SaaSFort

For SaaS & startups

Small team, external perimeter, someone about to review it.

The same engine as everywhere else on this site: 66 controls across 25 categories, every finding returned with its raw evidence and its timestamp. This page is about the four situations where a small team reaches for it first.

Four situations

Your first enterprise security questionnaire

A prospect's security team sends a vendor questionnaire and most of it asks about your external perimeter: TLS configuration, security headers, DNS and email authentication, exposed paths. A scan answers that part with an observation and a date instead of a self-declaration.

A team with no dedicated security engineer

When nobody owns security full time, the external surface drifts silently: an expired certificate, a header dropped in a refactor, a staging path left reachable. Continuous measurement turns that drift into a dated diff rather than a discovery during an audit.

Pre-Series A technical due diligence

Investor-side technical due diligence asks what is exposed and since when. A control set that is fixed and re-runnable produces a history, not a snapshot assembled the week of the process.

A procurement review you did not plan for

Reviews arrive with a deadline. Having the 66 controls already mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA removes the re-formatting step, which is usually where the days go.

Evidence standard

What a security department gets, check by check

  • 66 controls across 25 categories

    A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared.

  • Raw evidence and a timestamp on every finding

    Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.

  • Mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA

    Mapping happens in the engine, so the export goes to the auditor without re-formatting.

  • Exposure confirmed by content signature

    Any exposed file or sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s.

SaaSFort performs automated external-surface analysis. It is complementary to a manual penetration test, not a replacement for one, and it does not detect business-logic flaws.

What this is not

Worth stating plainly, because a reviewer will ask and a small team should not be caught promising more than the engine does.

  • -- A replacement for a manual penetration test. It is not, and a serious reviewer will ask for both.
  • -- A certification. No accreditation body certifies this service.
  • -- Business-logic testing. Broken authorisation between two of your tenants is out of scope for an external automated analysis.
  • -- A compliance programme. NIS2 and ISO 27001 cover far more than an external perimeter; this covers the external perimeter.

Measure it before someone else does

Free scan, no account. Every finding comes back with its evidence and its timestamp.