
AI SAAS / SAMPLE SIZE: 10
100% of tested AI SaaS
can be breached via
session replay
All tested AI applications were
vulnerable to in-session attacks.
AI SaaS showed the highest
exposure among the categories
analyzed, though the sample is
not large enough to be considered
statistically representative.
SESSION REPLAY
After replay was successful,
no tested SaaS application detected
two concurrent sessions running
in different browsers with the same
authenticated cookies. Sessions
remained active and undetected
for the full test window.
PARALLEL SESSIONS
/ Created, edited, and deleted
a teamspace
/ Created a new API key and deleted
existing keys/integrations
/ Used workspace chat to extract
company information
CRITICAL ACTIONS

Of the five SaaS applications where
replay persisted after logout, three
were AI SaaS. While less common
than the issues above, this remains
a significant concern: stolen
authentication cookies could still
bypass the security perimeter until
expiry, which varied by application but
was often long-lived.
SESSION PERSISTENCE
SEE MORE RESULTS: AI / DEVELOPMENT / FINANCIAL & HR / PRODUCTIVITY / MARKETING & SALES