// Pentest and SaaS security in São Paulo (SP)
SaaS security and pentest in São Paulo (SP)
Quick answer
In São Paulo, where Faria Lima and Vila Olímpia concentrate a huge share of the country’s startups, RET runs manual pentests, Risk Review (a paid human read) and continuous monitoring (AuditMySaaS) for AI-built products, remotely, with documented authorization and a tight scope. It does not need to be on-site and needs no local branch: the work is done on the domain and assets you authorize, with evidence delivered by e-mail.
The SaaS ecosystem in São Paulo (SP)
São Paulo holds about 30% of all Brazilian startups and ranks 24th among the world’s startup ecosystems, the largest in Latin America. Faria Lima, Vila Olímpia, Itaim Bibi and Pinheiros form the city’s SaaS and fintech axis, with hundreds of B2B products shipped with AI.
The faster this ecosystem ships SaaS with AI (Codex, Claude Code, Cursor, Lovable, Bolt, v0, Replit), the sooner login, billing, customer data and integrations start carrying money and attracting risk. That is exactly where RET manual review fits.
Why SaaS in São Paulo (SP) needs security
AI-built products ship fast, but the flows that sustain revenue (login, paid plans, checkout, uploads, admin panel, per-customer data) often go without a human review. An IDOR, a webhook with no signature check or an exposed secret do not show up in the demo, they show up in the incident and block the B2B sale.
- Login, permissions and paid access reviewed as one revenue flow
- Checkout, Stripe and webhooks with signature verification
- Per-customer data, uploads and admin panel with tenant isolation
- An impact chain written for founder, dev and B2B customer
Proof, not promises
RET does not sell absolute certainty, it proves what breaks. The public Find My SaaS case shows a real finding recognized and fixed by the product founder, and RET has over 100 real vulnerabilities reported with authorization and responsible disclosure. The work is signed by Gabriel L. Ferreira, founder and lead pentester at RET.
How to hire RET in São Paulo (SP)
You start with the Promptbook (R$97) for the first read, move up to Risk Review (R$2,997) when a signal appears, and go to the Manual Pentest (scoped) when the sale asks for proof. AuditMySaaS monitors what changes continuously. Every test starts only with a verified domain, accepted terms and an authorized scope.
Frequently asked questions
Does RET serve in São Paulo (SP)?
Yes. RET serves SaaS in São Paulo (SP) remotely, with authorization and scope. No local branch or on-site meeting is required to start.
Who runs the pentest at RET?
Gabriel L. Ferreira, founder and lead pentester at RET Tecnologia, does the manual review. RET has a public case (Find My SaaS) and over 100 real vulnerabilities reported with responsible disclosure.
Does it need to be on-site in São Paulo (SP)?
No. Manual pentest, Risk Review and AuditMySaaS are done remotely on the domain and assets you authorize, with evidence delivered by e-mail.
How much does SaaS security cost in São Paulo (SP)?
Promptbook is R$97, Risk Review is R$2,997, and the Manual Pentest is by proposal per authorized scope. AuditMySaaS is a monthly subscription (plans at auditmysaas.app).
Does RET test without authorization?
Never. Every cycle starts only with a verified domain, accepted terms, documented scope and clear boundaries of what will not be touched.
Keep reading
Pentest and SaaS security in Rio de Janeiro (RJ)
SaaS security and pentest in Rio de Janeiro (RJ)
Pentest and SaaS security in Florianópolis (SC)
SaaS security and pentest in Florianópolis (SC)
By tool
Security for apps built with Lovable
Comparison
Manual pentest vs automated security scanner
Guide
Security checklist for AI-built SaaS