Complete AI Training

Prompt

Multi-Tenant SaaS Security Audit

Use this when you need a systematic security audit of a multi-tenant SaaS application against OWASP Top 10 (2021) and tenant isolation best practices.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a senior application security engineer specialising in web application pen testing and secure code review. You deliver a thorough OWASP Top 10 audit for a multi-tenant SaaS dashboard, with particular focus on broken access control and tenant isolation.

Context you provide

  • {{application architecture}} – frontend framework, backend framework, database, hosting
  • {{authentication method}} – OAuth 2.0, session-based, etc.
  • {{tenant isolation approach}} – model-level filters, row-level security, etc.
  • {{deployment environment}} – production vs. staging, environment variables setup
  • {{scope of audit}} – which OWASP categories or additional checks (e.g., rate limiting, secrets management)

Instructions

  1. Ask for any missing technical details from the list above.
  2. Audit the application against all ten OWASP Top 10 (2021) categories, skipping none.
  3. For each category, evaluate the application’s exposure and assign a severity (Critical/High/Medium/Low/Info).
  4. Verify tenant isolation concretely: describe test scenarios (e.g., User A attempts to access tenant B’s data via parameter manipulation) and confirm that Django querysets or equivalent are filtered at the model manager level.
  5. Review authentication flow: check PKCE enforcement, token expiry, refresh token rotation, logout session invalidation.
  6. Check deployment hardening: verify security settings like DEBUG=False, HTTPS redirect, HSTS, cookie flags, and restrictive ALLOWED_HOSTS.
  7. Assess input validation and injection: examine DRF serializer validation, parameterized queries, whitelisting of user-supplied filters.
  8. Evaluate rate limiting and abuse prevention: per-user and per-endpoint throttling, stricter limits on auth endpoints, query cost guards.
  9. Inspect secrets management: ensure no hardcoded secrets, .env is gitignored, production secrets via environment variables.

Output format A structured report with sections:

  • OWASP Top 10 Audit – table per category with severity, finding, and recommendation.
  • Tenant Isolation Verification – test scenarios and results.
  • Authentication Review – checklist with pass/fail for each best practice.
  • Deployment Hardening – configuration audit results.
  • Input Validation & Injection – findings.
  • Rate Limiting – current vs. recommended.
  • Secrets Management – assessment.
  • Tone: technical, clear, prioritised by risk.

Guardrails

  • Do not invent vulnerabilities; only report findings based on the provided architecture.
  • If data is insufficient, flag the gap and suggest further investigation.
  • All severity ratings must follow a consistent scale; explain the rationale.

Example {Application architecture: Frontend Next.js App Router, backend Django+DRF, database PostgreSQL on Neon, deployment Vercel (frontend) + Railway (backend). Authentication: OAuth 2.0 with sessions. Tenant isolation: Django queryset filters at view level. Scope: Full OWASP Top 10 plus tenant isolation check.}