Decipher
Book a Call Get Started
Home / Security / Security for SaaS
Industry: B2B SaaS Selling into US, EU & APAC

Cyber security for Indian B2B SaaS selling into global enterprises

SOC 2 Type II ready inside 6-9 months. ISO 27001 in parallel with the same policy library. VAPT reports in the format US and EU procurement accepts. Cloud posture on AWS, GCP and Azure. Secrets rotation, tenant isolation review, SSO hardening. Built for teams whose next enterprise deal depends on passing a 400-question security questionnaire.

6-9 mo
SOC 2 Type II end-to-end
90+
VAPT engagements shipped
6+
Own SaaS products live
4
Compliance regimes in parallel
Threat Surface for SaaS

Attack shapes SaaS security teams have to plan against

Supply chain and dependency compromise. npm and PyPI packages get hijacked. Container base images ship with known CVEs. A single upstream compromise (think event-stream, ua-parser-js, xz-utils) puts a foreign runtime inside your production. Enterprise buyers ask for SBOM these days, not because they enjoy it, but because they have been burned. You need dependency scanning on every deploy, base image pinning, and a queue that actually gets triaged rather than growing forever.

Tenant isolation failures. The classic SaaS breach shape. IDOR on tenant IDs, missing tenant context in a background job, cache key collisions between tenants, a database query that forgot the WHERE tenant_id clause. Every SOC 2 auditor and every serious enterprise pen test looks for this pattern first because it is where the biggest breaches happen. Testing has to be done with two accounts, not one, and by someone who has seen the pattern before.

SSO and auth flow abuse. SAML signature wrapping, OAuth redirect abuse, JWT alg confusion, missing state parameter on OAuth flows, sub claim mismatches. Every SaaS eventually needs enterprise SSO (Okta, Azure AD, Google Workspace). The auth flows added in a rush to unblock a deal are often the weakest surface in the product. We test them like an attacker, not like a compliance checkbox.

Secrets sprawl and cloud posture drift. A GitHub token committed by mistake, an S3 bucket flipped public during a debug session, an IAM role over-permissioned to unblock a deploy at 2am and never tightened. These are the boring failures that end up on the front page of TechCrunch. Continuous secrets scanning, CSPM (AWS Security Hub, GCP SCC, Azure Defender), and a quarterly IAM review are the baseline for any SaaS above 20 engineers.

Why SaaS founders pick us

We ship SaaS ourselves. We know the deal-unblock pressure.

Dcomply, Fluxeta, VakeelSaathi, RealZent, SignupDesk, Dpublish. Every one of them has been through the security questionnaire treadmill for at least one enterprise buyer. The controls, evidence pipeline, and pen test cadence we roll out for you is the same one we run on our own products. We know what actually matters to a US Fortune 500 procurement team versus what looks nice on a policy PDF.

See full security service
What We Do

Six security engagements for B2B SaaS

SOC 2 Type II Readiness

Gap assessment against Trust Services Criteria, policy library, control implementation, evidence automation with Vanta / Drata / Secureframe, auditor introduction, observation period support, fieldwork prep. Type I option if the sales deadline is tight.

6-9 months end-to-end

ISO 27001 Certification

Statement of Applicability, risk register, policy library shared with the SOC 2 track, internal audit cycle, stage-1 and stage-2 audit prep with a UKAS-accredited cert body of your choice. Post-cert surveillance audit cadence baked in.

Runs parallel with SOC 2

Product + API VAPT

Named-tester engagement on web app, API, tenant isolation, SSO flows. Two-account testing for IDOR and tenant leakage. Report format US and EU procurement accepts. Critical findings flagged same-day for hot fixes.

Deal-unblock ready

Cloud Posture (CSPM)

AWS Security Hub, GCP SCC, Azure Defender for Cloud setup and rule tuning. IAM review with least-privilege refactor. S3 / GCS / blob public-access audit. GuardDuty and Cloud Trail wired into your SIEM. Dashboard evidence buyers accept.

CSPM dashboard for buyers

Secrets Management & Rotation

HashiCorp Vault or AWS Secrets Manager rollout. Automated rotation for database credentials, API keys, service accounts. GitHub secret scanning wired to CI. Historical audit of committed secrets. 1Password Business for team credentials.

Rotation on schedule

DPDP + GDPR Alignment

DPA templates, sub-processor register, Article 32 technical measures documented, DPIA where needed, SCCs for cross-border transfer, DPO advisory. Storage residency options in EU regions. DPDP delta filled alongside GDPR.

India + EU + US ready

Enterprise deal blocked on a security questionnaire?

15-min call. Tell us the buyer's ask, the deadline, the current state. Fixed-price plan back in 48 hours. SOC 2 Type I option if the deal cannot wait for Type II.

Book Free 15-min Call
Tech Stack We Use

Tools SaaS security teams already recognise

If your team already runs Vanta, Drata, or Secureframe for evidence collection, we plug in. No parallel tooling for you to babysit.

Compliance Automation

Vanta Drata Secureframe Sprinto

VAPT Toolchain

Burp Suite Pro Nessus Pro Nuclei Semgrep (SAST)

Cloud Posture (CSPM)

AWS Security Hub GCP SCC Azure Defender for Cloud Wiz / Prisma Cloud

Runtime & SIEM

Wazuh Falco (container runtime) Sysdig Secure Microsoft Sentinel

Secrets & Identity

HashiCorp Vault AWS Secrets Manager 1Password Business Okta / Azure AD

Endpoint & EDR

CrowdStrike Falcon SentinelOne Jamf (Mac fleet)
Compliance We Prep You For

Regimes global SaaS buyers ask about

SOC 2 Type II

TSC mapping, controls, observation period, auditor coordination. US enterprise baseline.

ISO 27001

SoA, risk register, stage-1 and stage-2 audit prep, surveillance cycle. EU baseline.

DPDP Act 2023

Consent, purpose limitation, 72-hour breach notification, DPO advisory.

GDPR (EU)

DPA, SCCs, Article 32 measures, DPIA, EU region storage where required.

HIPAA (healthtech SaaS)

BAA templates, PHI encryption, HHS OCR breach workflow where applicable.

CCPA (California)

DSR workflow, opt-out signals, sub-processor list. Overlaps with DPDP + GDPR.

PCI-DSS (payment SaaS)

Where you touch card data, scope reduction and annual pen test.

CERT-In Directions

6-hour reporting, 180-day log retention. Applies to any India-run SaaS.

Pricing

Fixed-scope engagements, fixed prices

Engagement
Product + API VAPT

Web app, API, tenant isolation, SSO. Two-account IDOR tests. Report format enterprise buyers accept.

Rs. 1.5-4 L
Sprint
SOC 2 Type II Readiness

Readiness + observation window + auditor coordination. Auditor fee separate. Type I option for tight deadlines.

Rs. 5-8 L
Sprint
ISO 27001 Certification

SoA, policies, risk register, internal audit, stage-1 and stage-2 prep. Cert body fee separate.

Rs. 4-7 L
Ongoing
Cloud Posture + Managed

CSPM tuning, secrets rotation, IAM review, dependency queue, quarterly pen test cadence.

Rs. 80k-2.5 L/mo
FAQ

Questions SaaS CTOs ask on every call

6 to 9 months end to end for most Indian SaaS teams. Readiness work (gap assessment, policy library, control implementation, evidence automation) is 8 to 12 weeks. Observation period is a minimum of 3 months, most teams pick 6. Auditor fieldwork is 3 to 5 weeks. If you have a hard sales deadline, we start with SOC 2 Type I (point-in-time attestation) which can ship in about 10 weeks, then convert to Type II at the end of the observation period.

Depends on where the buyer is. US enterprise buyers ask for SOC 2 first, ISO 27001 second. EU buyers ask for ISO 27001 first, SOC 2 second. If you sell globally, the controls overlap 70 to 80 percent so doing both is not double the work. We usually run them in parallel with a single policy library and shared evidence pool. That way the SOC 2 auditor and the ISO 27001 stage-2 audit reuse the same artefacts.

Named-tester engagement, CVSS 3.1 scoring, PoC screenshots, remediation retest included, report signed on Decipher letterhead. The report format is what US and EU procurement teams accept in security questionnaires. We cover the web app, API, tenant isolation, SSO flows and any customer-facing integration surface. Turnaround is typically 2 to 3 weeks depending on scope. Critical findings get a same-day heads-up so your team can start fixing before the report lands.

Data Processing Agreement templates, sub-processor management, DPA schedule with the customer, Article 32 technical measures documented, DPIA where the processing warrants it, DPO advisory. Storage residency options in EU regions (Frankfurt, Dublin, Stockholm) for customers who require it. Cross-border transfer mechanism (Standard Contractual Clauses since Schrems II) documented. We do the DPDP + GDPR delta together so the compliance work compounds rather than duplicating.

It is the health check on your AWS / GCP / Azure account. Public S3 buckets, over-permissive IAM roles, security groups open to 0.0.0.0/0, unused access keys, MFA not enforced on the root account, missing GuardDuty. Enterprise security questionnaires now ask specifically about CSPM (Cloud Security Posture Management). We set up AWS Security Hub, GCP SCC or Azure Defender for Cloud, tune the rules for your architecture, and give you a dashboard the buyer's security team accepts as evidence.

Baseline is annual for compliance (SOC 2, ISO 27001, PCI-DSS all require it). Practical cadence is quarterly if you ship major features frequently, or on trigger (new payment integration, major auth change, new customer-facing surface). Between full tests, we run continuous vulnerability scanning on the API surface and dependency SBOM checks on every deploy. That way findings show up early rather than in the annual audit.

Product + API VAPT: Rs. 1.5 to 4 lakh depending on surface. SOC 2 Type II readiness sprint (readiness + observation + auditor coordination): Rs. 5 to 8 lakh, plus the auditor fee separately (usually USD 15-30k). ISO 27001 certification sprint: Rs. 4 to 7 lakh, plus cert body fee. Ongoing cloud posture + managed security retainer: Rs. 80,000 to 2.5 lakh per month. Fixed-price scoping in 48 hours.
Explore More

Related services

Unblock the enterprise deal, not the questionnaire

15-min call. Tell us the buyer's ask, the deadline, the current state. Fixed-price plan back in 48 hours. Type I fast-track option available.

Decipher Assistant
Typically replies instantly