TenantShield — Continuous Authorization Posture Monitoring for HR-Tech Vendors
A monitoring product built specifically for HR-tech, ATS, and recruitment-platform vendors that continuously probes their own APIs for tenant isolation failures, BOLA, and broken function-level authorization — surfacing findings in a customer-trust portal so enterprise buyers can see your security posture live.
product security leads and CTOs at HR-tech, ATS, and recruitment SaaS companies selling into enterprise
- Tenant-isolation dashboard that maps each customer's data boundary and shows where your last scan found risk
- Trust portal embeddable on your sales pages showing live "last scanned" status and authorization health score
- Regression alerts wired into your CI so a deploy that re-introduces a BOLA fails the pipeline before merging
- Customer-facing remediation timeline — enterprise buyers want to see how fast you fixed flagged issues
The AuthProbe README calls out the McHire class of bug specifically — HR-tech is uniquely exposed because every customer's candidates are PII, and enterprise buyers increasingly demand proof of tenant isolation before signing.
BOLA is OWASP API #1 since 2019 and SaaS breaches surged 300% in 2024 (Obsidian), with HR-tech-specific incidents like TalentHook confirming pain, but AuthProbe's actual traction is thin (140 stars, only 5 commits, 1 watcher) — not a 'trending' signal.GitHub - jbarach2012/AuthProbe ↗SaaS Security Threat Report 2025 | Obsidian Security ↗The TalentHook Data Breach: How a Simple Cloud Misstep Exposed Candidate Data ↗
Agnitestudio already offers 'SaaS Tenant Isolation Audit' testing for BOLA/tenant-isolation failures, and general BOLA detection is crowded (Invicti, Cloudflare API Shield, Aptori); only the HR-tech vertical specialization plus customer-trust portal is differentiated.SaaS Tenant Isolation Audit | Find Cross-Tenant Data Leaks ↗Broken Object Level Authorization vulnerability detection | Cloudflare ↗
Enterprise security budgets support premium pricing (Invicti-class tools charge thousands/yr), but the open-source AuthProbe engine is free and 'good enough' for many HR-tech vendors, capping willingness to pay without strong trust-portal differentiation.GitHub - jbarach2012/AuthProbe ↗BOLA Prevention | Aptori ↗
Structural problem (BOLA atop OWASP since 2019, candidate PII under GDPR pressure, enterprise procurement questionnaires demanding isolation proof) gives multi-year tailwinds, but incumbents (Cloudflare, Invicti) can add HR-vertical features and trust-portal standards (Vanta/Drata) may absorb the wedge.API Security 2026: Stopping BOLA Attacks | NuageSec ↗SaaS Security Threat Report 2025 | Obsidian Security ↗
Open-source AuthProbe provides a working BOLA-scanning engine to wrap, but false-positive risk on authorization findings is reputationally dangerous for the vendor, and selling into HR-tech product-security teams requires long enterprise cycles plus multi-tenant trust-portal infra.GitHub - jbarach2012/AuthProbe ↗