01
Tenant isolation
I test whether an authenticated user can cross the boundary between separate customer accounts.
Independent application security · United Kingdom
GreySurface finds and explains the authentication, authorisation, API and tenant-isolation failures that let one user reach what belongs to another.
Self-controlled accounts
Minimum necessary proof
No payment condition
Remediation support
Published acknowledgements
Commissioned security
Focused, authorised reviews for teams that need a careful look at who can read, change or administer what inside a SaaS product—without turning the engagement into a broad compliance exercise.
Best suited to product and engineering teams shipping B2B software with roles, workspaces, organisations, APIs or customer-separated data.
01
I test whether an authenticated user can cross the boundary between separate customer accounts.
02
I check whether access decisions are applied to the individual record requested, not only to the route or session.
03
I review registration, activation, invitation, session, recovery, and account-state boundaries.
04
I compare intended product permissions with the behaviour of authenticated API endpoints.
References
Feedback from vendors after private disclosure, remediation support or fix validation. Every attributed quote is used with permission; identities stay private where requested.
18
published vendor references and acknowledgements
01 / FEATURED
“I would like to acknowledge the professional and responsible manner in which Nick from GreySurface handled the security disclosure for My Sport Manager. The report was well-structured, thorough, and clearly documented with easy-to-reproduce findings, enabling us to secure our infrastructure promptly. We appreciate the value provided by such responsible security research.”
Ciarán Doyle
Lead Developer · My Sport Manager / OF Software
02 / FEATURED
“Nick (GreySurface) reported a security issue in SecTrak to us through responsible disclosure. The report was clear, well-scoped and reproducible, with testing limited to trial tenants he created himself. The issue he identified was genuinely useful for our team to fix, and the way he handled the disclosure end-to-end is the standard I'd want from anyone doing this work.”
Steve Drenkovics
Director · Montalex Limited
03
“Nick from GreySurface identified and documented two real vulnerabilities in our Cognito configuration, including a silent account takeover chain. The report was technically accurate, the disclosure was handled responsibly, and the fixes were live in production the same day. If you manage a B2B product and receive a report from him, I'd recommend taking it seriously.”
Massimiliano
itinovo CRM
04
“The report was thorough, well-documented with reproduction steps, and clearly written with the intent to help. We'd have no hesitation recommending Nick.”
Dimity Tindall
Head of Operations · Coassemble
05
“Nick reported it to me professionally, providing enough information to identify and resolve the matter within a few hours. I recommend his professionalism and expertise.”
Ika Balzam
CEO · WorkZen
06
“Nick provided a professional review of our platform's security. He was thorough but respectful and provided a detailed report of his findings. We will definitely be using his services in the future.”
SimplyInspect Support
SimplyInspect
07
“GreySurface was very kind to perform a security audit on Pulso and submit a professional report. Thanks to them our platform is more secure.”
Ivan Stoilov
Team Pulso
08
“GreySurface responsibly reported a security issue to PropReady, communicated it clearly, and helped us validate the fix.”
PropReady Team
PropReady
09
“The findings were well-structured, clearly written and easy to reproduce and verify.”
Public security acknowledgement
10
“Your report demonstrated a high level of professionalism and ethical conduct. Your actions directly assist us in our ongoing efforts to enhance our security posture.”
Responsible Disclosure Team
Crunch
11
“Nick (GreySurface) reported a security issue to us through responsible disclosure. His communication was clear and professional throughout the process. I'd recommend him to anyone handling a similar report.”
SaaS co-founder
Identity withheld by request
12
“Your write-up was thorough, professional, and clearly in good faith. The responsible disclosure approach was exactly the right way to handle this.”
Vendor reference
Identity withheld by request
13
“The reproduction steps, timestamps, CVSS scoring, and cleanup list made it genuinely easy for our team to triage and validate quickly.”
Vendor reference
Identity withheld by request
14
“I really appreciate the time, care, and clarity you put into this write-up. The clean reproductions made it easy to act on quickly.”
Vendor reference
Identity withheld by request
15
“I appreciate the care you took: registering your own accounts, pulling only enough to confirm the issue, and writing it up clearly.”
Vendor reference
Identity withheld by request
16
“Nick's report was clear, well scoped and responsibly handled. The control tests saved us time confirming scope and helped us validate the fixes.”
Kelvin
CertNow
17
“We appreciate your responsible disclosure and the professionalism you demonstrated throughout this process. Your commitment to improving security, combined with the clarity of your report, enabled our team to assess and mitigate the issue. We value the time and effort you invested in reporting the issue”
Vendor security team
Identity withheld by request
18
“Nick reported a security issue to us privately, handled the disclosure responsibly and professionally throughout, and was straightforward to deal with in resolving the matter.”
Michael Saunders
References can be confirmed directly where the vendor has offered to do so.
Discuss a reviewMethod
Small proof, clear impact and enough technical detail for an engineer to reproduce the issue without guesswork.
01
I establish access using an account or trial environment I control.
02
I use the minimum read-only proof needed to establish whether a security boundary has failed.
03
I do not bulk enumerate records or test state-changing actions against data outside my account.
04
I contact the vendor directly with an impact summary, reproducible evidence, and remediation context.
05
I remain available to clarify the report and validate the fix.
Vendors receive the report, evidence and remediation support regardless of whether they choose to recognise the research with a discretionary contribution.
Read the disclosure principlesFor security and engineering teams
Verify the sender, understand the testing boundary and see the safest next steps for routing and remediation.
For SaaS product teams
Commission a focused review of tenant isolation, authorisation, authentication or API access control with a written scope and practical report.