Independent security & stability audit
for pre-PMF SaaS.
An independent forensic review of your SaaS — security, stability, and 152-ФЗ compliance — done in two or four weeks. Latest audit: 9 P0 + 19 P1 found in 12 days, including a live JWT impersonation bypass.
10+ years building product at Ozon · Avito · Yandex
What we audit.
Three layers. Each one matters separately. Together they tell you whether your SaaS can survive scale.
Security
OWASP Top 10, auth flows, multi-tenant isolation, IDOR, JWT, secrets, webhooks. Runtime exploitation against a staging or production endpoint, with your permission.
Stability
Production log forensics, database pool config, error budgets, idle-session timeouts, P0 fatal patterns. Why your server “just falls over” — found in the logs, not guessed.
152-ФЗ compliance
Data flow mapping, consent logs, DPA gaps with cloud vendors (Yandex Cloud OCR, OpenAI, etc.), Roskomnadzor readiness. Compliance as code, not paperwork.
Two audit tiers. One retainer.
Fixed price, fixed scope. No RFP, no procurement theatre. Pick a tier, sign, start within a week.
Code review + production log analysis + OWASP Top 10 sweep + 152-ФЗ status. Top P0/P1 findings with fix recommendations.
Best for: pre-PMF SaaS, 5–50 usersExpress + runtime exploitation tests + live demos of every P0 + 152-ФЗ deep dive + cloud DPA review + full-team walkthrough session.
Best for: SaaS with paying usersMonthly audit sweep + every-PR review on security-sensitive changes + 152-ФЗ ongoing advisory + design+engineering supervision.
Best for: SaaS scaling its teamNot for: bug-bounty replacement · ФСТЭК certification (need licence) · marketing “security badge” engagements
A recent audit, redacted.
From a 12-day engagement with a Russian document-management SaaS, May 2026. Names removed, findings preserved.
+ 18 positive findings
[CRITICAL] Full multi-tenant bypass via JWT impersonation. Any authenticated user can become ADMIN of any other company on the platform with 3 lines of JavaScript in the browser console. Verified end-to-end.
[CRITICAL] Webhook signature verification fails open in production. 60 fail-open warnings + 57 unauthenticated callbacks in the past 12 days of production logs.
[CRITICAL] PostgreSQL connection instability — 1320 FATAL `terminating connection due to idle-session timeout` errors in 12 days. 6.7% of all log lines. Root cause: Prisma connection pool not configured for keepalive against Timeweb Postgres.
— 6 more P0 findings, 19 P1 findings, full fix plan, and a Sprint 1 roadmap delivered in the final report. Client gave permission to share this summary, anonymized.
Audit your own SaaS first.
A free 32-point checklist combining OWASP Top 10, 152-ФЗ readiness, and production stability. Read it now or send the link to your inbox.
No newsletter. No drip funnel. One email with the checklist link, then we leave you alone.
Questions we get.
Do you need access to our production database?
Ideally read-only access, yes. If that’s a blocker, a sanitized SQL dump works for most checks. We sign an NDA either way and we run our own PII sanitizer (Anonymous) over any logs you send before they touch any cloud tool.
Will you exploit findings on production?
Only with explicit written permission and with you watching. Default mode is static + low-impact runtime probes. The JWT bypass demo from the example above was run on a staging copy first, then reproduced on production with the client’s engineering lead in the room.
What about the deliverable?
A markdown report with severity-tagged findings (P0 / P1 / P2 / P3), reproduction steps, fix recommendations, and a Sprint 1 roadmap. Plus a 60-minute walkthrough call with your team. No 80-page Word documents.
Who actually runs the audit?
The audit is run by Egor Sazanov, founder. One accountable name, one signature on the report. The lab is small by design — security buyers get a single human to escalate to, not a rotating bench.
Do you have an ФСТЭК licence?
No — and that’s on purpose. If you need a licenced auditor for state contracts or Roskomnadzor inspection prep, talk to RTM Group, Бастион, or Digital Security. Our engagement is technical and practical, not certificatory.
How fast can you start?
Typical lead time is 1–2 weeks from signature to kick-off. Express Audit fits a 2-week sprint, Full Audit a 4-week one. We confirm the exact start date before signing.
Ready to look?
One email. We talk for 30 minutes, we tell you which tier fits, you decide. No pitch deck.