The setup: A SaaS platform passes its SOC 2 Type II exam.
The twist: Three months later, one changed number in an API request opens another customer's full record.
The fix: Four targeted changes that lock every record to its rightful owner.
Your takeaway: A clear view of where audits stop and API testing begins, plus the exact controls to put in place on your own platform.