✓Schedules run daily, weekly, monthly, quarterly, every six months, yearly or on a custom rhythm, and one app can have several
- ✓From Standard up, reports are released within one working day, after the engineer review
- ✓Staging environments are supported, so deep runs don't have to touch production
- ✓Customer data is stored and hosted in Sweden, and AI processing runs in the EU
- ✓Not tested: internal networks, Active Directory, mobile apps, physical security, social engineering and TLPT under DORA
What the plan includes.
Continuous pentesting comes with it. It's the plan for teams with several apps, and it's priced to what you run.
- ✓Continuous AI pentesting
- ✓Volume discounts on pentest credits
- ✓A pentest program scoped to your apps
- ✓Teams & organizations
- ✓API access
- ✓Daily passive scans, 10 domains
- ✓Slack & Teams alerts
- ✓Priority support, dedicated contact
What drives the cost of a program?
Four things: how many apps and APIs are in scope, how deep each run goes, how often each one runs, and how many authenticated roles need testing. A daily Light run on one app and a monthly Deep run on five APIs are very different programs.
Continuous programs are scoped to your apps, cadence and depth. Talk to us and we'll price it for your setup. What other vendors publish for year-round programs is on continuous pentesting cost.
Need a single pentest first? Per-run prices are on pricing, and Essential starts at €199/month.
Read more before you scope it.
Continuous pentesting, explained
How often should you pentest?
PTaaS vs continuous AI pentesting
Does NIS2 require penetration testing?
SOC 2 compliance monitoring
ISO 27001 compliance monitoring
Pentesting for SaaS companies, answered.
Do SaaS companies need a pentest if no law requires one?
How often should a SaaS company pentest its apps?
Can one program cover several apps and APIs with different cadences?
Will our customers accept an AI pentest report?
Can we test staging instead of production?
Where is our test data stored and processed?
How is a continuous program priced?
Scope a continuous program.
Tell us which apps and APIs you run and who asks for the report. One reply within a working day, with a scope and a price.