Skip to main content

Pre-launch security review

What a security review looks like

The findings section of a pre-launch security review, answering the question the client actually asked: is this safe to put a competitor's data into? Three findings from a multi-tenant SaaS on Node.js, PostgreSQL and AWS. The P0 is a composite chain rather than a list of separate weaknesses — a token claim never re-checked against current membership, row-level security enabled on 3 of 19 tenant-scoped tables, and an application role that owns those tables and is therefore exempt from the policies on them. The subject is fictional and every finding invented; external claims are cited to PostgreSQL, OWASP and AWS documentation.

PostgreSQL · Row-level security · Multi-tenant SaaS

Your browser can't display the PDF inline.

Open the document (PDF)
Fictional sample. 3 pages. Open in a new tab