Skip to content
Whitepaper

SaaS-to-SaaS Breaches: The Integration Tokens Nobody Is Watching

The fastest-growing path into an organization is not the front door. It is the OAuth token connecting one vendor to another. A due-diligence and monitoring guide for app-to-app risk.

Written for
Heads of TPRM, CISOs, identity and SaaS security leads, procurement, internal audit
Reading time
10 minutes
Published

When a vendor is breached, the instinct is to ask what happened inside their environment. Increasingly, the more important question is what that vendor was connected to. Modern SaaS products are woven together by integrations: your marketing platform reads your CRM, your CRM syncs to your data warehouse, your support desk posts to your chat tool, an analytics add-on holds a token into all of them. Each connection is authorized once, usually through OAuth, and then persists silently, often with broad access, frequently forgotten. These connections are now a leading way that a compromise of one vendor becomes a compromise of your data held in another.

The uncomfortable feature of this risk is that the breached system is often not yours and not even your primary vendor's. An attacker who obtains the tokens held by a small, connected add-on can read the data those tokens unlock in a major platform, without ever touching the platform's own defenses. The primary vendor's security posture, the one you assessed, was never the weak point. This paper treats SaaS-to-SaaS integration as a first-class category of third-party risk: why it has grown, what recent public incidents teach, and how to bring integration tokens and their scopes into due diligence, contracts and monitoring. It describes the risk and the defenses; it is not an attack guide.

Bringing integrations into due diligence

Integration risk is assessable with questions that elicit evidence, not assurances. Add an integration section to assessments for vendors that connect to systems holding sensitive data, scaled to criticality.

Integration due-diligence questions
AreaWhat to ask for
Connection inventoryWhich of our systems the vendor connects to, and the OAuth scopes or API permissions each connection holds
Least privilegeWhether connections can be scoped down, and the justification for any broad read-write or admin scope
Token storageHow the vendor stores integration tokens and secrets, and whether they are encrypted and access-controlled
Token rotationHow often tokens are rotated, and whether they can be revoked and reissued without service disruption
Their fourth partiesWhich subprocessors or connected apps the vendor in turn grants access to your data
Exposure notificationHow, and how quickly, the vendor would notify you if integration tokens were exposed
OffboardingHow connections and tokens are revoked when the relationship ends

A vendor that can answer these has thought about the connection as a risk. A vendor that treats "we use OAuth" as a sufficient answer has not.

Scope and standing access: the two levers that matter most

Two properties determine how much an integration breach costs you. The first is scope. A connection granted read-write access to everything, because that was the default at setup, hands an attacker who obtains its token the same breadth. The same integration scoped to the one object it needs limits the blast radius to that object. Most integrations are over-scoped, and tightening them is among the highest-value, lowest-effort controls available.

The second is standing access. A human credential is bounded by the human: it fails when they leave, when they change their password, when multi-factor challenges them. An integration token has none of those bounds. It keeps working until someone deliberately revokes it, which means a forgotten integration from a vendor you stopped using three years ago may still hold live access. Offboarding a vendor is not complete until its connections are revoked, and that step is routinely missed because the connection is invisible in the contract-centric view of the relationship.

Monitoring for the connections you did not authorize

Due diligence assesses the integrations you know about. Monitoring is how you find the ones you do not. Connected apps appear without a formal decision: a team enables a marketplace add-on, a trial integration is never removed, a vendor switches on a new connection by default. An outside-in and inside-out monitoring posture should treat a newly appearing connection into a sensitive system the same way it treats a new exposed service, as a signal to confirm, attribute and act on. The question a monitoring program should be able to answer is not only "how are our vendors' external postures changing" but "what now holds a token into our data that did not last month."

Contract levers

The connection should be governed by the contract, not only by the setup screen.

  • Scope minimization: the vendor holds the least access needed, and broad scopes require written justification
  • Token protection: integration tokens and secrets are encrypted, access-controlled and rotated on a defined cadence
  • Exposure notification: prompt notice if integration tokens or secrets are exposed, aligned to your incident regime
  • Subprocessor flow-down: connected apps and subprocessors the vendor grants access to are disclosed with equivalent obligations
  • Revocation on exit: all connections and tokens are revoked on termination, with confirmation
  • Right to review: you may review the scopes and connections the vendor holds into your systems

What examiners and boards increasingly ask

Supervisory attention to identity and outsourcing already reaches this territory. Operational resilience and outsourcing regimes expect firms to understand and control how third parties access their systems and data, and identity-security guidance increasingly names non-human identities specifically. The board-level question is simple to ask and hard to answer without an inventory: which third parties hold standing access into our critical systems, at what scope, and how would we know if that access were abused.

Practical checklist

  • Vendors that connect to sensitive systems have an integration section in their assessment
  • Each integration's OAuth scopes or API permissions are recorded and justified against least privilege
  • Integration tokens the vendor holds are covered by storage, rotation and exposure-notification terms
  • Connected apps and their subprocessors are recorded in the nth-party inventory
  • Offboarding includes revoking every connection and confirming it
  • Monitoring flags new or dormant connections into sensitive systems for confirmation and action
  • The board can be shown which third parties hold standing access into critical systems

How VendRisk360 supports this

VendRisk360 lets you treat SaaS-to-SaaS integration as the risk category it has become, and assess the connection, not only the vendor.

Artifact-based assessments across 30+ control domains and configurable questionnaires let you add an integration section, connections, OAuth scopes, token storage and rotation, exposure notification and revocation, to any vendor that connects to systems holding sensitive data, scoped by criticality tier. Because the questions ask for evidence, a vendor's answers on scope and token handling become reviewable facts rather than assurances. Findings, remediation and formal risk acceptance run through multi-stage sign-off with segregation of duties, so a decision to accept a broad integration scope has an owner and a review date. See Comprehensive Vendor Risk Assessment Services.

The connected apps and providers a vendor in turn grants access to are fourth parties, and [nth-party intelligence](/solutions/nth-party-intelligence/) records them from SOC report subservice organizations and your own relationship data, so a connector that sits behind several of your vendors surfaces as a concentration and data-flow question. Where the connection changes, [Continuous Monitoring](/services/continuous-monitoring/) applies the confirm-attribute-act discipline: a confirmed, attributed, material signal, including a vendor's changing external posture, is routed to the relationship owner and can trigger an early reassessment or a targeted evidence request, rather than adding to an unread feed. Offboarding runs through the platform's exit workflow with a checklist and audit trail, so revoking a vendor's access is a tracked step rather than a forgotten one.

When an examiner asks which third parties hold access into your systems and how you govern it, the examiner package export bundles the assessment, evidence, sign-offs and audit trail, and board and executive reporting summarizes program status. Customer data is protected by row-level-security tenant isolation, encryption in transit and at rest, SSO (SAML/OIDC), mandatory MFA, custom roles and a full audit trail. See Security and Board and executive reporting.

How to work with VendRisk360. On the Vendor Lifecycle Management Platform, your team manages vendors, sends integration-focused due diligence through the vendor portal, performs the review and signs off, with every step tracked, and runs offboarding as a governed workflow. With Comprehensive Vendor Risk Assessment Services, you onboard the vendor and certified assessors collect the evidence, perform the review scaled to the vendor's tier with a second-expert quality review, and follow findings through remediation, while you keep final approval. Continuous Monitoring Services add the outside-in view between assessments, and Report-Specific Reviews are available standalone or alongside either. Assessors hold certifications such as CISSP, CISA, CISM, CRISC and ISO/IEC 27001 Lead Auditor and Lead Implementer.

To see integration risk assessed and monitored end to end, book a demo.

VendRisk360

About VendRisk360

VendRisk360 is an independent company providing a third-party risk management platform and expert services for regulated organizations: banks, credit unions, fintech and payments, healthcare and SaaS. The platform runs vendor lifecycle management, risk-tiered assessments, continuous monitoring, nth-party intelligence and board-ready reporting from one governed record per vendor, combining point-in-time, evidence-based review with continuous outside-in monitoring. Customers run it themselves on the Vendor Lifecycle Management Platform, or add Comprehensive Vendor Risk Assessment Services, Continuous Monitoring Services and Report-Specific Reviews delivered by certified VendRisk360 assessors.

Learn more at vendrisk360.com or write to info@vendrisk360.com.

This paper is general guidance for practitioners, not legal advice. Regulatory requirements change and vary by jurisdiction and institution; confirm your obligations with counsel and your supervisors.

Get started

Put this guidance to work on your own vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.