S.01SaaS and startups

Penetration testing for SaaS teams that ship weekly and answer questionnaires.

Your customers' security questionnaires, your SOC 2 or ISO 27001 auditor and your own board all ask the same question: has anyone actually tried to break the product? Darkmoon runs an autonomous penetration test against your multi-tenant application, APIs, cloud accounts and pipelines, and proves each finding with the request that exploited it. Run the open-source engine in CI, or order a managed engagement when you need an external report produced by security experts.

3
CI pipelines: GitHub Actions, GitLab CI, Jenkins
50
specialist AI agents, 142 tools
OTP
secure client space for the report
Local
self-hosted option, model on your side

S.03Technology & SaaS
Why SaaS companies are exposed.

A SaaS company concentrates the data of every customer behind one codebase, one cloud account and one deploy pipeline. ANSSI observed more compromises of cloud environments in 2025 and data exfiltrations that followed the compromise of a service provider: for a software vendor, that provider is you.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

One bug, every tenant

A broken authorization check or a predictable object identifier does not leak one account, it leaks the account next to it. Tenant isolation is the property your customers assume and your test suite rarely proves.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Velocity outruns review

Weekly or daily releases mean the application your last pentest covered no longer exists. A yearly report describes a product you replaced three sprints ago.

Attack surfaceexposure

Secrets live in the pipeline

CI/CD runners hold cloud credentials, signing keys and registry tokens. A leaked token or an over-permissive IAM role turns a build job into an administrator of your production account.

darkmoon-licence.dmeDocker
LicencePro · annual
Machine code7F3A-…-C21E
Seats1 node
Statussealed ✓

Evidence is now a sales document

SOC 2 and ISO 27001 audits, enterprise security questionnaires and GDPR Article 28 processor clauses all ask whether the product was tested and what was found. Without a report, the deal waits.

S.04Attack surface
The attack surface of a SaaS product.

Six families of systems a Darkmoon campaign enumerates and attacks on a SaaS stack, from the login page to the build runner.

Web app / API
Multi-tenant application and REST or GraphQL APIs

Object-level and function-level authorization across tenants, mass assignment, rate limits, export and import features, GraphQL introspection and batching.

SSO / OAuth
Authentication, SSO and OAuth flows

SAML and OIDC assertions, OAuth redirect and PKCE handling, session fixation, password reset and invitation links, API keys and personal access tokens.

AWS / Azure / GCP
Cloud accounts and IAM

Public storage buckets, over-privileged roles and service accounts, instance metadata reachability, exposed management endpoints and forgotten environments.

CI/CD
Pipelines, runners and secrets

GitHub Actions, GitLab CI or Jenkins jobs holding cloud credentials, workflows triggered by pull requests, artifact registries, infrastructure-as-code state files.

Kubernetes
Clusters and workloads

API server exposure, RBAC, service-account tokens mounted in pods, network policies, ingress controllers, container images with known vulnerabilities.

Webhooks / LLM
Third-party integrations and AI features

Inbound webhooks without signature checks, outbound fetches open to SSRF, OAuth app scopes, and LLM-backed features tested against the OWASP LLM Top 10 (the /for/ai-developers/ page is the deep dive).

S.05Attack paths

From one leaked token to every customer's data.

Four chains Darkmoon's agents attempt on SaaS targets. Each step is executed, not inferred, and the evidence of each hop is kept.

01
CI token to production account

A registry or cloud token committed in a workflow file or printed in build logs is replayed against the cloud API; an over-privileged role turns it into read access on the production database snapshots.

How the engine works

S.06What Darkmoon tests
What Darkmoon tests on a SaaS stack.

The orchestrator dispatches specialist agents by surface and keeps the proof of every exploitation; 142 security tools run behind a build-enforced allow-list and the model never gets a shell.

web / API
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Tenant isolation and authorization

Cross-tenant access on every object and function, privilege escalation between roles, mass assignment, GraphQL abuse. Findings are qualified EXPLOITED, CONFIRMED or UNCONFIRMED by an adversarial rubric, never by a probability score.

AWS, Azure, GCP, k8s
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Cloud, Kubernetes and CI/CD

IAM roles and service accounts, storage exposure, cluster RBAC and mounted tokens, pipeline secrets and runner reachability, laid out in the infrastructure graph of hosts, paths and relationships.

SSO, webhooks, LLM
Attack surfaceexposure

Identity, integrations and AI endpoints

SAML and OIDC handling, OAuth flows, webhook signature checks and SSRF, and your LLM features or MCP servers against the OWASP LLM Top 10.

S.07How an engagement works

From order to report, in five steps.

A process designed to be simple for the client and rigorous on the security side.

01
Describe your target

A guided form: target type, scope and objectives.

How the engine works

S.08Evidence & reporting
Concrete, actionable deliverables.

Not just an automated scan: a structured, validated and debriefed audit.

ranked
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Detailed pentest report

Vulnerabilities ranked by severity, technical evidence, business impact and prioritized remediation guidance.

email + OTP
darkmoon-licence.dmeDocker
LicencePro · annual
Machine code7F3A-…-C21E
Seats1 node
Statussealed ✓

Secure client space

Access by email and OTP code. Contractual documents, report and exchanges centralized, available whenever you need them.

video call
Attack surfaceexposure

Debrief meeting

A video call with an expert to walk through the findings, answer questions and guide you on the fixes.

S.09Where your data goes
Your customers' data stays in your cloud.

Point Darkmoon at a staging tenant, or at production under a signed authorization: the Privacy Gateway tokenizes IPs, hostnames, URLs, emails, credentials and internal paths on your side before anything reaches the model, and you can run the whole engine on a local LLM via Ollama or llama.cpp. Evidence, reports and the infrastructure graph stay on the machine or runner you control; across integrations only safe metadata leaves the host (severity, status, ids, MITRE tags, timestamps), never evidence bodies or raw requests.

S.10Regulatory context
Where a SaaS company stands with SOC 2, GDPR and NIS2.

SaaS is not a sector listed in NIS2 Annex I or II. The duties that reach a software vendor come from its auditors, its customers' contracts and the GDPR, and from NIS2 only when the company is itself a cloud, managed-service or digital provider.

SOC 2 and ISO 27001: evidence, not a mandate

The AICPA Trust Services Criteria do not name a mandatory penetration test, but auditors commonly request one as evidence under the monitoring and system-operations criteria, and ISO 27001 auditors ask the same question about technical vulnerability management. Darkmoon produces a documented, reproducible report you can hand to your SOC 2 auditor; acceptance is the auditor's call, and Darkmoon does not certify compliance.

GDPR Articles 28 and 32: the processor's duties

A SaaS vendor is usually a processor under Article 28, bound by contract to implement the appropriate technical and organisational measures of Article 32 and to assist its customers with the 72-hour breach notification of Article 33. A penetration test is one way to document those measures.

NIS2: in scope only as a cloud, MSP or digital provider

A software company falls under NIS2 Annex I point 8 (cloud computing service providers), Annex I point 9 (managed service providers) or Annex II point 6 (online marketplaces, search engines, social networks) only when its activity fits one of those types and it is at least a medium-sized enterprise: 50 staff or more, or an annual turnover and balance-sheet total above €10 M, plus the size-independent cases of Article 2(2) and Article 3. Otherwise NIS2 reaches it indirectly: customers that are essential or important entities flow the supply-chain security measure of Article 21(2)(d) down into their contracts.

Informational summary, not legal advice: whether your company is a cloud, managed-service or digital provider under NIS2 depends on your actual activity, your size and national identification. The French transposition law is not in force as of 4 October 2026 (public session at the Assemblée nationale scheduled 7 October 2026). Darkmoon does not certify compliance.

S.11Use case
A B2B SaaS before its first SOC 2 Type II audit.

A B2B SaaS company selling to enterprise accounts enters its SOC 2 observation period with several open customer questionnaires asking for a recent penetration test. The team clones the Community engine, points it at a staging environment seeded with test tenants and runs it from GitHub Actions on every release; the cross-tenant and IAM findings are fixed and retested in the following sprints. Before the audit window closes, they order a managed Pentest on Demand engagement so that ASC-IT's experts run the external test, debrief the findings and deliver the report in the secure client space.

Outcome

A report with exploited, confirmed and unconfirmed findings, evidence attached and fixes retested, handed to the auditor and attached to the customer questionnaires. Whether it satisfies a given control is the auditor's decision; the team now has the test in its pipeline rather than in its backlog.

S.12Run it yourself
Open source, self-hosted, on a local model if you want.

The Community edition is GPLv3: clone it, install it, point it at a target you are authorized to test. Pro adds the dashboard, scheduler, branded reports and the remediation agent. The managed engagement stays available when you would rather hand it to us.

S.13Frequently asked
What a SaaS CTO asks first.

Does SOC 2 require a penetration test?

Not by name: the Trust Services Criteria ask for monitoring and evaluation of controls and leave the method to the organisation. In practice most SOC 2 auditors request a recent penetration test as evidence, and enterprise customers ask for it in their questionnaires. Darkmoon gives you a report with proof of exploitation; whether it satisfies a given control is your auditor's call.

Can I hand the Darkmoon report to my auditor or to a customer?

Yes. The Community edition produces Markdown and JSON reports; Pro adds branded PDF and web reports with CVSS 3.1, MITRE ATT&CK and ISO 27001 mapping. The managed Pentest on Demand engagement delivers a report produced and debriefed by ASC-IT's security experts in a secure client space, which is what most questionnaires mean by an external test.

Can I run it in our CI/CD pipeline?

Yes. The open-source CLI runs as a stage in GitHub Actions, GitLab CI or Jenkins against an authorized staging URL, on a schedule or on deploy, and uploads the report as a build artifact. Scheduled campaigns, the live dashboard and the remediation agent that opens sandbox-validated pull requests are Pro features; the /ci/ and /integrations/ pages hold the copy-paste examples.

Is a SaaS company in scope of NIS2?

SaaS is not a sector listed in NIS2 Annex I or II. A software company is covered only when its actual activity makes it a cloud computing service provider, a managed service provider or a digital provider (online marketplace, search engine, social network) and it meets the size rule. Otherwise it meets NIS2 through its customers: essential and important entities must address supply-chain security under Article 21(2)(d) and write it into their contracts.

Will the test touch production and other customers' data?

You choose the target: most teams point Darkmoon at a staging environment seeded with test tenants, and the managed engagement scopes the target, test accounts and intervention window with you before anything runs. No test is launched without a signed authorization.

Does the model see our customers' data or our infrastructure?

No. The Privacy Gateway tokenizes IPs, hostnames, URLs, emails, credentials and internal paths on your machine before anything reaches the model and rehydrates them locally. You can also run the whole engine on a local model via Ollama or llama.cpp, so nothing leaves your network.

Community, Pro or managed: which one for a startup?

Start with the GPLv3 Community engine if you have an engineer to run it and want the test in CI. Pro adds the dashboard, scheduler, branded reports and remediation pull requests for teams that run campaigns continuously. The managed engagement at a flat €799 (indicative, adjusted to the final scope) is for the moment you need an external report with a debrief and the legal framework handled for you.

What happens after the report?

You get a prioritised fix list with the evidence for each finding, a debrief call to walk through it, and the option to retest once the fixes are in. Teams that self-host can schedule recurring campaigns (Pro) so the same checks run after each change; the Pro remediation agent can also open sandbox-validated fix pull requests for your developers to review.

S.14Related
Go deeper

S.15Next
Prove the product holds before the auditor asks.

Clone the GPLv3 engine and run it against a staging tenant you own, or order a managed engagement and get the external report with a debrief.