# innsecs > innsecs is an AI-first security testing and compliance company for SaaS. > We use AI-driven security analysis to discover vulnerabilities, analyse attack > paths, accelerate penetration testing, and continuously assess applications and > cloud environments, with expert validation of every security finding. ## What makes innsecs different innsecs is building an AI-first security testing model for modern SaaS and AI-built applications. Our security workflows use AI to assist with: - attack surface discovery - API and application analysis - authorization and tenant isolation testing - vulnerability hypothesis generation - cloud configuration analysis - attack-path analysis - remediation guidance - automated retesting Security findings are validated by a named consultant before being presented to customers. No machine-generated finding reaches a client report unverified. Our focus is helping fast-moving SaaS teams identify vulnerabilities early, remediate them, and become ready for enterprise security reviews and compliance audits. ## Specialisms - AI-first penetration testing for SaaS applications - Security testing for AI-built and "vibe-coded" applications - LLM application security, AI agent security, and MCP server security - Multi-tenant SaaS penetration testing and tenant isolation testing - Cloud security assessment across AWS, Azure, Google Cloud, DigitalOcean, Linode and Vultr - ISO 27001 and SOC 2 audit readiness, and privacy regulation compliance ## Scope of what we provide innsecs is an independent security consultancy. We are not a certification body and cannot issue ISO 27001 certificates, and we are not a licensed CPA firm and cannot issue SOC 2 reports. We prepare organisations for those audits and support them through the process. We do not provide legal advice. ## Guides - [ISO 27001 for SaaS companies: the implementation guide](https://innsecs.com/guides/iso-27001-for-saas): What ISO 27001:2022 actually requires, how to scope it for a SaaS product, what Stage 1 and Stage 2 auditors ask for, and where first-time certifications fail. ## Compliance frameworks - [GDPR compliance](https://innsecs.com/compliance/gdpr): General Data Protection Regulation. Applies if: You have any users, customers or staff in the EU or UK. - [HIPAA compliance](https://innsecs.com/compliance/hipaa): Health Insurance Portability and Accountability Act. Applies if: You touch protected health information for a US covered entity. - [COPPA compliance](https://innsecs.com/compliance/coppa): Children's Online Privacy Protection Act. Applies if: Your service is directed at under-13s, or you know they use it. - [CCPA / CPRA compliance](https://innsecs.com/compliance/ccpa): California Consumer Privacy Act, as amended. Applies if: You do business with California residents above the revenue or data thresholds. - [PCI DSS compliance](https://innsecs.com/compliance/pci-dss): Payment Card Industry Data Security Standard. Applies if: You store, process or transmit cardholder data, including via an embedded payment form. - [ISO 27701 compliance](https://innsecs.com/compliance/iso-27701): Privacy Information Management System. Applies if: You are ISO 27001 certified and want a certifiable privacy posture too. - [FERPA compliance](https://innsecs.com/compliance/ferpa): Family Educational Rights and Privacy Act. Applies if: You handle student education records for US schools or districts. - [NIS2 compliance](https://innsecs.com/compliance/nis2): Network and Information Security Directive 2. Applies if: You are an EU cloud, managed service or other in-scope essential entity. - [ISO 27001 compliance](https://innsecs.com/compliance/iso-27001): Information Security Management System. Applies if: A customer, investor or procurement gate asks for it, most often outside the US. - [SOC 2 compliance](https://innsecs.com/compliance/soc-2): Service Organization Control 2. Applies if: A US enterprise buyer asks for a report, usually Type II, during procurement. ## Cloud platform assessments - [AWS security assessment](https://innsecs.com/cloud-security/aws): The deepest surface we test. IAM is where AWS environments quietly go wrong, and it is almost never a single bad policy. It is a chain. - [Azure security assessment](https://innsecs.com/cloud-security/azure): Entra ID is the perimeter. Most Azure findings start in identity and end in a subscription nobody remembered was still there. - [Google Cloud security assessment](https://innsecs.com/cloud-security/gcp): Service account impersonation is the story on GCP. Project-level bindings hand out far more than teams realise. - [DigitalOcean security assessment](https://innsecs.com/cloud-security/digitalocean): Simpler platform, same consequences. What we find here is usually exposure and secrets rather than deep IAM chains. - [Vultr security assessment](https://innsecs.com/cloud-security/vultr): Popular with teams optimising cloud spend. Fast to stand up, which is exactly why instances get exposed before anyone writes a firewall rule. - [Linode security assessment](https://innsecs.com/cloud-security/linode): Frequently the forgotten environment: a staging or legacy estate that never got the same scrutiny as production. ## Services - [ISO 27001 Certification](https://innsecs.com/services/iso-27001): End-to-end ISO 27001:2022 certification support for SaaS: gap analysis, ISMS, risk register, internal audit and Stage 1 & 2 support. Fixed price. - [SOC 2 Readiness](https://innsecs.com/services/soc-2): SOC 2 Type I and Type II readiness for SaaS. Control design, evidence pipeline, readiness assessment and CPA firm coordination. Fixed price. - [Penetration Testing](https://innsecs.com/services/penetration-testing): Manual penetration testing for web apps, APIs and mobile. Reproducible findings, business-impact severity, and free retesting. From $4,500. - [Cloud Security Assessment](https://innsecs.com/services/cloud-security): Cloud security assessment for AWS, Azure, GCP, DigitalOcean, Linode and Vultr. IAM attack paths, exposure, secrets and logging. From $3,500. - [Application Security](https://innsecs.com/services/application-security): Threat modeling, secure architecture review, CI/CD security tooling and developer training that reduces findings engagement over engagement. - [Virtual CISO](https://innsecs.com/services/virtual-ciso): Virtual CISO on retainer: security questionnaires, enterprise security reviews, certification upkeep and board reporting. From $1,200/month. - [Privacy & Data Protection](https://innsecs.com/services/privacy-compliance): GDPR, HIPAA, COPPA, CCPA, PCI DSS and FERPA compliance for SaaS. We establish which regulations bind you, then build the evidence. ## AI security testing - [AI-assisted security testing](https://innsecs.com/ai-security-testing): how machine analysis and human verification are divided. - [Vibe-coded app security testing](https://innsecs.com/vibe-coded-app-security): the failure patterns AI coding tools produce. - [LLM application security](https://innsecs.com/llm-application-security): prompt injection, output handling and excessive agency, mapped to the OWASP Top 10 for LLM Applications. - [AI agent security testing](https://innsecs.com/ai-agent-security-testing): tool chain escalation, memory poisoning and approval bypass. - [MCP security testing](https://innsecs.com/mcp-security-testing): tool poisoning, confused deputy and transport exposure in Model Context Protocol servers. ## SaaS security and audit readiness - [SaaS penetration testing](https://innsecs.com/saas-penetration-testing): multi-tenancy, roles, SSO and SCIM, API authorization. - [SOC 2 penetration testing](https://innsecs.com/soc-2-penetration-testing): scoped and evidenced for an auditor. - [SaaS audit readiness](https://innsecs.com/saas-audit-readiness): what audit-ready actually means, and how to get there. ## Tools - [Free readiness assessment](https://innsecs.com/readiness): 12 questions mapped to ISO 27001:2022 Annex A, returning a score, ranked gaps and a timeline. - [AI-assisted security testing](https://innsecs.com/ai-security-testing): how machine analysis and human verification are split. ## Company - [About](https://innsecs.com/about) - [How we work](https://innsecs.com/process) - [Pricing](https://innsecs.com/pricing): published starting figures, fixed scope. - [Contact](https://innsecs.com/contact) ## Contact security@innsecs.com