TENANT ISOLATION AUDIT

Prove Customer A Cannot Access Customer B's Data

Your SaaS can look finished while still trusting the wrong organization ID, exposing an API route or returning another tenant's file. I test the tenant boundary across authentication, roles, database queries, APIs and storage, then show you exactly what passed, what failed and what must be fixed.

For Next.js, Supabase, Prisma, PostgreSQL and AI-built B2B applications.

Read-only review available. Production testing requires an approved staging environment and defined scope.

Risk Recognition

Multi-tenancy usually fails in the gaps between systems

Authentication only proves who the user is. It does not prove which organization they may access. Cross-tenant exposure often appears when the application trusts a request parameter, checks a resource ID without its organization, accepts an inactive membership or protects the database but not file storage.

Organization ID tampering

A user replaces a header, query parameter or request-body organization ID with another tenant’s identifier.

IDOR in API routes

A route retrieves, updates or deletes a record by ID without also enforcing verified tenant ownership.

RLS gaps

Supabase policies protect common reads but miss inserts, storage objects, service-role paths or security-definer functions.

Role escalation

A viewer, member or administrator can grant themselves permissions or create a more privileged membership.

Storage leakage

Database rows are tenant-scoped while files, signed URLs, public buckets or deletion operations are not.

AI-generated inconsistency

Rapidly generated routes use different authorization patterns, leaving a small number of high-impact exceptions.

The dangerous failure is not that every route is insecure. It is that one forgotten path can defeat an otherwise sound architecture.

Who This Is For

Built for teams crossing the line from prototype to real customer data

AI-built SaaS founders

You used Lovable, Bolt, Replit, Cursor, Windsurf or another AI development workflow and now need independent verification before onboarding customers.

B2B SaaS teams

You are adding organizations, workspaces, invitations, roles, team billing or enterprise accounts.

Development agencies

You need a repeatable, white-label tenant review before handing client applications into production.

Regulated or sensitive applications

You handle financial, legal, healthcare, employment, compliance or operational data where cross-customer exposure would be material.

This is not intended for static marketing websites, single-user applications with no shared data model or teams seeking a broad infrastructure penetration test.

What Gets Tested

The tenant boundary is tested as a system

Authentication and organization context

  • Session and token handling
  • Organization selection and switching
  • Header, query, body and URL parameter substitution
  • Stale organization context
  • Missing organization context
  • Deleted and inactive organizations
  • Development authentication bypasses

Membership and roles

  • Pending and inactive memberships
  • Invitation acceptance
  • Owner, admin, member and viewer boundaries
  • Self-promotion
  • Admin-to-owner escalation
  • Custom permission overrides
  • Last-owner protections
  • Cross-organization memberships

API and database access

  • Route authentication coverage
  • Resource ownership checks
  • IDOR testing
  • Tenant-scoped create, read, update and delete operations
  • Prisma query filters
  • PostgreSQL constraints
  • Supabase RLS policies where applicable
  • Service-role and server-side bypass paths
  • Background jobs, webhooks and administrative routes

Storage isolation

  • Upload ownership
  • Bucket and object policies
  • Blob-path construction
  • Public versus private access
  • Signed URL behavior
  • Download authorization
  • Cross-tenant deletion
  • Retention and archival operations

Evidence and regression protection

  • Cross-tenant behavioral tests
  • Sanitized request and response evidence
  • Finding severity and execution path
  • Required regression test
  • CI-gate recommendation
  • Re-test after remediation
Technology Coverage

Focused on modern SaaS stacks

Next.js App RouterReact and TypeScriptSupabase Auth, PostgreSQL RLS and Supabase StoragePrisma and PostgreSQLNeonNextAuth / Auth.jsVercel and Vercel BlobStripe organization or seat-based billingLovable, Bolt, Replit, Cursor and Windsurf-generated applications

If your stack differs, request a fit review. The engagement depends on whether the tenant boundary can be safely reproduced and tested in an isolated environment.

Audit Process

A narrow process designed to produce actionable evidence

01

Scope the tenant boundary

We identify the authentication system, organization model, roles, tenant-owned resources, storage paths and highest-risk API surfaces.

02

Review the implementation

I trace how organization context moves from the authenticated identity through middleware, API handlers, database queries, background operations and file access.

03

Attempt controlled cross-tenant access

Using synthetic tenants in an approved environment, I attempt unauthorized reads, writes, deletes, role changes and storage access.

04

Deliver findings and next actions

You receive confirmed execution paths, severity, affected code, remediation priorities and the tests required to prevent regression.

Deliverables

What you receive

Tenant architecture map
Inventory of protected and public routes
Authorization-helper comparison
Confirmed cross-tenant findings
Rejected false positives
Role-escalation analysis
Storage-isolation analysis
Database and RLS analysis
Sanitized test evidence
Prioritized remediation plan
Executive summary for founders or clients
Technical appendix for developers
Optional post-fix verification report

Reports document the tested scope and observed behavior. They are not certifications, legal opinions or guarantees that no vulnerability exists outside the reviewed scope.

Audit Versus Deployment

Choose verification, remediation or a complete tenant foundation

Tenant Isolation AuditAudit and RemediationMulti-Tenant Deployment
Existing application requiredYesYesOptional
Architecture reviewIncludedIncludedIncluded
Cross-tenant testingIncluded when staging fixtures are availableIncludedIncluded
Findings reportIncludedIncludedIncluded
Code changesNot includedIncluded within agreed scopeFull implementation
Organization and membership modelNot includedRepairs and consolidationIncluded
RBAC implementationNot includedRepairs includedIncluded
Storage isolationReviewedRepairs includedIncluded
CI regression gateRecommendedIncluded where technically feasibleIncluded
Re-testOptionalIncludedIncluded
Best suited forTeams needing independent answers before deploymentApplications with confirmed or suspected authorization gapsSingle-user or prototype applications becoming B2B SaaS
Pricing

Clear starting points

Final pricing depends on route count, number of tenant-owned resource types, storage systems, authentication complexity and whether a safe staging environment already exists.

Tenant Boundary Review

Starting at $950

A focused, read-only review for a small application or one critical workflow.

  • Architecture and tenant-context review
  • Up to 25 priority API routes
  • Membership and role review
  • One storage path review
  • Written findings and remediation priorities
  • 45-minute findings walkthrough
Recommended

Tenant Isolation Audit

Starting at $2,500

Behavioral verification across the application’s principal tenant boundary.

  • Two synthetic organizations
  • Cross-tenant read, write and delete attempts
  • IDOR and organization-context testing
  • Role-escalation testing
  • Storage-isolation testing
  • Database or RLS review
  • Sanitized evidence report
  • Developer remediation plan
  • Executive findings walkthrough

Hardening and Verified Deployment

Starting at $5,000

Remediation or implementation of a secure organization-based multi-tenant foundation.

  • Confirmed finding remediation
  • Canonical tenant authorization helper
  • Active membership enforcement
  • Strict role and permission model
  • Tenant-scoped database access
  • Storage authorization
  • Cross-tenant regression tests
  • CI security gate
  • Post-fix verification report
  • Deployment handoff

Agency, white-label, regulated-data and larger application engagements are custom scoped.

Why Subodh

Built from implementation experience, not a generic checklist

I am a former Fortune 50 software and AI program leader who now builds and reviews AI, compliance and operational systems. My work spans application architecture, authorization, evidence generation, testing and production delivery.

This service comes from the expensive part of building multi-tenant products: tracing organization ownership across hundreds of routes, resolving inconsistent authorization patterns and converting security assumptions into executable tests.

The objective is not to produce a long list of theoretical concerns. It is to determine which paths are reachable, which controls actually hold and what must change before customer data is placed behind them.

About Subodh KC All Services
Engagement Boundaries

Safe testing boundaries

Testing is performed against source code and an approved staging, test or isolated environment. Production testing is only performed under explicit written scope and safeguards.

No destructive testing without approval
No use of real customer data in demonstrations
No credential extraction
No social engineering
No denial-of-service testing
No compliance certification
No legal opinion
Findings are limited to the reviewed commit, configuration and environment
Critical findings are communicated promptly rather than held until the final report
FAQ

Tenant isolation audit FAQ

What is a SaaS tenant isolation audit?+

A tenant isolation audit determines whether one customer, organization or workspace can access another tenant’s records, files, administrative functions or billing context. It reviews authentication, organization membership, API authorization, database queries, role changes and storage access as one connected boundary.

Is authentication enough to protect a multi-tenant SaaS?+

No. Authentication establishes who the user is. Tenant authorization must also establish which organizations and resources that identity may access. A valid signed-in user can still exploit a route that trusts a supplied organization ID or retrieves a record without verifying ownership.

Do you audit Supabase Row-Level Security policies?+

Yes. A Supabase review can cover RLS policies for reads, inserts, updates and deletes; membership functions; service-role paths; storage policies; security-definer functions and the relationship between server-side routes and database enforcement.

Do you review Next.js and Prisma applications?+

Yes. The review traces authorization through Next.js middleware and route handlers into Prisma queries, PostgreSQL relationships, background operations and storage access. Special attention is given to resource queries that use an ID without a verified organization constraint.

Can you review an application built with Lovable, Bolt, Replit or AI coding tools?+

Yes. AI-built applications are a strong fit because individually generated routes may use inconsistent authorization patterns. The review evaluates the resulting implementation rather than judging which tool produced it.

Will you test my production database?+

The preferred approach is an isolated staging environment with synthetic tenants and data. Production testing requires explicit scope, backups, access controls and agreement on permitted actions. Destructive tests are excluded unless separately authorized.

What access do you need?+

A read-only repository review can begin with source access and architecture context. Behavioral verification normally requires a dedicated branch or commit, an isolated database, synthetic user accounts, staging deployment access and relevant logs. Credentials should be scoped to the minimum required permissions.

What does the final report include?+

The report includes the tested scope, architecture observations, confirmed findings, rejected false positives, execution paths, severity, affected code, existing mitigations, recommended fixes and regression tests. Behavioral engagements also include sanitized request and response evidence.

Can you fix the vulnerabilities you find?+

Yes. Remediation can be scoped after the audit or included in the Hardening and Verified Deployment engagement. Fixes may include canonical authorization middleware, role restrictions, tenant-scoped queries, RLS policies, private storage delivery and automated isolation tests.

Can you convert a single-user application into a multi-tenant SaaS?+

Yes. The deployment service can add organizations, memberships, invitations, roles, organization switching, tenant-owned resources, storage isolation and regression testing. Scope depends on the existing data model and application workflows.

Is this a penetration test or compliance certification?+

No. This is a specialized application-security and architecture review focused on tenant isolation. It does not replace a comprehensive penetration test, independent compliance examination or legal review.

How long does an audit take?+

A focused review can often be completed within several business days after access and scope are ready. A behavioral audit or remediation engagement may require one to several weeks depending on route count, data models, storage systems and environment readiness.

Can agencies use this as a white-label service?+

Yes. Agencies can request a white-label engagement, repeatable pre-delivery review or agency license when the TenantProof tooling becomes available. Client communication, report branding and remediation responsibilities are defined during scoping.

What happens if no serious vulnerability is found?+

The report documents what was tested, which controls held, remaining limitations and the regression tests needed to preserve that result. The value is evidence about the tenant boundary, not a predetermined vulnerability count.

Request an Audit

Before onboarding the next customer, test the boundary between them

Send the stack, approximate API-route count, authentication system and whether a staging environment exists. I will confirm whether the application fits a focused review, behavioral audit or full multi-tenant deployment.

Do not include credentials, API keys or secrets. Your information is used only to assess fit and respond to your inquiry.
Let's Talk →