Vesey Cyber Security

Security architecture review for micro SaaS businesses and AI/LLM platforms.

Your system architecture, reviewed against real-world attacks.

Checked against the current OWASP, MITRE ATLAS and agentic AI threat landscape.

TRUST BOUNDARY PRIVILEGE BOUNDARY UNTRUSTED Browser EDGE API gateway APPLICATION Agent runtime ! DATA Tenant store acts as the service, not as the user who prompted it
Illustrative. The flagged crossing is the most common finding in AI products that act on their own. No scanner looks for it.

Coverage

What reviews typically cover

Four patterns come up again and again.

Tenant isolation
A reporting feature that queries the database with its own permissions, skipping the check that confirms the data belongs to the requesting customer. See guides →
Agent permissions
An AI agent given the company's permissions instead of the user's, open to hijacking by a hidden instruction. See guides →
Over-privileged roles
A service account given higher privileges than needed for the job. See guides →
Exposed storage
A storage bucket or database reachable without authentication, because a default was never locked down after launch. See guides →

The deliverable

Documented hardening, ready to act on.

Every finding names the attack, the fix, and the requirement it satisfies. The same document works for your engineers and your buyer's security reviewer. This is what one looks like.

High SA-04 Tenant isolation

Tenant identifier accepted from a client-supplied header

Path browser → api gateway → data layer
What an attacker does Authenticates as a legitimate user on any tenant, replays the request with a different X-Tenant-Id, and reads records belonging to another customer. No credential theft required.
Requirement Derive the tenant identifier from the verified session at the gateway and discard any client-supplied value. Enforce it again at the data layer so a single bypass is not sufficient.
Satisfies SOC 2 CC6.1 · ISO 27001 A.8.3 · common SIG questionnaire item

↑ Illustrative example, not a real client finding.

Engagements

Three ways to start.

Fit

Who this is for.

  • →A multi-tenant SaaS where one bad header check could expose another customer's data.
  • →A team shipping an LLM agent with tool access and no threat model behind it.
  • →An architecture that grew faster than anyone documented it.
  • →A platform about to go live that nobody's stress-tested against real attacks.

Contact

Let's talk about your architecture.

No charge, no deck. Just a conversation to see where things stand.

Or email hello@zyvra.studio directly.

  • CompanyVesey Cyber Security is a trading name of Zyvra Studio Ltd · Company No. 17180795 · Birmingham, UK

You'll hear back within two business days. See how we handle your data.