SaaS Security Hardening & Production Monitoring
I audit and harden live products: tenant isolation, authentication, admin routes and payments, then leave behind monitoring that tells you before your users do.
The dangerous bugs in a live SaaS are not the ones that crash it. They are the tenant whose data another tenant can read, the reset flow that can be replayed, the admin route that looks protected and is not, and the outage nobody notices until a customer emails. I audit the running product against its real traffic, fix what I find, verify the fix in production rather than on a branch, and install probes so the next problem announces itself.
What you get
How I work
- 01
Map what is actually live
Most codebases contain more dead code than anyone remembers. I establish which routes, policies and flows the deployed product really uses, so the audit covers reality instead of the repository.
- 02
Audit and rank
Findings come with a concrete failure scenario, not a severity label. You get a ranked list you can act on, and I flag which ones are exploitable today versus which are debt.
- 03
Fix and verify in production
I fix the critical findings and verify each one against the deployed environment. A fix that works on a branch and not on the server is not a fix, and environment shadowing is a real cause of that.
- 04
Install the monitor
Probes for the paths that matter, deduplicated incidents, and alerts into Slack or email. You leave with something that watches the product, not just a document.
Ways to work together
Security audit of a live product
A full pass over authentication, authorisation, tenant isolation, payments and admin surfaces, delivered as a ranked list with a reproduction and a fix for each finding.
Multi-tenant isolation review
Row Level Security policies and query-level scoping tested tenant against tenant, because the common failure is an endpoint that forgets the tenant filter, not a missing policy.
Authentication hardening
Reset and OTP flows, session handling, role escalation paths and admin route protection, each verified against the deployed environment rather than assumed from the code.
Production monitoring and alerting
Probes across auth, database, payments and key pages, running every few minutes with incident deduplication so you get one alert per incident instead of a hundred.
Tech I use for this
Common questions
Q.How much does a security audit cost?
A focused audit of authentication and tenant isolation on a single product starts around $2.5k. A full pass across auth, payments, admin and data access with fixes usually runs $6k to $15k depending on size. Monitoring setup on its own is around $2k.
Q.Is this a penetration test?
No, and I will not pretend otherwise. This is a white-box engineering audit: I read your code, test your deployed environment with your permission, and fix what I find. If you need a signed pentest report for a compliance requirement, hire a licensed firm. I am often the person who fixes what their report finds.
Q.Will you touch production?
Only with your explicit permission and only for verification. Fixes go through your normal deploy path. I take a backup before anything destructive, and I tell you the exact scope before I run it.
Q.What if you find something serious?
You hear about it immediately, not in the final report. Critical findings are raised the day I find them with a recommended fix, so you can decide whether to patch now or accept the risk.
Q.Do you work on products you did not build?
That is most of this work. I have audited and hardened live products in legal tech and AI SaaS that other teams built, including ones where the schema had drifted a long way from the migrations.
Q.How long does it take?
A focused audit is about a week. A full audit with fixes and monitoring is two to four weeks. Monitoring alone is a few days.
Related services
Start your project
Tell me what you are building and I will reply within one business day with next steps. You talk to me, the person writing the code, the whole way through.