Skip to content

Independent application security · United Kingdom

Independent security research for multi-tenant SaaS.

GreySurface finds and explains the authentication, authorisation, API and tenant-isolation failures that let one user reach what belongs to another.

Self-controlled accounts

Minimum necessary proof

No payment condition

Remediation support

Published acknowledgements

  • My Sport Manager
  • SecTrak
  • itinovo CRM
  • Coassemble
  • WorkZen
  • SimplyInspect
  • Pulso
  • PropReady
  • Skribble
  • Crunch
  • CertNow
  • StockCraft

Commissioned security

The boundary is the product. I test whether it holds.

Focused, authorised reviews for teams that need a careful look at who can read, change or administer what inside a SaaS product—without turning the engagement into a broad compliance exercise.

Best suited to product and engineering teams shipping B2B software with roles, workspaces, organisations, APIs or customer-separated data.

01

Tenant isolation

I test whether an authenticated user can cross the boundary between separate customer accounts.

02

Object-level authorisation

I check whether access decisions are applied to the individual record requested, not only to the route or session.

03

Authentication and account lifecycle

I review registration, activation, invitation, session, recovery, and account-state boundaries.

04

API access control

I compare intended product permissions with the behaviour of authenticated API endpoints.

References

Useful findings. Clear reports. Professional handling.

Feedback from vendors after private disclosure, remediation support or fix validation. Every attributed quote is used with permission; identities stay private where requested.

18

published vendor references and acknowledgements

01 / FEATURED

I would like to acknowledge the professional and responsible manner in which Nick from GreySurface handled the security disclosure for My Sport Manager. The report was well-structured, thorough, and clearly documented with easy-to-reproduce findings, enabling us to secure our infrastructure promptly. We appreciate the value provided by such responsible security research.

Ciarán Doyle

Lead Developer · My Sport Manager / OF Software

02 / FEATURED

Nick (GreySurface) reported a security issue in SecTrak to us through responsible disclosure. The report was clear, well-scoped and reproducible, with testing limited to trial tenants he created himself. The issue he identified was genuinely useful for our team to fix, and the way he handled the disclosure end-to-end is the standard I'd want from anyone doing this work.

Steve Drenkovics

Director · Montalex Limited

03

Nick from GreySurface identified and documented two real vulnerabilities in our Cognito configuration, including a silent account takeover chain. The report was technically accurate, the disclosure was handled responsibly, and the fixes were live in production the same day. If you manage a B2B product and receive a report from him, I'd recommend taking it seriously.

Massimiliano

itinovo CRM

04

The report was thorough, well-documented with reproduction steps, and clearly written with the intent to help. We'd have no hesitation recommending Nick.

Dimity Tindall

Head of Operations · Coassemble

05

Nick reported it to me professionally, providing enough information to identify and resolve the matter within a few hours. I recommend his professionalism and expertise.

Ika Balzam

CEO · WorkZen

06

Nick provided a professional review of our platform's security. He was thorough but respectful and provided a detailed report of his findings. We will definitely be using his services in the future.

SimplyInspect Support

SimplyInspect

07

GreySurface was very kind to perform a security audit on Pulso and submit a professional report. Thanks to them our platform is more secure.

Ivan Stoilov

Team Pulso

08

GreySurface responsibly reported a security issue to PropReady, communicated it clearly, and helped us validate the fix.

PropReady Team

PropReady

09

The findings were well-structured, clearly written and easy to reproduce and verify.

Skribble

Public security acknowledgement

10

Your report demonstrated a high level of professionalism and ethical conduct. Your actions directly assist us in our ongoing efforts to enhance our security posture.

Responsible Disclosure Team

Crunch

11

Nick (GreySurface) reported a security issue to us through responsible disclosure. His communication was clear and professional throughout the process. I'd recommend him to anyone handling a similar report.

SaaS co-founder

Identity withheld by request

12

Your write-up was thorough, professional, and clearly in good faith. The responsible disclosure approach was exactly the right way to handle this.

Vendor reference

Identity withheld by request

13

The reproduction steps, timestamps, CVSS scoring, and cleanup list made it genuinely easy for our team to triage and validate quickly.

Vendor reference

Identity withheld by request

14

I really appreciate the time, care, and clarity you put into this write-up. The clean reproductions made it easy to act on quickly.

Vendor reference

Identity withheld by request

15

I appreciate the care you took: registering your own accounts, pulling only enough to confirm the issue, and writing it up clearly.

Vendor reference

Identity withheld by request

16

Nick's report was clear, well scoped and responsibly handled. The control tests saved us time confirming scope and helped us validate the fixes.

Kelvin

CertNow

17

We appreciate your responsible disclosure and the professionalism you demonstrated throughout this process. Your commitment to improving security, combined with the clarity of your report, enabled our team to assess and mitigate the issue. We value the time and effort you invested in reporting the issue

Vendor security team

Identity withheld by request

18

Nick reported a security issue to us privately, handled the disclosure responsibly and professionally throughout, and was straightforward to deal with in resolving the matter.

Michael Saunders

References can be confirmed directly where the vendor has offered to do so.

Discuss a review

Method

A disciplined path from access to evidence.

Small proof, clear impact and enough technical detail for an engineer to reproduce the issue without guesswork.

01

Create

I establish access using an account or trial environment I control.

02

Confirm

I use the minimum read-only proof needed to establish whether a security boundary has failed.

03

Stop

I do not bulk enumerate records or test state-changing actions against data outside my account.

04

Report

I contact the vendor directly with an impact summary, reproducible evidence, and remediation context.

05

Support

I remain available to clarify the report and validate the fix.

Independent reports are never conditional on payment.

Vendors receive the report, evidence and remediation support regardless of whether they choose to recognise the research with a discretionary contribution.

Read the disclosure principles

For security and engineering teams

Received a GreySurface report?

Verify the sender, understand the testing boundary and see the safest next steps for routing and remediation.

For SaaS product teams

Need the boundary checked before someone else finds it?

Commission a focused review of tenant isolation, authorisation, authentication or API access control with a written scope and practical report.