Skip to content

Independent application security · United Kingdom

Independent security research for multi-tenant SaaS.

GreySurface finds and explains the authentication, authorisation, API and tenant-isolation failures that let one user reach what belongs to another.

Self-controlled accounts

Minimum necessary proof

No payment condition

Remediation support

Published acknowledgements

  • My Sport Manager
  • SecTrak
  • itinovo CRM
  • Coassemble
  • WorkZen
  • SimplyInspect
  • Pulso
  • PropReady
  • Skribble
  • Crunch
  • CertNow
  • StockCraft
  • CertNudge
  • APPOSIA TEKNOLOJİ A.Ş.
  • Xota
  • Onzane SL
  • Simple Focus
  • DéclarPro
  • Roanex
  • MyPetSitter Ltd
  • Axiospec
  • Kobli
  • KyoOS
  • Book'Adventure
  • Redbit s.r.o.
  • Uptera

Commissioned security

The boundary is the product. I test whether it holds.

Focused, authorised reviews for teams that need a careful look at who can read, change or administer what inside a SaaS product—without turning the engagement into a broad compliance exercise.

Best suited to product and engineering teams shipping B2B software with roles, workspaces, organisations, APIs or customer-separated data.

01

Tenant isolation

I test whether an authenticated user can cross the boundary between separate customer accounts.

02

Object-level authorisation

I check whether access decisions are applied to the individual record requested, not only to the route or session.

03

Authentication and account lifecycle

I review registration, activation, invitation, session, recovery, and account-state boundaries.

04

API access control

I compare intended product permissions with the behaviour of authenticated API endpoints.

References

Useful findings. Clear reports. Professional handling.

Feedback from vendors after private disclosure, remediation support or fix validation. Every attributed quote is used with permission; identities stay private where requested.

35

published vendor references and acknowledgements

01 / FEATURED

“I would like to acknowledge the professional and responsible manner in which Nick from GreySurface handled the security disclosure for My Sport Manager. The report was well-structured, thorough, and clearly documented with easy-to-reproduce findings, enabling us to secure our infrastructure promptly. We appreciate the value provided by such responsible security research.”

Ciarán Doyle

Lead Developer · My Sport Manager / OF Software

02 / FEATURED

“Nick (GreySurface) reported a security issue in SecTrak to us through responsible disclosure. The report was clear, well-scoped and reproducible, with testing limited to trial tenants he created himself. The issue he identified was genuinely useful for our team to fix, and the way he handled the disclosure end-to-end is the standard I'd want from anyone doing this work.”

Steve Drenkovics

Director · Montalex Limited

03

“Nick from GreySurface identified and documented two real vulnerabilities in our Cognito configuration, including a silent account takeover chain. The report was technically accurate, the disclosure was handled responsibly, and the fixes were live in production the same day. If you manage a B2B product and receive a report from him, I'd recommend taking it seriously.”

Massimiliano

itinovo CRM

04

“The report was thorough, well-documented with reproduction steps, and clearly written with the intent to help. We'd have no hesitation recommending Nick.”

Dimity Tindall

Head of Operations · Coassemble

05

“Nick reported it to me professionally, providing enough information to identify and resolve the matter within a few hours. I recommend his professionalism and expertise.”

Ika Balzam

CEO · WorkZen

06

“Nick provided a professional review of our platform's security. He was thorough but respectful and provided a detailed report of his findings. We will definitely be using his services in the future.”

SimplyInspect Support

SimplyInspect

07

“GreySurface was very kind to perform a security audit on Pulso and submit a professional report. Thanks to them our platform is more secure.”

Ivan Stoilov

Team Pulso

08

“GreySurface responsibly reported a security issue to PropReady, communicated it clearly, and helped us validate the fix.”

PropReady Team

PropReady

09

“The findings were well-structured, clearly written and easy to reproduce and verify.”

Skribble

Public security acknowledgement

10

“Your report demonstrated a high level of professionalism and ethical conduct. Your actions directly assist us in our ongoing efforts to enhance our security posture.”

Responsible Disclosure Team

Crunch

11

“Nick (GreySurface) reported a security issue to us through responsible disclosure. His communication was clear and professional throughout the process. I'd recommend him to anyone handling a similar report.”

SaaS co-founder

Identity withheld by request

12

“Your write-up was thorough, professional, and clearly in good faith. The responsible disclosure approach was exactly the right way to handle this.”

Vendor reference

Identity withheld by request

13

“The reproduction steps, timestamps, CVSS scoring, and cleanup list made it genuinely easy for our team to triage and validate quickly.”

Vendor reference

Identity withheld by request

14

“I really appreciate the time, care, and clarity you put into this write-up. The clean reproductions made it easy to act on quickly.”

Vendor reference

Identity withheld by request

15

“I appreciate the care you took: registering your own accounts, pulling only enough to confirm the issue, and writing it up clearly.”

Vendor reference

Identity withheld by request

16

“Nick's report was clear, well scoped and responsibly handled. The control tests saved us time confirming scope and helped us validate the fixes.”

Kelvin

CertNow

17

“We appreciate your responsible disclosure and the professionalism you demonstrated throughout this process. Your commitment to improving security, combined with the clarity of your report, enabled our team to assess and mitigate the issue. We value the time and effort you invested in reporting the issue”

Vendor security team

Identity withheld by request

18

“Nick reported a security issue to us privately, handled the disclosure responsibly and professionally throughout, and was straightforward to deal with in resolving the matter.”

Michael Saunders

19

“Nick at GreySurface responsibly disclosed a vulnerability within our authentication flow. His initial report was clear, professional, and highly actionable, and he was highly respectful of our systems and boundaries throughout the process. I appreciate his ethical approach to security research and his help in keeping CertNudge secure.”

Craig, Founder of CertNudge

Founder

20

“GreySurface submitted a clear, well-documented responsible-disclosure report regarding a reflected input-handling issue in a public-facing form on our platform (a SaaS practice-management platform for service businesses). The report included precise reproduction steps, impact assessment, and suggested remediation, and testing was scoped responsibly to the reporter's own test account throughout. Following our fix, GreySurface independently validated the remediation and confirmed it was effective. We'd recommend GreySurface for careful, professional security research and responsible disclosure.”

Vendor security team

Identity withheld by request

21

“Roomnix ekibi bildirilen bulguyu hızlı ve yapıcı bir şekilde ele alıp düzeltmeyi kısa sürede yayına aldı.”

Baris Pektas

Roomnix

22

“Nick from GreySurface approached us unprompted, looked for a way to report responsibly before he tested anything, and worked only against dummy records he created himself. His write-up was clear and well structured, and every finding came with steps we could follow straight away, so we were able to close them quickly. Security research handled to that standard is genuinely valuable, and we are grateful for it.”

John Geater

23

“Hemos recibido un informe relativo a seguridad por parte de Nick de uno de nuestros productos que ya estaban en du fase final de vida. Sinceramente el trabajo es más de lo que hubiese esperado, porque además de incluir los posibles fallos de seguridad, incorporaba información acerca del proceso para explotar la vulnerabilidad junto con ideas para solucionarla. Todo ello a un nivel de detalle más que profundo, incluyendo ejemplos de llamadas, nombres de variables, etc. Volveremos a contar con la ayuda de Nick para nuestra próxima herramienta.”

Onzane SL

24

“Yours was precise, scoped. That made this easy to take seriously.”

JD Graffam

25

“C'est exactement le niveau de rigueur qui rend un rapport actionnable rapidement.”

Grégoire

26

“Nick’s work with GreySurface was extremely helpful to Roanex. His responsible and thoughtful approach helped us identify areas where we could further strengthen our security and make the platform even more secure. He communicated everything clearly and professionally throughout the process, and I genuinely appreciate the time and effort he put into helping us improve.”

Brian Mercedes

Founder

27

“GreySurface (Nick) responsibly disclosed a security finding to MyPetSitter and handled the entire process professionally from start to finish. The report was clear, well documented and responsibly disclosed, with all testing remaining within the agreed scope and limited to controlled trial accounts. Throughout the process, communication was professional, constructive and collaborative. We'd happily recommend GreySurface to organisations looking for responsible security research and vulnerability disclosure services.”

Marian-Viorel Petrisor

Founder

28

“Nick from GreySurface flagged several security issues to us in a clear and responsible way, laying them out with enough detail for us to fix them quickly. He was professional and easy to work with, and I would gladly recommend him.”

Timothy Malone

Founder

29

“Le rapport était clair, reproductible et directement actionnable : chaque faille était accompagnée de la cause racine localisée à l'endpoint près, des contrôles négatifs et positifs, et d'un correctif concret. Nos équipes ont pu passer à la correction sans phase d'interprétation. Les effets de bord ont été déclarés spontanément, ce qui a facilité notre analyse.”

Editeur SaaS français

Identity withheld by request

30

“GreySurface nous a signalé une vulnérabilité de sécurité sur la plateforme Kobli de manière responsable et coordonnée. Le rapport était clair, documenté et accompagné d'une preuve de concept reproductible, ce qui nous a permis de comprendre et de corriger le problème rapidement. Les échanges ont été professionnels, transparents et menés de bonne foi tout au long de la divulgation. Nous recommandons GreySurface pour le sérieux et la qualité de son travail.”

Raphael Mortier

CEO & Founder

31

“KyoOS thanks GreySurface for responsibly disclosing a security issue prior to launch, and for working with us through a swift resolution.”

Nate Browns

Founder

32

“We would like to thank Greysurface for disclosing a security vulnerability identified in 2026. The analysis was conducted with due respect for our infrastructure. The report was clear, well documented, and accompanied by relevant recommendations.”

Co-founder of Book’Adventure

33

“GreySurface reported a security issue responsibly and provided a clear, detailed report that helped us investigate and address the issue quickly.”

A UK salon-management platform

Identity withheld by request

34

“Bezpečnostní report od GreySurface byl velmi užitečný. Jasně strukturovaný s důrazem na to, co je skutečně důležité, takže jsme mohli rychle reagovat.”

Vojtěch Pejša

Lead Developer

35

“Nick (GreySurface) reported a column-level access control flaw in our database. The report was precise, reproducible, and included control tests that let us scope the problem in minutes rather than a day. His suggestion to extend the review to adjacent tables led us to close a second path with greater impact than the first. His testing stayed on accounts he created himself and touched no customer data, which our own audit confirmed. We were not in a position to pay for the work and he accepted that without argument. For a small team, this is the kind of report you want to receive.”

Maxime Folio

Founder

References can be confirmed directly where the vendor has offered to do so.

Discuss a review

Method

A disciplined path from access to evidence.

Small proof, clear impact and enough technical detail for an engineer to reproduce the issue without guesswork.

01

Create

I establish access using an account or trial environment I control.

02

Confirm

I use the minimum read-only proof needed to establish whether a security boundary has failed.

03

Stop

I do not bulk enumerate records or test state-changing actions against data outside my account.

04

Report

I contact the vendor directly with an impact summary, reproducible evidence, and remediation context.

05

Support

I remain available to clarify the report and validate the fix.

Independent reports are never conditional on payment.

Vendors receive the report, evidence and remediation support regardless of whether they choose to recognise the research with a discretionary contribution.

Read the disclosure principles

For security and engineering teams

Received a GreySurface report?

Verify the sender, understand the testing boundary and see the safest next steps for routing and remediation.

For SaaS product teams

Need the boundary checked before someone else finds it?

Commission a focused review of tenant isolation, authorisation, authentication or API access control with a written scope and practical report.