Security Research & Resources
Practical security reports, technical guides, testing methodologies, and downloadable resources designed to help SaaS companies understand modern application security.
Covers API security, access control and IDOR/BOLA testing, authorization and tenant isolation, AI security, and general SaaS security, updated as new reports, checklists, and guides are published.
Featured Resource
Sample SaaS Penetration Test Report
Review a sanitized example of THF reporting, including executive summary, technical evidence, business impact, remediation guidance, and retesting criteria.
View ReportExplore Resource Categories
Sample Reports
Professional examples of security assessment deliverables.
3 AvailableSecurity Checklists
Practical review checklists for engineering and security teams.
4 Available • 0 Coming SoonTechnical Guides
Long-form guidance on modern application security.
Guides: 3 Available • 0 Coming SoonAPI Security
Resources focused on REST, GraphQL, authorization, and data exposure.
3 ResourcesAccess Control
Authorization, IDOR, BOLA, RBAC, and tenant isolation resources.
2 ResourcesAI Security
Guidance for AI-enabled SaaS workflows, tools, agents, and data access.
2 ResourcesSaaS Security
Research and resources focused on SaaS platforms and product security.
4 ResourcesWhich Resource to Use
Sample reports
Sanitized examples of the report an engagement produces. Read one before you commission a test, so you know what a useful finding contains and can compare it with what other providers deliver.
Checklists
Self review aids for engineering teams. Work through one before a release or before a test, so the obvious gaps are closed and testing time goes on the hard ones.
Guides
For the person buying or running a test: how to prepare, what happens during an assessment, and how to choose a provider.
Research articles
Longer write-ups on single vulnerability classes, such as IDOR, broken access control and business logic flaws, published on the blog.
Resource Library
New reports, checklists, and technical guides will be added regularly as part of The Hidden Finds resource library.
No matching resources yet.
Sample SaaS Penetration Test Report
Sanitized reporting example showing evidence, impact, remediation, and retesting criteria. Useful before commissioning a test, to see what each finding should contain.
Intermediate • Updated July 2026View ResourceSample AI Workflow Security Assessment Report
A sanitized AI security report covering LLM workflows, RAG authorization, prompt injection, tool execution, and cross-tenant data exposure. For teams shipping LLM features that can reach customer data or call tools.
Advanced • Updated July 2026View ResourceSample Access Control Security Assessment Report
A sanitized access-control review showing authorization testing, IDOR/BOLA validation, tenant isolation risk, privilege escalation paths, and remediation guidance. For multi-tenant products where the main risk is one customer reaching another customer’s data.
Advanced • Updated July 2026View ResourceAPI Security Checklist
A practical review checklist for API authorization, exposure, rate limits, and sensitive data flows. Use it before exposing a new endpoint or opening an API to partners.
Beginner • Updated July 2026View ResourceAccess Control Testing Checklist
A focused checklist for authorization boundaries, tenant isolation, RBAC, BOLA, and IDOR testing. Use it whenever roles, permissions or tenant boundaries change.
Intermediate • Updated July 2026View ResourceGraphQL Security Checklist
A review guide for GraphQL authorization, introspection, query depth, object access, and data exposure. For teams running GraphQL in production, especially with nested resolvers.
Advanced • Updated July 2026View ResourceSaaS Security Checklist
A product security checklist for SaaS platforms, tenant boundaries, workflows, integrations, and APIs. A starting point for a product team reviewing the whole platform before a launch.
Beginner • Updated July 2026View ResourceHow to Prepare for a Penetration Test
A preparation guide for SaaS teams planning access, scope, environments, documentation, and test objectives. Read it once a test is booked and before kickoff.
Beginner • Updated July 2026View ResourceWhat Happens During a Security Assessment
A clear walkthrough of scoping, access setup, manual testing, evidence development, reporting, remediation guidance, and retesting. For anyone commissioning a first assessment who wants to know each step in advance.
Beginner • Updated July 2026View ResourceChoosing the Right Penetration Testing Company
A practical guide for evaluating testing depth, methodology, deliverables, communication, and fit. For buyers comparing providers or replacing one.
Beginner • Updated July 2026View ResourceNeed a Review Built Around Your Product?
If your team needs SaaS, API, access control, AI workflow, or business logic testing, The Hidden Finds can help scope the right review and deliver practical next steps.
Request a Security Review