Security testing use cases
A test plan for the way your application works.
Choose a workflow, prepare the right accounts and define the evidence you need. These plans combine an authorized automated baseline with specific decisions about manual review.
12 practical security testing plans.
Each plan covers assets, roles, preparation, report evidence and the limits of automation. Choose by application architecture or the decision your team needs to make.
- SaaS teams
Security testing for SaaS applications
Plan SaaS security testing around organizations, invitations, subscription permissions and exports, with repeatable evidence and clear manual review limits.
Read the testing plan - Ecommerce
Security testing for ecommerce websites
An ecommerce testing plan for cart totals, order ownership, discounts, refunds and checkout transitions, using sandbox payments and traceable evidence.
Read the testing plan - Fintech applications
Security testing for fintech applications
Scope fintech application testing around account access, transaction approvals and ledger evidence. Separate automated checks from financial workflow review.
Read the testing plan - Healthcare applications
Security testing for healthcare applications
Plan healthcare application testing with synthetic patient records, explicit clinician permissions, redacted evidence and separate compliance review.
Read the testing plan - Before launch
Security testing before a startup launch
A practical pre-launch security testing plan for public exposure, account boundaries and core workflows, with fixes and documented release decisions.
Read the testing plan - Development agencies
Security testing for development agencies
A client-ready testing workflow for agencies: written scope, isolated test accounts, reproducible findings, remediation ownership and handover evidence.
Read the testing plan - Multi-tenant applications
Security testing for multi-tenant applications
A tenant-isolation test plan for records, search, exports, files and background jobs, with two controlled tenants and positive and negative evidence.
Read the testing plan - REST APIs
Security testing for REST APIs
Plan REST API testing using a route and permission inventory, controlled object ownership, response evidence and separate business-flow review.
Read the testing plan - GraphQL APIs
Security testing for GraphQL APIs
A GraphQL security test plan for resolvers, nested fields, mutations and query limits, with manual schema review and explicit automated coverage boundaries.
Read the testing plan - Release validation
Security testing for release validation
Connect scoped security assessments with release evidence: stable staging, commit context, coverage review, regression tests and explicit deployment decisions.
Read the testing plan - Authenticated applications
Security testing for authenticated applications
Improve signed-in testing coverage with representative users, session verification, role controls and explicit account-recovery and SSO review.
Read the testing plan - Small engineering teams
Security testing for small engineering teams
Build a manageable security testing routine with a scoped baseline, evidence-driven triage, repair owners, retests and focused manual review.
Read the testing plan
Choose the plan by the boundary you need to test.
Customer data boundaries
Use the SaaS, multi-tenant or authenticated plans when the question is who can access a customer's record, organization or privileged action.
Transactions and state changes
Use the ecommerce or fintech plan when permissions alone are insufficient and a payment, approval, cancellation or retry can change value.
Release and delivery decisions
Use the pre-launch, agency or release validation plan to tie a scoped assessment to a known deployment, repair owner and retest result.
A useful report says what was tested and where access or coverage was missing. These plans describe a testing approach; they do not imply industry certification or that every step is an automated MyPentest feature.