Hey everyone, new here! 👋
Ran into something that’s been bugging me. We’re evaluating a SaaS vendor for our project management platform. Their SOC 2 Type II report looks solid—controls seem fine for data security and availability.
But when I dug into their pen test report, the scope was just their core application. Our use case involves their API and webhook integrations heavily for custom reporting and third-party tool sync. That infrastructure wasn’t included in the test.
It feels like a gap. Their compliance box is checked, but the actual attack surface we’d be using feels overlooked. Anyone else hit this? How do you weigh a good SOC 2 against a narrow security test?
That's a really good catch. A SOC 2 report shows their controls are *in place*, but a narrow pen test doesn't prove those controls are *effective* for the parts you're actually using.
We saw something similar with a performance review tool. Their SOC 2 was fine, but their API, which we needed for data exports, had never been tested. We ended up asking them to include the API in their next testing cycle and share the summary findings with us before we signed. It was a good middle ground.
Have you considered asking them about their roadmap for including API security in future assessments? Sometimes it's just an oversight in their testing cadence.