• Cyber Safety
  • Posts
  • The Security Risk Hiding Inside Your SaaS Stack

The Security Risk Hiding Inside Your SaaS Stack

In partnership with

Join Anthropic, Kalshi, and Clay at Pioneer on October 7th

Pioneer, the summit where CX leaders redefine what’s possible, is on October 7th.

Join leaders from Fin, Anthropic, Clay, and Kalshi for an insightful conversation on the state of AI transformation.

You’ll discover how some of the most innovative minds in CX have transformed their organizations, learn how they think about CX, and hear how they're planning for what's next.

Join the conversation in San Francisco, or tune in virtually.

Every New SaaS Tool Creates Another Trust Relationship

Teams connect CRMs, analytics platforms, productivity tools, AI applications, and automation software every day. Each connection introduces permissions that can quietly expand your attack surface.

OAuth Can Become a Backdoor Without a Password

Third-party applications may retain access through OAuth tokens even after users change passwords. If those permissions aren't reviewed, forgotten integrations can remain connected for months or years.

Former Employees Aren’t the Only Offboarding Problem

Removing a user account doesn't automatically remove every application, API key, shared workspace, or external integration they configured.

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads

Blu Dot used Roku Ads Manager to drive incredible results for its furniture sales event. Its strategy hinged on custom audiences and retargeting, where intent was strongest.

“Roku has been a top performer,” said Blu Dot’s Claire Folkestad. “We have seen…CPMs lower than any other CTV partner we've worked with.”

Small Integrations Can Hold Powerful Permissions

A simple productivity app might have permission to read email, access files, modify calendars, or interact with company data — far beyond what employees realize.

SaaS Sprawl Makes Ownership Unclear

When nobody knows who approved an application, why it exists, or which data it can access, removing risky integrations becomes significantly harder.

Treat Integrations Like Privileged Accounts

Inventory connected applications, review OAuth scopes, assign owners, revoke unused integrations, and establish approval processes for new tools. Your security perimeter now includes every application your organization trusts.

Jira Product Discovery gives teams one place to capture customer feedback, prioritize ideas with consistent frameworks, and build living roadmaps everyone can align on. And when it’s time to build, those decisions connect directly to delivery in Jira, so everyone can see how the roadmap turns into real work.