Methodology

How I actually test your SaaS.

The Zero-Leak method: a transparent process, mapped to the OWASP API Security Top 10, driven by one question — what would leak, and how fast? Written authorization first, always.

01

Scope & written authorization

We agree exactly what's in scope and you authorize it in writing. No target is touched without it.

ScopeRoENDA
02

Map your stack

I map your real surface — Supabase, APIs, auth, Stripe, secrets — the way an attacker enumerates it.

ReconEnumeration
03

Find the holes

Manual testing where SaaS actually breaks: RLS, broken access control, exposed secrets, payment logic.

ManualOWASP
04

Prove the impact

I safely demonstrate real impact — like retrieving the customer list — so severity isn't a debate.

Safe PoCImpact
05

Report in plain English

A founder-readable report: what's broken, the proof, the business impact, and the exact fix — prioritized.

Fix-firstRepro steps
06

Fix together & free retest

I walk your team through the fixes, then re-test them for free and confirm the hole is closed.

DebriefRetestClosure

Deliverables

What lands on your desk.

Plain-English report

Every finding with severity, business impact, proof and the exact fix.

The customer-list test

If your data can be pulled, I show you exactly how — and how to stop it.

Prioritized fixes

Ranked by real risk, written for the people who'll actually ship them.

Criticals, same day

Anything critical is flagged the day I find it — never held back for the report.

Free retest

Proof your fixes actually closed the hole — not just a promise.

GDPR context

What each finding means for your GDPR / CNIL exposure, in real terms.

Standards & stakes

Grounded in real frameworks — and real consequences.

I test against recognized references — and I spell out the real stakes. A hole closed means no leak → no GDPR/CNIL → no fine → customer trust intact → you can go after bigger accounts.

OWASP API Security Top 10

The reference for the API and access-control bugs that leak SaaS data.

OWASP Top 10

The classic web application risk baseline every SaaS should meet.

GDPR / RGPD

A customer-data leak means CNIL exposure: fines and reputation damage.

Authorized testing only

Everything runs under your written authorization — nothing else, ever.

See a real sample report.

I'll send a redacted example so you know exactly what you get. And the guarantee holds: zero critical vulns found, the Zero-Leak audit is free.