AI SAAS / SAMPLE SIZE: 10

100% of tested AI SaaS

can be breached via

session replay


All tested AI applications were

vulnerable to in-session attacks.

AI SaaS showed the highest

exposure among the categories

analyzed, though the sample is

not large enough to be considered

statistically representative.

SESSION REPLAY


After replay was successful,

no tested SaaS application detected

two concurrent sessions running

in different browsers with the same

authenticated cookies. Sessions

remained active and undetected

for the full test window.

PARALLEL SESSIONS

/ Created, edited, and deleted

a teamspace

/ Created a new API key and deleted

existing keys/integrations

/ Used workspace chat to extract

company information

CRITICAL ACTIONS


Of the five SaaS applications where

replay persisted after logout, three

were AI SaaS. While less common

than the issues above, this remains

a significant concern: stolen

authentication cookies could still

bypass the security perimeter until

expiry, which varied by application but

was often long-lived.

SESSION PERSISTENCE

SEE MORE RESULTS: AI / DEVELOPMENT / FINANCIAL & HR / PRODUCTIVITY / MARKETING & SALES

END

  • TOKEN THEFT

  • SESSION HIJACKING

  • ACCOUNT TAKEOVER

  • MFA BYPASS

© 2026 Relock, Inc. | 701 Brazos St., STE 150 | 78701 Austin, TX

END

  • TOKEN THEFT

  • SESSION HIJACKING

  • ACCOUNT TAKEOVER

  • MFA BYPASS

© 2026 Relock, Inc. | 701 Brazos St., STE 150 | 78701 Austin, TX