Skip to main content

What are you looking for?

Explore our services and discover how we can help you achieve your goals

SaaS security checklist for product teams: ten areas to check before launch and at every release

A SaaS security checklist works when each item names an owner and the evidence that proves it. Check ten areas: tenant isolation, identity and access, API and business logic, data protection, secrets, dependencies and builds, logging and detection, backup and recovery, incident response, and customer evidence. Review before launch, then again at every major release.

Book a solution review See the related service

Reviewed by David (CEO) · Updated 1 Oct 2026 · 11 min read

star

This checklist is for product managers, engineering leads and founders who ship a multi-tenant product and must answer customer security questionnaires. Our SaaS platform engineering guide lists the security basics in a short section; this page turns them into items a team can tick, with the evidence to attach.

In this guide

How to use the checklist

Treat each item as a question with three parts: who owns it, what proof exists today, and when it was last checked. An item without an owner is not done, whatever the code does. Keep the answers in one place, such as the repository, so a customer's security review can be answered from the record instead of from memory.

Two rules keep the list honest. Tick an item only when a test, a log, a setting or a document shows it, and run the list against the product you operate today, not the architecture diagram.

Ten areas at a glance

Area What to check Evidence to keep
Tenant isolation Every query, cache key, file path and background job carries the tenant Automated cross-tenant tests that must fail to read another tenant's data
Identity and access Strong sign-in, MFA for admins, least-privilege roles, session limits Role matrix, MFA enforcement setting, session settings
API and business logic Object and function level authorisation, rate limits, an inventory of endpoints API inventory, authorisation test results, rate-limit configuration
Data protection Encryption in transit and at rest, data classes, retention and deletion Encryption settings, data map, deletion procedure
Secrets No secrets in code, rotation, separate keys per environment Secret scan results, rotation log
Dependencies and builds Dependency scanning, reviewed code, a record of what is deployed where Scan reports, pull request history, release log
Logging and detection Who accessed which tenant's data, and when; alerts on failed and cross-tenant access Audit log sample, alert rules, retention setting
Backup and recovery Backups restored by test, including one tenant on its own Restore test record with date and result
Incident response A written plan, named roles and a customer notice template The plan, contact list, last exercise date
Customer evidence Answers to questionnaires drawn from the record above A maintained answer library and a list of what you can share

Tenant isolation: where SaaS products fail

Access control is the area where web applications fail most often: the OWASP Top 10:2025 lists Broken Access Control first. For a multi-tenant product one missing tenant check can show one customer's data to another. The OWASP Multi-Tenant Security Cheat Sheet turns that into concrete controls:

  • Bind the tenant to a verified identity. Take the tenant from the server-side session, not from a value the client sends, and check membership on every request.
  • Scope every lookup. Include the tenant in database queries, or enforce it in the database with row-level policies, so a guessed identifier does not return another tenant's record.
  • Key caches by tenant. A cache entry without the tenant in its key can serve one customer's page to another.
  • Carry the tenant through queues and jobs. A background job must re-check the tenant it runs for, and storage paths and signed file links need the same scope and a short life.
  • Offboard cleanly. Revoke credentials and apply the retention rule to backups and file storage when a tenant leaves.

Our multi-tenant SaaS architecture guide compares the isolation models behind these controls.

Identity, API and business-logic checks

Identity and access. Require multi-factor authentication for administrators and offer it to every user; support single sign-on for business customers who ask for it. Keep roles few and specific, expire sessions, and review administrator rights each quarter.

API security. Most SaaS features are APIs, so the OWASP API Security Top 10 (2023) is a practical test list. Start with object level authorisation (API1), authentication (API2), property level authorisation (API3), unrestricted resource consumption (API4) and function level authorisation (API5). Keep an inventory of every endpoint, including old versions: improper inventory management is API9.

Business logic. Some flaws are not bugs in one request but in a sequence: skipping a payment step, reusing an invite, or exporting more than a plan allows. API6 names this unrestricted access to sensitive business flows. Write down the intended flows for sign-up, invitations, billing and export, and test that each step is enforced on the server, not only hidden in the interface.

Data, secrets and the supply chain

  • Encrypt in transit and at rest, and keep keys outside the application code with a named owner for each key.
  • Classify the data. Know which fields are personal or sensitive, where they are copied, such as logs, exports and analytics, and how long each copy lives.
  • Keep secrets out of repositories. Scan for them, use a secret store, give each environment its own credentials and rotate them when people leave.
  • Know your dependencies. Scan packages and container images, review code before merge, and keep a record of what version runs where. The NIST Secure Software Development Framework (SP 800-218) describes the practices behind this, and OWASP's Application Security Verification Standard lists requirements you can reference in tickets.
  • Treat third-party services as part of your attack surface. Each integration key is scoped to the least it needs, and OWASP calls out unsafe consumption of APIs (API10) when you trust an upstream response too far.

Logging, recovery and incident response

A product that cannot answer "who accessed this tenant's data, and when?" cannot investigate or prove anything. Log sign-ins, permission changes, exports and administrator actions with the tenant and user, protect the logs from the people they describe, and alert on repeated failures and on any denied cross-tenant attempt.

Backups only count when restored. Restore a whole environment and also a single tenant into a clean environment, record the date and the outcome, and repeat after major changes. For incident response, write a short plan with named roles, a decision on when customers are told, and a template for the notice; run a tabletop exercise before the first real incident.

Security for AI features

AI features add new paths to the same data. Treat every document, message or web page an assistant reads as untrusted input; keep retrieval and prompts limited to the current tenant, enforced outside the prompt; log what the assistant read and did; and require human approval before an action changes records or money. Our guide to security and human approval for AI agents covers the controls in detail. Netbase works with the major commercial and open-source AI models, chosen per product rather than tied to one vendor. Each item below states how mature it is at Netbase.

Who does the review: alternatives and selection criteria

Route Strength Weakness Choose it when
Internal review with this checklist Cheap, repeatable and close to the code Shared blind spots; marks its own homework Early products and every routine release
Independent penetration test Fresh attacker's view, with a report customers accept A snapshot; costs time and money; needs fixes after Before a launch to business customers, or after major change
Security built into the delivery team Controls are designed in, reviewed and tested every sprint Needs a team that already works this way A product still being built or reworked
Compliance framework and audit A recognised report that shortens customer reviews Slow to start; proves a process, not that the code is safe Customers ask for a report as a condition of buying

Choose by four criteria: what customers require in contracts, how sensitive the data is, how often you release, and whether anyone on the team can own security. Most products need the first two together: a routine checklist, and a test by outsiders before a major launch.

A review plan

  1. Draw the data flows

    List where tenant data enters, is stored, is copied and leaves, including logs, exports, queues and AI features.

  2. Assign an owner to each of the ten areas

    One person answers for each area, even if several do the work.

  3. Collect the evidence

    Run the tests, export the settings and file the records named in the table above.

  4. Fix and rank the gaps

    Close tenant isolation and access findings first, because they carry the most damage.

  5. Test from outside

    Commission an independent test when the product goes to business customers or changes materially.

  6. Repeat on a schedule

    Re-run the list at each major release and each quarter, and update the questionnaire answers from it.

How Netbase builds and checks SaaS products

Netbase builds multi-tenant products for clients and runs its own. Its published security practices are secure code review and version control, TLS in transit and AES at rest, role-based access control, MFA for admin dashboards, vulnerability scanning and penetration testing, and disaster recovery; NDAs, data processing agreements and SLAs are available on request. Netbase holds ISO 27001 certification and a SOC 2 Type II attestation. Both cover how Netbase itself works, not a client's product or hosting, which still needs its own controls, evidence and, where customers require it, its own audit. Netbase works on AWS, Google Cloud, DigitalOcean and Cloudflare, and claims no cloud partner tier. Most Netbase projects are delivered on fixed-price contracts agreed after discovery. See SaaS development, the SaaS product accelerator for reusable accounts, tenants and roles, and application security assurance for testing. The MVP roadmap places these checks in the first weeks; to judge a vendor's answers, see security questions for a software development partner.

What delivery record exists, and what does not

  • What exists. Netbase builds and operates Cloodo Workspace, a multi-tenant digital workplace, and Printcart, a SaaS serving many merchants. Since 2020 it has worked as offshore development and managing partner on a multi-tenant cloud ERP for a US client, whose name is withheld.
  • What does not. No Netbase record publishes penetration test results, incident history, audit findings, vulnerability counts or response times, and none is offered as evidence that a particular control works. Nothing on this page certifies any product.

Limits of this guide

  • It is a working checklist, not a compliance programme; regulated sectors such as payments or healthcare add their own requirements, so take specialist advice.
  • Standards change: check the current OWASP, NIST and provider guidance on the day you review.
  • A checklist cannot find unknown flaws; that is the job of testing and independent review.

Plan the next step with a Netbase consultant

Frequently asked questions

Tenant isolation and access control, then secrets, backups you have restored, and logging. These carry the largest damage for the least effort, and customers ask about them first.

Only if your customers require it. Many buyers start with a questionnaire and ask for a report later; the checklist above gives you the answers either way.

At each major release and at least quarterly, with an independent test before a launch to business customers or after a major change.

No. A test is a snapshot by outsiders; the checklist keeps the controls in place between tests.

Next step

Share your tenancy model, your current evidence and the questionnaires customers send you, and we will book a solution review to map gaps to the ten areas. You can also see SaaS development or more Netbase insights.

AI-ready SaaS development from a team that runs its own SaaS AI-ready SaaS development from a team that runs its own SaaS

Netbase provides SaaS development services for founders and product teams to launch and scale multi-tenant subscription software with AI features customers will pay for. We build and operate our own SaaS platforms, Printcart and the AI-powered Cloodo workplace, and bring that experience to client products. A typical SaaS MVP takes 8–12 weeks, depending on scope, integrations and review speed.

Learn More
line
Application security assurance for web, SaaS and AI features Application security assurance for web, SaaS and AI features

Netbase provides application security testing for product and engineering leaders to find and fix vulnerabilities before release, including in AI features. We review code with AI-assisted triage, scan dependencies and test running applications, then rank findings and retest fixes. Netbase's own ISO 27001 certification and SOC 2 Type II attestation cover Netbase's operations, never your application.

Learn More
line
SaaS product accelerator: launch an AI-ready SaaS on proven Netbase modules SaaS product accelerator: launch an AI-ready SaaS on proven Netbase modules

A SaaS product accelerator is a set of reusable Netbase modules for accounts, billing, roles and integrations that helps founders and product teams launch subscription software faster, with room for in-product AI from the first release. Reusing these modules can cut development time by up to 60%, and the approach is proven on Printcart, Netbase's own web-to-print SaaS.

Learn More
line
Contact Netbase

Discuss a project

Netbase JSC helps organizations design, build, modernize, and operate digital products and AI-enabled business systems.
Project enquiries

[email protected]

WhatsApp

+84 937 869 689

Office address

91 Nguyen Chi Thanh, Dong Da, Hanoi, Vietnam

Get in touch

Tell us what you want to build, modernize, or operate.

Tell us what you want to build, modernize, or operate.

Contact Netbase