This checklist is for product managers, engineering leads and founders who ship a multi-tenant product and must answer customer security questionnaires. Our SaaS platform engineering guide lists the security basics in a short section; this page turns them into items a team can tick, with the evidence to attach.
In this guide
- How to use the checklist
- Ten areas at a glance
- Tenant isolation: where SaaS products fail
- Identity, API and business-logic checks
- Data, secrets and the supply chain
- Logging, recovery and incident response
- Security for AI features
- Who does the review: alternatives and selection criteria
- A review plan
- How Netbase builds and checks SaaS products
- What delivery record exists, and what does not
- Limits of this guide
- Frequently asked questions
- Next step
How to use the checklist
Treat each item as a question with three parts: who owns it, what proof exists today, and when it was last checked. An item without an owner is not done, whatever the code does. Keep the answers in one place, such as the repository, so a customer's security review can be answered from the record instead of from memory.
Two rules keep the list honest. Tick an item only when a test, a log, a setting or a document shows it, and run the list against the product you operate today, not the architecture diagram.
Ten areas at a glance
| Area | What to check | Evidence to keep |
|---|---|---|
| Tenant isolation | Every query, cache key, file path and background job carries the tenant | Automated cross-tenant tests that must fail to read another tenant's data |
| Identity and access | Strong sign-in, MFA for admins, least-privilege roles, session limits | Role matrix, MFA enforcement setting, session settings |
| API and business logic | Object and function level authorisation, rate limits, an inventory of endpoints | API inventory, authorisation test results, rate-limit configuration |
| Data protection | Encryption in transit and at rest, data classes, retention and deletion | Encryption settings, data map, deletion procedure |
| Secrets | No secrets in code, rotation, separate keys per environment | Secret scan results, rotation log |
| Dependencies and builds | Dependency scanning, reviewed code, a record of what is deployed where | Scan reports, pull request history, release log |
| Logging and detection | Who accessed which tenant's data, and when; alerts on failed and cross-tenant access | Audit log sample, alert rules, retention setting |
| Backup and recovery | Backups restored by test, including one tenant on its own | Restore test record with date and result |
| Incident response | A written plan, named roles and a customer notice template | The plan, contact list, last exercise date |
| Customer evidence | Answers to questionnaires drawn from the record above | A maintained answer library and a list of what you can share |
Tenant isolation: where SaaS products fail
Access control is the area where web applications fail most often: the OWASP Top 10:2025 lists Broken Access Control first. For a multi-tenant product one missing tenant check can show one customer's data to another. The OWASP Multi-Tenant Security Cheat Sheet turns that into concrete controls:
- Bind the tenant to a verified identity. Take the tenant from the server-side session, not from a value the client sends, and check membership on every request.
- Scope every lookup. Include the tenant in database queries, or enforce it in the database with row-level policies, so a guessed identifier does not return another tenant's record.
- Key caches by tenant. A cache entry without the tenant in its key can serve one customer's page to another.
- Carry the tenant through queues and jobs. A background job must re-check the tenant it runs for, and storage paths and signed file links need the same scope and a short life.
- Offboard cleanly. Revoke credentials and apply the retention rule to backups and file storage when a tenant leaves.
Our multi-tenant SaaS architecture guide compares the isolation models behind these controls.
Identity, API and business-logic checks
Identity and access. Require multi-factor authentication for administrators and offer it to every user; support single sign-on for business customers who ask for it. Keep roles few and specific, expire sessions, and review administrator rights each quarter.
API security. Most SaaS features are APIs, so the OWASP API Security Top 10 (2023) is a practical test list. Start with object level authorisation (API1), authentication (API2), property level authorisation (API3), unrestricted resource consumption (API4) and function level authorisation (API5). Keep an inventory of every endpoint, including old versions: improper inventory management is API9.
Business logic. Some flaws are not bugs in one request but in a sequence: skipping a payment step, reusing an invite, or exporting more than a plan allows. API6 names this unrestricted access to sensitive business flows. Write down the intended flows for sign-up, invitations, billing and export, and test that each step is enforced on the server, not only hidden in the interface.
Data, secrets and the supply chain
- Encrypt in transit and at rest, and keep keys outside the application code with a named owner for each key.
- Classify the data. Know which fields are personal or sensitive, where they are copied, such as logs, exports and analytics, and how long each copy lives.
- Keep secrets out of repositories. Scan for them, use a secret store, give each environment its own credentials and rotate them when people leave.
- Know your dependencies. Scan packages and container images, review code before merge, and keep a record of what version runs where. The NIST Secure Software Development Framework (SP 800-218) describes the practices behind this, and OWASP's Application Security Verification Standard lists requirements you can reference in tickets.
- Treat third-party services as part of your attack surface. Each integration key is scoped to the least it needs, and OWASP calls out unsafe consumption of APIs (API10) when you trust an upstream response too far.
Logging, recovery and incident response
A product that cannot answer "who accessed this tenant's data, and when?" cannot investigate or prove anything. Log sign-ins, permission changes, exports and administrator actions with the tenant and user, protect the logs from the people they describe, and alert on repeated failures and on any denied cross-tenant attempt.
Backups only count when restored. Restore a whole environment and also a single tenant into a clean environment, record the date and the outcome, and repeat after major changes. For incident response, write a short plan with named roles, a decision on when customers are told, and a template for the notice; run a tabletop exercise before the first real incident.
Security for AI features
AI features add new paths to the same data. Treat every document, message or web page an assistant reads as untrusted input; keep retrieval and prompts limited to the current tenant, enforced outside the prompt; log what the assistant read and did; and require human approval before an action changes records or money. Our guide to security and human approval for AI agents covers the controls in detail. Netbase works with the major commercial and open-source AI models, chosen per product rather than tied to one vendor. Each item below states how mature it is at Netbase.
-
Available capability
AI features with tenant-scoped data
Machine learning, NLP and generative AI inside a SaaS product with per-tenant limits; not yet tied to a published security case.
Who does the review: alternatives and selection criteria
| Route | Strength | Weakness | Choose it when |
|---|---|---|---|
| Internal review with this checklist | Cheap, repeatable and close to the code | Shared blind spots; marks its own homework | Early products and every routine release |
| Independent penetration test | Fresh attacker's view, with a report customers accept | A snapshot; costs time and money; needs fixes after | Before a launch to business customers, or after major change |
| Security built into the delivery team | Controls are designed in, reviewed and tested every sprint | Needs a team that already works this way | A product still being built or reworked |
| Compliance framework and audit | A recognised report that shortens customer reviews | Slow to start; proves a process, not that the code is safe | Customers ask for a report as a condition of buying |
Choose by four criteria: what customers require in contracts, how sensitive the data is, how often you release, and whether anyone on the team can own security. Most products need the first two together: a routine checklist, and a test by outsiders before a major launch.
A review plan
-
Draw the data flows
List where tenant data enters, is stored, is copied and leaves, including logs, exports, queues and AI features.
-
Assign an owner to each of the ten areas
One person answers for each area, even if several do the work.
-
Collect the evidence
Run the tests, export the settings and file the records named in the table above.
-
Fix and rank the gaps
Close tenant isolation and access findings first, because they carry the most damage.
-
Test from outside
Commission an independent test when the product goes to business customers or changes materially.
-
Repeat on a schedule
Re-run the list at each major release and each quarter, and update the questionnaire answers from it.
How Netbase builds and checks SaaS products
Netbase builds multi-tenant products for clients and runs its own. Its published security practices are secure code review and version control, TLS in transit and AES at rest, role-based access control, MFA for admin dashboards, vulnerability scanning and penetration testing, and disaster recovery; NDAs, data processing agreements and SLAs are available on request. Netbase holds ISO 27001 certification and a SOC 2 Type II attestation. Both cover how Netbase itself works, not a client's product or hosting, which still needs its own controls, evidence and, where customers require it, its own audit. Netbase works on AWS, Google Cloud, DigitalOcean and Cloudflare, and claims no cloud partner tier. Most Netbase projects are delivered on fixed-price contracts agreed after discovery. See SaaS development, the SaaS product accelerator for reusable accounts, tenants and roles, and application security assurance for testing. The MVP roadmap places these checks in the first weeks; to judge a vendor's answers, see security questions for a software development partner.
What delivery record exists, and what does not
- What exists. Netbase builds and operates Cloodo Workspace, a multi-tenant digital workplace, and Printcart, a SaaS serving many merchants. Since 2020 it has worked as offshore development and managing partner on a multi-tenant cloud ERP for a US client, whose name is withheld.
- What does not. No Netbase record publishes penetration test results, incident history, audit findings, vulnerability counts or response times, and none is offered as evidence that a particular control works. Nothing on this page certifies any product.
Limits of this guide
- It is a working checklist, not a compliance programme; regulated sectors such as payments or healthcare add their own requirements, so take specialist advice.
- Standards change: check the current OWASP, NIST and provider guidance on the day you review.
- A checklist cannot find unknown flaws; that is the job of testing and independent review.
Plan the next step with a Netbase consultant
Frequently asked questions
Tenant isolation and access control, then secrets, backups you have restored, and logging. These carry the largest damage for the least effort, and customers ask about them first.
Only if your customers require it. Many buyers start with a questionnaire and ask for a report later; the checklist above gives you the answers either way.
At each major release and at least quarterly, with an independent test before a launch to business customers or after a major change.
No. A test is a snapshot by outsiders; the checklist keeps the controls in place between tests.
Next step
Share your tenancy model, your current evidence and the questionnaires customers send you, and we will book a solution review to map gaps to the ten areas. You can also see SaaS development or more Netbase insights.
Related services and solutions
AI-ready SaaS development from a team that runs its own SaaS
Netbase provides SaaS development services for founders and product teams to launch and scale multi-tenant subscription software with AI features customers will pay for. We build and operate our own SaaS platforms, Printcart and the AI-powered Cloodo workplace, and bring that experience to client products. A typical SaaS MVP takes 8–12 weeks, depending on scope, integrations and review speed.
Learn More
Application security assurance for web, SaaS and AI features
Netbase provides application security testing for product and engineering leaders to find and fix vulnerabilities before release, including in AI features. We review code with AI-assisted triage, scan dependencies and test running applications, then rank findings and retest fixes. Netbase's own ISO 27001 certification and SOC 2 Type II attestation cover Netbase's operations, never your application.
Learn More
SaaS product accelerator: launch an AI-ready SaaS on proven Netbase modules
A SaaS product accelerator is a set of reusable Netbase modules for accounts, billing, roles and integrations that helps founders and product teams launch subscription software faster, with room for in-product AI from the first release. Reusing these modules can cut development time by up to 60%, and the approach is proven on Printcart, Netbase's own web-to-print SaaS.
Learn More
Discuss a project
Netbase JSC helps organizations design, build, modernize, and operate digital products and AI-enabled business systems.+84 937 869 689
91 Nguyen Chi Thanh, Dong Da, Hanoi, Vietnam
Get in touch
Tell us what you want to build, modernize, or operate.