SaaS security & compliance
Your product passed the demo. Now it has to pass security review.
Enterprise deals now stall in the security review, not the product evaluation. The buyer wants an attestation you may not have yet, a questionnaire answered with evidence, and — since a year of breaches through connected apps — to know exactly which of your integrations can reach their data. This page is about getting through that review honestly: what to build first, what regulated buyers are required to ask you, and what can be ready in ninety days.
Reviewed 24 September 2026 · 15 sources cited
The short answer
SaaS security compliance is what gets you through an enterprise buyer’s security review. North American technology buyers usually ask for a SOC 2 Type II report; European, Indian and regulated buyers usually ask for ISO 27001. Indian banks, NBFCs and SEBI-regulated firms add their own requirements on audits and hosting. Before either attestation, get deal-ready: an independent penetration test with a retest, a clear security overview, evidence-backed questionnaire answers, and a tight inventory of every connected-app token.
Why SaaS
Buyers are not auditing your code. They are auditing your access to theirs.
A SaaS vendor is a standing connection into its customers: an API they call, a login they federate, a data store holding their records, and often an OAuth token that lets your product read their CRM, their mailboxes or their cloud data. Verizon’s 2026 Data Breach Investigations Report found that 48% of breaches involved a third party, up 60% in a year — and that only 23% of the third-party organisations it looked at had fully fixed missing or weak multi-factor login on their cloud accounts.
The past year made that concrete. In August 2025, attackers used OAuth tokens stolen from Salesloft’s Drift chat app to pull data out of Salesforce instances belonging to the app’s customers, and went hunting in that data for AWS access keys, passwords and Snowflake tokens. In November, Salesforce revoked tokens after unauthorised access through Gainsight-published connected apps. In April 2026, Vercel traced an intrusion to Context.ai, an AI tool one of its employees used, whose Google Workspace access became the way in; the same month, stolen tokens at the analytics vendor Anodot left more than a dozen companies facing extortion. In June, Salesforce disabled the Klue app after an attacker used a legacy integration credential to take the tokens connecting Klue to its customers.
None of these vendors was breached through its core product. Each was breached through the trust its customers had delegated to it — and every enterprise security team now asks about that trust first. Which apps hold tokens into our environment? What can each token do? Where are they stored, and how fast can you revoke them?
Behind the buyer’s questions sit the buyer’s regulators. An Indian bank or NBFC must audit its service providers and their sub-contractors; a SEBI-regulated firm may only use SaaS built on MeitY-empanelled, STQC-audited infrastructure; a European bank must write DORA’s audit and testing rights into your contract. The rest of this page takes those in the order a deal meets them.
Evidence
What the data says about vendor risk
From Verizon’s 2026 breach report and IBM’s 2026 India study. Each figure is linked in the sources.
IBM’s India figures cover organisations of every size. The same study found offensive security testing — penetration testing and red teaming — to be the single largest factor reducing the cost of a breach.
Ten months, one pattern
How attackers learned to use your integrations
Five incidents, each through a token or credential a customer had granted to a SaaS vendor. This is why buyers now ask about your integrations before your firewall.
-
Aug 2025
Salesloft Drift
Stolen OAuth tokens from the Drift app were used against customers’ Salesforce instances between at least 8 and 18 August; the attackers searched the exported data for AWS keys, passwords and Snowflake tokens. Drift Email tokens reached a small number of Google Workspace accounts too.
-
Nov 2025
Gainsight connected apps
Salesforce flagged unauthorised access through Gainsight-published connected apps and revoked their tokens — the same technique, a different vendor.
-
Apr 2026
Vercel, via Context.ai
A compromised third-party AI tool used by one Vercel employee led to that employee’s Google Workspace account, and from there into Vercel’s environment; some customers’ environment variables were exposed.
-
Apr 2026
Anodot
Authentication tokens that customers used to connect the analytics vendor to their cloud data were stolen; Snowflake cut off Anodot’s access after unusual activity, and more than a dozen companies faced extortion.
-
Jun 2026
Klue
An attacker used a compromised legacy credential for an integration service to obtain the OAuth tokens connecting Klue to Salesforce and other platforms. Salesforce disabled the Klue app.
Each case is described from the vendor’s or the affected platform’s own account, or from reporting that quotes it. Victim counts that could not be confirmed at source are deliberately left out.
Decision helper
SOC 2 or ISO 27001 first? Four questions.
The honest answer depends on who is buying from you, not on which framework is “better”. Answer for the next twelve months of pipeline, not for the company you hope to be in five years.
Answer the questions to see where we would start.
Start with SOC 2
Your buyers are mostly North American technology companies, and they ask for SOC 2 by name. Begin with a readiness assessment and a Type I, then run the Type II observation period. A licensed CPA firm issues the report — not us, and not any consultancy.
How SOC 2 readiness worksStart with ISO 27001
Your buyers are in Europe, India or the Middle East, or you sell into tenders and regulated sectors. ISO 27001 certification comes from an accredited certification body; we build the management system and prepare you for Stage 1 and Stage 2.
How ISO 27001 readiness worksPlan for both — on one control set
Build one set of controls and map it to both frameworks; most of the work overlaps. Do first whichever your largest current buyers ask for by name, and let the second reuse the evidence.
One control set, several frameworksNeither yet — get deal-ready first
An attestation certifies controls that have been running for a while. Until yours have, a scoped penetration test with a retest, a short security overview and honest questionnaire answers will close more first deals than a promise of SOC 2 next year.
A first penetration testBy buyer
What each kind of buyer will require of you — and why
The questionnaire is the visible part. Behind it, many buyers are carrying out obligations their own regulator placed on them, which is why some requirements are not negotiable.
| Buyer | What they will ask for | Where it comes from |
|---|---|---|
| US technology company | A SOC 2 Type II report, a recent penetration test, a completed questionnaire such as SIG or CAIQ | Their own vendor-risk programme and their customers’ expectations |
| European enterprise | ISO 27001, a GDPR data-processing agreement with standard contractual clauses for transfers to India, and increasingly NIS2 supply-chain clauses | GDPR, and NIS2 for firms in its sectors |
| EU bank, insurer or investment firm | Contract terms giving them, their auditors and their regulator unrestricted audit rights, and your participation in their threat-led penetration tests | DORA Article 30 — see our IT services page for the detail |
| Indian bank or NBFC | Audit rights over you and your sub-contractors, access to data and logs, and evidence of your controls | RBI’s 2025 “Managing Risks in Outsourcing” Directions, which replaced the 2023 IT-outsourcing directions |
| SEBI-regulated entity | Proof that your SaaS runs on a MeitY-empanelled cloud with its data in MeitY-empanelled, STQC-audited data centres in India, back-to-back terms with your sub-contractors, and tenant isolation | SEBI’s 2023 cloud framework, carried into the Cybersecurity and Cyber Resilience Framework (CSCRF) as Annexure J |
| Any Indian enterprise under the DPDP Act | A contract that binds you to reasonable security safeguards, a year of logs and breach notice to them — so they can meet their own 72-hour duty | DPDP Rules, 2025, Rules 6 and 7 — the customer is the Data Fiduciary, you are its Data Processor |
| Buyer of AI features | An account of the models you use, the data they see and how outputs are governed — now part of SIG 2026, which maps to ISO 42001 | Buyer questionnaires today; the EU AI Act’s high-risk obligations from December 2027 |
General information, not legal advice. Where a requirement turns on how a regulator reads its own rules — SEBI’s hosting conditions for a particular SaaS architecture, for example — ask the customer’s compliance team what they will accept before you build for it.
Next step
Bring the deal that is stuck, not a wish list.
A 30-minute call with a practitioner who has sat on both sides of a vendor security review. No charge, and no obligation.
- What this buyer actually needs, as opposed to what their questionnaire lists
- Whether SOC 2 or ISO 27001 should come first for your pipeline
- A test scope built around the tenant separation and integrations buyers now ask about
- A written scope and a fixed price, with a retest of every fix included
Deal-ready in 90 days
What can honestly be ready in ninety days
Everything here is something a buyer can check. The attestation clock can start in parallel; it cannot be skipped.
-
Days 1–30
Know your own estate
- Inventory every connected app and OAuth token your product holds into customers’ systems — and every one your own staff have granted into yours
- Cut token scopes to what each integration needs, and write down how a token is revoked within an hour
- Multi-factor login on every admin, cloud and code-host account, enforced rather than suggested
- Logs switched on and kept for 180 days in India, as the CERT-In Directions require; a year for personal-data processing, as the DPDP Rules expect
-
Days 31–60
Test what buyers ask about
- An independent penetration test of the product and its APIs, logged in as two tenants to prove neither can see the other’s data
- Integration paths in scope: token handling, webhook verification, secrets in support tooling
- Fixes, then a retest — and a shareable proof of testing that does not hand over the report
- A two-page security overview a buyer can read in five minutes
-
Days 61–90
Package the evidence
- A library of approved questionnaire answers, each tied to dated evidence that expires
- Contract templates: a data-processing agreement and security schedule you can offer before being asked
- A public trust page answering the common questions before they are asked
- The SOC 2 or ISO 27001 plan chosen, with the observation period or Stage 1 scheduled
-
After day 90
Keep it true
- Retest after major releases, not once a year
- Review connected-app tokens quarterly and revoke the unused
- Let answers retire when their evidence expires, instead of reusing last year’s
- Run the attestation — the controls now have a history to show
Since 2025
Six questions buyers now ask about your integrations
Have the answers ready before the review starts. Each one traces back to one of the connected-app breaches above.
Which of your apps hold tokens into our environment, and what can each one do?
Buyers want a list, with scopes. “Read all objects” where “read contacts” would do is the first thing a reviewer will flag.
Where are those tokens stored, and who in your company can reach them?
The Klue intrusion began with a legacy credential for an integration service. Tokens belong in a secrets store, reachable by the service that uses them and nobody else.
How quickly can you revoke every token you hold for us?
In the Gainsight and Klue cases, the platform revoked or disabled the app. Be able to do it yourself, per customer, in minutes — and have practised it.
Do support cases or chat transcripts ever contain our secrets?
The attackers behind the Drift intrusion searched stolen Salesforce data for AWS keys and passwords. Scan what you store for credentials and purge them.
Which third-party tools can your own staff connect to their work accounts?
Vercel was reached through an AI tool an employee had connected to Google Workspace. Control which apps staff can authorise, especially AI tools.
What do your logs show about token use, and will you share them after an incident?
Buyers need to know what was read, when and from where. Keep token-use logs, and say in the contract how long and how you will share them.
Where SemperWise fits
What we do for SaaS companies
Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Each row says which.
“The buyer wants a recent penetration test.”
Authenticated testing of the product, its APIs and its integrations, logged in as more than one tenant. Every finding is confirmed by a person, and a retest is included.
Web application testing“Our product is mostly APIs.”
Object-level authorisation, token handling, webhook verification and tenant separation, tested endpoint by endpoint.
API security testing“We ship weekly and test yearly.”
Testing on a subscription, with findings delivered as they are confirmed and retests included, so a release that reopens a flaw is caught in weeks.
Continuous testing“US buyers want SOC 2 Type II.”
Control design against the Trust Services Criteria and the evidence trail for the observation period. A licensed CPA firm issues the report.
SOC 2 readiness“EU and Indian buyers want ISO 27001.”
We build the management system, run the internal audit and prepare you for Stage 1 and Stage 2. An accredited certification body issues the certificate.
ISO 27001 readiness“Every buyer sends a different questionnaire.”
Answer once with evidence and reuse it. Each answer retires when the evidence behind it expires, so nothing stale goes out under your name.
Questionnaire automation“Buyers want proof, not a PDF.”
An assessment certificate at a live link that shows scope and remediation status as fixes land — without publishing a finding — alongside a public trust page.
Assessment certificates“Our AI features raise new questions.”
An inventory of the AI in your product and your business, classified and owned, ready for SIG 2026 and ISO 42001 questions.
AI governance registerQuestions
SaaS Companies security — answered.
What buyers in this sector ask us before they commit to anything.
Should a SaaS company get SOC 2 or ISO 27001 first?
Whichever your buyers ask for by name. North American technology buyers usually ask for a SOC 2 Type II report; European, Indian and Middle Eastern buyers, tenders and regulated sectors usually ask for ISO 27001. If your pipeline is genuinely mixed, build one control set and map it to both, doing first the one your largest current buyers want. If your controls have not been running long enough to show a history, get deal-ready first — the decision helper on this page walks through it.
Can SemperWise make us SOC 2 certified?
No — and nobody else can either, because SOC 2 is not a certification. It is an attestation report in which a licensed CPA firm gives its opinion on your controls, over a point in time (Type I) or over an observation period (Type II). What we do is the readiness work: control design against the Trust Services Criteria, the evidence trail, the penetration testing behind the technical controls and support through the audit. The same applies to ISO 27001, which only an accredited certification body can certify. A provider offering to both build and certify is offering something informed buyers will not accept.
Are we a Data Processor under the DPDP Act?
Usually, for your customers’ data. If you process personal data on behalf of an Indian customer that decides why and how it is processed, the customer is the Data Fiduciary and you are its Data Processor. Section 8 of the Act makes the fiduciary responsible for what you do, and the DPDP Rules, 2025 expect its contract with you to bind you to reasonable security safeguards and to keep logs for a year — so expect those clauses in renewals now, ahead of the main duties in May 2027. For your own users, marketing lists and employees, you are the fiduciary. See DPDP Act compliance.
Can we sell to SEBI-regulated firms if our SaaS is on AWS or Azure?
Possibly, but check the specifics with the customer. SEBI’s 2023 framework for cloud adoption, now carried into its CSCRF as Annexure J, says regulated entities may use cloud services only from MeitY-empanelled providers, and that SaaS must be built on a MeitY-empanelled provider’s infrastructure with the regulated entity’s data hosted and processed only in MeitY-empanelled, STQC-audited data centres in India. Check whether your cloud provider holds that empanelment for the region you run in, and ask the customer’s compliance team early what evidence it accepts — before you architect for it.
What do Indian banks and NBFCs require from SaaS vendors?
The RBI replaced its 2023 IT-outsourcing directions on 28 November 2025 with entity-wise “Managing Risks in Outsourcing” Directions. In the NBFC version, “service provider” includes sub-contractors, and the NBFC must audit its providers on a risk basis — it may rely on pooled audits or recognised third-party certifications, but its own responsibility is undiluted. In practice, expect audit and inspection rights over you and your sub-contractors, access to data and logs, and incident notice terms. Our RBI framework page covers what the bank itself must do.
How long does SOC 2 take?
A Type I report assesses control design at a point in time and can follow a readiness phase of a few months. A Type II report covers controls operating over an observation period, commonly several months for a first report, so the elapsed time is readiness plus the observation period plus the auditor’s reporting. That is why “SOC 2 in thirty days” offers usually mean a Type I at best. You can be deal-ready — tested, documented and answering questionnaires with evidence — long before the report arrives, and many first buyers will accept that with a dated plan.
How do we answer security questionnaires faster without overstating anything?
Answer once, with evidence, and reuse. Most questionnaires ask the same things in different words, so a library of approved answers — each linked to the evidence behind it, with a date — turns a week of engineering time into an afternoon of review. The discipline that matters is expiry: an answer citing last year’s penetration test must not go out after this year’s. A public trust page answers common questions before they are asked. Questionnaire automation in SemperWise One works this way.
Does the EU AI Act apply to an Indian SaaS company?
It can, if your product puts an AI system on the EU market or its outputs are used in the EU. The obligations depend on the system’s risk class. The 2026 amendments pushed the high-risk obligations for Annex III uses — such as employment and education — to 2 December 2027. Before any of that, buyers are already asking: the 2026 edition of the SIG questionnaire maps to ISO 42001 and asks about AI governance directly. An inventory of the AI you use and ship, with owners and risk classes, answers most of those questions. Take the legal classification of a specific feature to counsel.
Sources
Checked by our research desk on 24 September 2026. Regulations and figures move; where a number here matters to a decision, follow it to the source.
- Widespread data theft targets Salesforce instances via Salesloft Drift — Google Threat Intelligence Group, August 2025
- Salesforce flags unauthorized data access via Gainsight-linked OAuth activity — The Hacker News, November 2025
- Vercel April 2026 security incident — Vercel, April 2026
- Hack at Anodot leaves over a dozen breached companies facing extortion — TechCrunch, 13 April 2026
- Salesforce disables Klue app after unauthorized activity — The Hacker News, June 2026
- Framework for Adoption of Cloud Services by SEBI Regulated Entities — SEBI, 6 March 2023
- Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities — SEBI, 20 August 2024
- IT outsourcing under the RBI’s 2025 Directions: what has changed — Vinod Kothari Consultants, February 2026
- Digital Personal Data Protection Act, 2023 — MeitY
- Digital Personal Data Protection Rules, 2025 (Rules 6, 7 and 8) — MeitY, 13 November 2025
- Directions under sub-section (6) of section 70B of the IT Act, 2000 — CERT-In, 28 April 2022
- EU digital omnibus on AI enters into force — Hunton Andrews Kurth, 2026
- SIG 2026: key updates and considerations — Mitratech, 2026
- 2026 Data Breach Investigations Report — Verizon, 2026
- India records its highest average cost of a data breach — Cost of a Data Breach Report 2026 — IBM, 3 August 2026
Next step
Unblock the deal stuck in security review.
A 30-minute call, no charge. Bring the questionnaire, the contract clause or the buyer’s email. You leave knowing what they actually need, what you can show this month, and whether SOC 2 or ISO 27001 should come first.