01
Tenant isolation
I test whether an authenticated user can cross the boundary between separate customer accounts.
Independent application security · United Kingdom
GreySurface finds and explains the authentication, authorisation, API and tenant-isolation failures that let one user reach what belongs to another.
Self-controlled accounts
Minimum necessary proof
No payment condition
Remediation support
Published acknowledgements
Commissioned security
Focused, authorised reviews for teams that need a careful look at who can read, change or administer what inside a SaaS product—without turning the engagement into a broad compliance exercise.
Best suited to product and engineering teams shipping B2B software with roles, workspaces, organisations, APIs or customer-separated data.
01
I test whether an authenticated user can cross the boundary between separate customer accounts.
02
I check whether access decisions are applied to the individual record requested, not only to the route or session.
03
I review registration, activation, invitation, session, recovery, and account-state boundaries.
04
I compare intended product permissions with the behaviour of authenticated API endpoints.
References
Feedback from vendors after private disclosure, remediation support or fix validation. Every attributed quote is used with permission; identities stay private where requested.
35
published vendor references and acknowledgements
01 / FEATURED
“I would like to acknowledge the professional and responsible manner in which Nick from GreySurface handled the security disclosure for My Sport Manager. The report was well-structured, thorough, and clearly documented with easy-to-reproduce findings, enabling us to secure our infrastructure promptly. We appreciate the value provided by such responsible security research.”
Ciarán Doyle
Lead Developer · My Sport Manager / OF Software
02 / FEATURED
“Nick (GreySurface) reported a security issue in SecTrak to us through responsible disclosure. The report was clear, well-scoped and reproducible, with testing limited to trial tenants he created himself. The issue he identified was genuinely useful for our team to fix, and the way he handled the disclosure end-to-end is the standard I'd want from anyone doing this work.”
Steve Drenkovics
Director · Montalex Limited
03
“Nick from GreySurface identified and documented two real vulnerabilities in our Cognito configuration, including a silent account takeover chain. The report was technically accurate, the disclosure was handled responsibly, and the fixes were live in production the same day. If you manage a B2B product and receive a report from him, I'd recommend taking it seriously.”
Massimiliano
itinovo CRM
04
“The report was thorough, well-documented with reproduction steps, and clearly written with the intent to help. We'd have no hesitation recommending Nick.”
Dimity Tindall
Head of Operations · Coassemble
05
“Nick reported it to me professionally, providing enough information to identify and resolve the matter within a few hours. I recommend his professionalism and expertise.”
Ika Balzam
CEO · WorkZen
06
“Nick provided a professional review of our platform's security. He was thorough but respectful and provided a detailed report of his findings. We will definitely be using his services in the future.”
SimplyInspect Support
SimplyInspect
07
“GreySurface was very kind to perform a security audit on Pulso and submit a professional report. Thanks to them our platform is more secure.”
Ivan Stoilov
Team Pulso
08
“GreySurface responsibly reported a security issue to PropReady, communicated it clearly, and helped us validate the fix.”
PropReady Team
PropReady
09
“The findings were well-structured, clearly written and easy to reproduce and verify.”
Public security acknowledgement
10
“Your report demonstrated a high level of professionalism and ethical conduct. Your actions directly assist us in our ongoing efforts to enhance our security posture.”
Responsible Disclosure Team
Crunch
11
“Nick (GreySurface) reported a security issue to us through responsible disclosure. His communication was clear and professional throughout the process. I'd recommend him to anyone handling a similar report.”
SaaS co-founder
Identity withheld by request
12
“Your write-up was thorough, professional, and clearly in good faith. The responsible disclosure approach was exactly the right way to handle this.”
Vendor reference
Identity withheld by request
13
“The reproduction steps, timestamps, CVSS scoring, and cleanup list made it genuinely easy for our team to triage and validate quickly.”
Vendor reference
Identity withheld by request
14
“I really appreciate the time, care, and clarity you put into this write-up. The clean reproductions made it easy to act on quickly.”
Vendor reference
Identity withheld by request
15
“I appreciate the care you took: registering your own accounts, pulling only enough to confirm the issue, and writing it up clearly.”
Vendor reference
Identity withheld by request
16
“Nick's report was clear, well scoped and responsibly handled. The control tests saved us time confirming scope and helped us validate the fixes.”
Kelvin
CertNow
17
“We appreciate your responsible disclosure and the professionalism you demonstrated throughout this process. Your commitment to improving security, combined with the clarity of your report, enabled our team to assess and mitigate the issue. We value the time and effort you invested in reporting the issue”
Vendor security team
Identity withheld by request
18
“Nick reported a security issue to us privately, handled the disclosure responsibly and professionally throughout, and was straightforward to deal with in resolving the matter.”
Michael Saunders
19
“Nick at GreySurface responsibly disclosed a vulnerability within our authentication flow. His initial report was clear, professional, and highly actionable, and he was highly respectful of our systems and boundaries throughout the process. I appreciate his ethical approach to security research and his help in keeping CertNudge secure.”
Craig, Founder of CertNudge
Founder
20
“GreySurface submitted a clear, well-documented responsible-disclosure report regarding a reflected input-handling issue in a public-facing form on our platform (a SaaS practice-management platform for service businesses). The report included precise reproduction steps, impact assessment, and suggested remediation, and testing was scoped responsibly to the reporter's own test account throughout. Following our fix, GreySurface independently validated the remediation and confirmed it was effective. We'd recommend GreySurface for careful, professional security research and responsible disclosure.”
Vendor security team
Identity withheld by request
21
“Roomnix ekibi bildirilen bulguyu hızlı ve yapıcı bir şekilde ele alıp düzeltmeyi kısa sürede yayına aldı.”
Baris Pektas
Roomnix
22
“Nick from GreySurface approached us unprompted, looked for a way to report responsibly before he tested anything, and worked only against dummy records he created himself. His write-up was clear and well structured, and every finding came with steps we could follow straight away, so we were able to close them quickly. Security research handled to that standard is genuinely valuable, and we are grateful for it.”
23
“Hemos recibido un informe relativo a seguridad por parte de Nick de uno de nuestros productos que ya estaban en du fase final de vida. Sinceramente el trabajo es más de lo que hubiese esperado, porque además de incluir los posibles fallos de seguridad, incorporaba información acerca del proceso para explotar la vulnerabilidad junto con ideas para solucionarla. Todo ello a un nivel de detalle más que profundo, incluyendo ejemplos de llamadas, nombres de variables, etc. Volveremos a contar con la ayuda de Nick para nuestra próxima herramienta.”
Onzane SL
24
“Yours was precise, scoped. That made this easy to take seriously.”
JD Graffam
25
“C'est exactement le niveau de rigueur qui rend un rapport actionnable rapidement.”
Grégoire
26
“Nick’s work with GreySurface was extremely helpful to Roanex. His responsible and thoughtful approach helped us identify areas where we could further strengthen our security and make the platform even more secure. He communicated everything clearly and professionally throughout the process, and I genuinely appreciate the time and effort he put into helping us improve.”
Founder
27
“GreySurface (Nick) responsibly disclosed a security finding to MyPetSitter and handled the entire process professionally from start to finish. The report was clear, well documented and responsibly disclosed, with all testing remaining within the agreed scope and limited to controlled trial accounts. Throughout the process, communication was professional, constructive and collaborative. We'd happily recommend GreySurface to organisations looking for responsible security research and vulnerability disclosure services.”
Founder
28
“Nick from GreySurface flagged several security issues to us in a clear and responsible way, laying them out with enough detail for us to fix them quickly. He was professional and easy to work with, and I would gladly recommend him.”
Founder
29
“Le rapport était clair, reproductible et directement actionnable : chaque faille était accompagnée de la cause racine localisée à l'endpoint près, des contrôles négatifs et positifs, et d'un correctif concret. Nos équipes ont pu passer à la correction sans phase d'interprétation. Les effets de bord ont été déclarés spontanément, ce qui a facilité notre analyse.”
Editeur SaaS français
Identity withheld by request
30
“GreySurface nous a signalé une vulnérabilité de sécurité sur la plateforme Kobli de manière responsable et coordonnée. Le rapport était clair, documenté et accompagné d'une preuve de concept reproductible, ce qui nous a permis de comprendre et de corriger le problème rapidement. Les échanges ont été professionnels, transparents et menés de bonne foi tout au long de la divulgation. Nous recommandons GreySurface pour le sérieux et la qualité de son travail.”
CEO & Founder
31
“KyoOS thanks GreySurface for responsibly disclosing a security issue prior to launch, and for working with us through a swift resolution.”
Founder
32
“We would like to thank Greysurface for disclosing a security vulnerability identified in 2026. The analysis was conducted with due respect for our infrastructure. The report was clear, well documented, and accompanied by relevant recommendations.”
33
“GreySurface reported a security issue responsibly and provided a clear, detailed report that helped us investigate and address the issue quickly.”
A UK salon-management platform
Identity withheld by request
34
“Bezpečnostní report od GreySurface byl velmi užitečný. Jasně strukturovaný s důrazem na to, co je skutečně důležité, takže jsme mohli rychle reagovat.”
Vojtěch Pejša
Lead Developer
35
“Nick (GreySurface) reported a column-level access control flaw in our database. The report was precise, reproducible, and included control tests that let us scope the problem in minutes rather than a day. His suggestion to extend the review to adjacent tables led us to close a second path with greater impact than the first. His testing stayed on accounts he created himself and touched no customer data, which our own audit confirmed. We were not in a position to pay for the work and he accepted that without argument. For a small team, this is the kind of report you want to receive.”
Founder
References can be confirmed directly where the vendor has offered to do so.
Discuss a reviewMethod
Small proof, clear impact and enough technical detail for an engineer to reproduce the issue without guesswork.
01
I establish access using an account or trial environment I control.
02
I use the minimum read-only proof needed to establish whether a security boundary has failed.
03
I do not bulk enumerate records or test state-changing actions against data outside my account.
04
I contact the vendor directly with an impact summary, reproducible evidence, and remediation context.
05
I remain available to clarify the report and validate the fix.
Vendors receive the report, evidence and remediation support regardless of whether they choose to recognise the research with a discretionary contribution.
Read the disclosure principlesFor security and engineering teams
Verify the sender, understand the testing boundary and see the safest next steps for routing and remediation.
For SaaS product teams
Commission a focused review of tenant isolation, authorisation, authentication or API access control with a written scope and practical report.