For SaaS & startups
Small team, external perimeter, someone about to review it.
The same engine as everywhere else on this site: 66 controls across 25 categories, every finding returned with its raw evidence and its timestamp. This page is about the four situations where a small team reaches for it first.
Four situations
Your first enterprise security questionnaire
A prospect's security team sends a vendor questionnaire and most of it asks about your external perimeter: TLS configuration, security headers, DNS and email authentication, exposed paths. A scan answers that part with an observation and a date instead of a self-declaration.
A team with no dedicated security engineer
When nobody owns security full time, the external surface drifts silently: an expired certificate, a header dropped in a refactor, a staging path left reachable. Continuous measurement turns that drift into a dated diff rather than a discovery during an audit.
Pre-Series A technical due diligence
Investor-side technical due diligence asks what is exposed and since when. A control set that is fixed and re-runnable produces a history, not a snapshot assembled the week of the process.
A procurement review you did not plan for
Reviews arrive with a deadline. Having the 66 controls already mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA removes the re-formatting step, which is usually where the days go.
Evidence standard
What a security department gets, check by check
66 controls across 25 categories
A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared.
Raw evidence and a timestamp on every finding
Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.
Mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA
Mapping happens in the engine, so the export goes to the auditor without re-formatting.
Exposure confirmed by content signature
Any exposed file or sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s.
SaaSFort performs automated external-surface analysis. It is complementary to a manual penetration test, not a replacement for one, and it does not detect business-logic flaws.
What this is not
Worth stating plainly, because a reviewer will ask and a small team should not be caught promising more than the engine does.
- -- A replacement for a manual penetration test. It is not, and a serious reviewer will ask for both.
- -- A certification. No accreditation body certifies this service.
- -- Business-logic testing. Broken authorisation between two of your tenants is out of scope for an external automated analysis.
- -- A compliance programme. NIS2 and ISO 27001 cover far more than an external perimeter; this covers the external perimeter.
Reference guides: SaaS Security Leaderboard: public NIS2 grades ·Security scan by use case ·NIS2 supplier questionnaire ·Prove SaaS security to enterprise buyers ·NIS2 audit evidence requirements ·NIS2 supply chain Article 21 ·How to answer a security questionnaire fast ·Vendor security assessment guide ·What a NIS2 audit costs
Measure it before someone else does
Free scan, no account. Every finding comes back with its evidence and its timestamp.