Tenant Isolation Security Testing

Can 1 user reach another customer’s data?

SuperPentest helps security & engineering leaders test whether a user can cross workspace, organization, or account boundaries—and documents what the testing actually shows.

Human-led, scoped testing in an authorized environment

Boundary TestIllustrative Demo
AWorkspace ATest user
Project Alpha
Billing profile
BWorkspace BTarget tenant
Project Bravo
Team records
Example observationCross-tenant request rejected
403 response

Example only—not a claim about your system. Findings depend on the agreed scope, access, and test conditions.

Built for decisions, not dashboards.

Agreed scope Reproducible evidence Clear remediation path

The Question Behind the Assessment

Your architecture says tenants are isolated. What does the application enforce?

Authorization mistakes can sit between the model and the implementation: an object identifier that resolves across workspaces, a role check that stops too early, or an API path with different rules than the interface. SuperPentest focuses the assessment on those boundaries.

01

Object-Level Access

Probe whether resource identifiers, exports, files, and records remain constrained to the requesting tenant.

02

Roles & Invitations

Examine role transitions, membership flows, and invitations for paths that could widen access unexpectedly.

03

API Boundary Behavior

Compare enforcement across supported request paths, including direct API calls within the authorized scope.

Evidence You Can Act On

Move from “we think” to a documented finding.

Each assessment is designed to give your team a defensible view of the tested boundary—not a generic vulnerability count.

  • Tested boundary mapWhat identities, tenants, roles, and surfaces were examined.
  • Reproduction evidenceRequests, responses, and conditions for validated findings.
  • Risk & remediation contextWhy a result matters and where engineering can investigate.
  • Scope-aware conclusionWhat the work supports—and what it does not establish.
Isolation Assessment
Sample Extract

Finding TI-02

Cross-workspace export reference

HighAuthorizationAPI
reproduction.txt
1 actor.workspace = “workspace-a”2 target.export = “workspace-b/exp_…”3 GET /api/exports/exp_…4 response.status = 200
Scope note

Observation shown for illustration. Real reports reflect only the agreed test environment, accounts, endpoints, and time window.

A Focused Engagement

Define the boundary. Test it. Review the evidence.

Start with the isolation question your team needs answered.

  1. 1

    Scope the Boundary

    Align on tenants, roles, surfaces, test accounts, exclusions, and operating constraints.

  2. 2

    Exercise the Controls

    Perform authorized, bounded checks against the agreed isolation paths and document observations.

  3. 3

    Review the Evidence

    Walk through validated findings, limitations, and prioritized remediation context with your team.

Start with Your Boundary

What tenant isolation question do you need answered?

Share the concern, architecture, or release decision behind it. We’ll discuss fit, scope, and safe test conditions before any assessment begins.

Discuss an Assessment Opens your email client. No testing begins without written authorization and an agreed scope.