Customer case study

Scalekit: SOC 2 pentest for enterprise B2B authentication

How a B2B SSO and SCIM platform used DeepScan to package auditor-ready SOC 2 pentest evidence for enterprise buyers.

Scalekit

SOC 2 Type II

B2B authentication

The challenge

What the team needed to prove.

The assessment began with business context, exposed workflows, and the evidence stakeholders needed.

Scalekit needed independent pentest evidence for a SOC 2 Type II review and enterprise customer security packets.

The scope included SSO, SCIM, tenant isolation, admin workflows, and API authorization paths where scanner output would not be enough.

The approach

Testing connected to the real operating surface.

Exploration, validation, and reporting stayed attached to the same approved scope.

DeepScan scoped the web app, API, SAML/OIDC flows, SCIM endpoints, and tenant boundary checks against the SOC 2 system description.

AI-powered discovery accelerated coverage, while human operators validated business logic, exploit chains, evidence quality, and report wording.

The result

Evidence ready for action and review.

Validated output gave engineering and assurance stakeholders a shared record.

The final report mapped validated findings to SOC 2 controls, included reproduction evidence, and gave engineering clear remediation steps.

Scalekit used the report in auditor review and enterprise buyer conversations without reformatting the evidence package.

Explore pentesting services

Start with proof

Build your own defensible security story.

Start with an approved target and keep every step from test to retest connected.

Start a pentestExplore case studies