Skip to content

Application

Salesforce
Penetration Testing

Org testing and AppExchange security review prep

Org test from $6,800, AppExchange review prep $5,200, fixed scope, free retest. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When a Salesforce org needs testing

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • You run a customer or partner portal on Experience Cloud and need to know what an unauthenticated guest can reach.
  • Years of sharing rules, profiles, and permission sets have accumulated and nobody can say who can see what.
  • You build on the platform with custom Apex and Lightning components that have never been tested by an outsider.
  • You are an ISV preparing a managed package for the AppExchange security review and want to pass on the first attempt.
  • An enterprise customer or auditor asked for independent testing of the Salesforce org that holds their data.
  • Donor records live in Salesforce, and staff and volunteer roles have piled up access over the years. Our page on cybersecurity for nonprofits covers the donor CRM scope.

Definition

What is Salesforce penetration testing?

Salesforce penetration testing is a manual test of your org: the sharing model that decides who sees which records, the profiles and permission sets that grant access, the Experience Cloud sites that expose data to guests and external users, the custom Apex and Lightning code you have built, and the connected apps and integrations that hold standing access. It is mostly configuration testing, because in Salesforce the sharing model and permissions decide who sees which record.

An org test starts at $6,800. For ISVs building a managed package, AppExchange security review prep is $5,200 and gets the package ready to pass Salesforce’s review. Both are tested under Salesforce’s Security Assessment Agreement, and our guide to penetration testing for SaaS companies covers how buyers read the result.

What we look for

Salesforce vulnerabilities we hunt for

Much of Salesforce security is configuration, not code: a sharing rule that exposes a record, a guest profile that reads too much, an Apex class that runs without sharing. We test the org the way an attacker with a login, or none at all, would.

Sharing model and record access

The heart of Salesforce security: whether org-wide defaults and sharing rules actually keep one user out of another user’s data.

We test for

  • Org-wide defaults that expose more than intended
  • Sharing rules, role hierarchy, and manual shares
  • Record access across users, roles, and business units
  • Report, list-view, and dashboard data leakage
  • Field-level access to sensitive data

Profiles, permissions, and admin roles

The permission sprawl that turns an ordinary user into one who can see or change far more than their job needs.

We test for

  • Over-permissioned profiles and permission sets
  • Modify All Data and View All Data grants
  • Standing administrator and delegated-admin access
  • Session, login, and IP-restriction policies
  • API and data-export permissions

Experience Cloud and guest exposure

The finding that makes headlines: an unauthenticated guest reading records through the portal APIs.

We test for

  • Guest-user profile and sharing exposure
  • Unauthenticated record access through Aura and LWC endpoints
  • GraphQL and REST object access as a guest
  • Site and community configuration weaknesses
  • External and self-registration user privileges

Apex, Visualforce, and Lightning

The custom code, where the classic Salesforce vulnerabilities live: injection, missing access checks, and code that ignores sharing.

We test for

  • SOQL and SOSL injection in Apex
  • Classes running without sharing that should enforce it
  • CRUD and field-level security not enforced in code
  • Cross-site scripting in Visualforce, Aura, and LWC
  • Insecure use of exposed Apex and remote actions

Connected apps and integrations

The OAuth apps, integration users, and installed packages that hold standing access to the org.

We test for

  • Connected app and OAuth scope over-permissioning
  • Integration users with excessive access
  • Installed and managed package permissions
  • Named credentials and stored secrets
  • Session and refresh-token handling

Beyond a scanner

What an automated Salesforce scan misses

Salesforce security scanners read the org configuration and flag deviations from a benchmark, which is useful and fast. What they cannot do is prove exploitation: whether a guest user can actually pull records through an Aura endpoint, whether one business unit can reach another through a sharing rule, or whether an Apex class marked without sharing exposes data in a way that matters. Those take a tester with test accounts in the roles that matter.

This engagement does the manual work a scan cannot: guest-user exploitation against Experience Cloud, sharing-model testing across real roles, and an Apex review for SOQL injection, missing CRUD and field-level checks, and cross-site scripting. The result is proof of what an attacker reaches, not a list of settings to double-check.

For ISVs

AppExchange security review prep

Salesforce charges $999 for each security review attempt on a paid solution, and a failed attempt means fixing and resubmitting. We get the package ready to pass the first time.

The scans Salesforce requires

A Salesforce Code Analyzer scan of the package with the violations triaged, the Partner Security Portal source scan, and a DAST scan (using OWASP ZAP or Burp Suite) of any external endpoints the package calls, all in the format the review expects.

Manual review and false positives

A manual review of the managed package against the security review checklist (CRUD and field-level security, injection, secrets, OAuth), and a false-positive document that explains each flagged item the automated tools got wrong, with the code that proves it.

Ready to submit

A recheck of the fixes before submission, so the package, its test org and credentials, and the scan reports are complete when you submit.

This prepares your submission. Salesforce runs the official review and charges its own fee, and we do not submit on your behalf. Our guide on how to pass the Salesforce security review walks through what reviewers check and why packages fail.

Pricing

How Salesforce testing is priced

Salesforce scopes are sized by the org, its code, and its external surface, and fixed in writing before work begins.

Org test

One production org or full-copy sandbox, up to about 50 custom objects, one Experience Cloud site, and up to about 10,000 lines of custom Apex, Visualforce, and LWC: $6,800.

Larger org

Two or more Experience Cloud sites, up to about 30,000 lines of custom code, more integrations and connected apps, or Agentforce and Einstein features in scope: $10,500.

AppExchange review prep

For ISVs: Code Analyzer and DAST scans, a manual package review, and a false-positive document, ready for Salesforce’s review: $5,200.

Several orgs, a large custom codebase, or complex multi-business-unit sharing are quoted from the scope, still fixed before work begins.

Methodology

Salesforce penetration testing methodology

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your Salesforce penetration testing runs through.

  1. 01

    Scope & access

    One org or full-copy sandbox, read-only admin plus test users per role, tested under Salesforce’s Security Assessment Agreement, with the fixed price in writing.

  2. 02

    Configuration & sharing

    Org-wide defaults, sharing rules, profiles, and permission sets reviewed for who can reach what.

  3. 03

    Guest & external testing

    Experience Cloud and guest-user access probed through the Aura, LWC, and GraphQL endpoints an attacker calls.

  4. 04

    Apex & code review

    Custom Apex and Lightning components tested for injection, missing access checks, and code that ignores sharing.

  5. 05

    Report & retest

    A report for admins and developers, an attestation letter, and a free retest once your fixes ship.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping Salesforce penetration testing.

Still have questions? 
01What does a Salesforce penetration test cover?

The org configuration and the code on top of it: org-wide defaults, sharing rules, role hierarchy, profiles, and permission sets; Experience Cloud and guest-user exposure through Aura, LWC, and GraphQL endpoints; custom Apex and Lightning components for SOQL injection, classes that run without sharing, missing CRUD and field-level checks, and cross-site scripting; and connected apps, OAuth scopes, integration users, and installed packages. Most of the work is configuration testing, with a code review on top.

02Do we need Salesforce’s approval to test our org?

No. Since January 31, 2023, Salesforce no longer requires customers to request prior approval or give advance notice before testing their own org, provided the work follows Salesforce’s Security Assessment Agreement. That agreement sets the rules: no denial-of-service testing, no access to any org or data other than your own, and validated findings reported to Salesforce. We test inside those rules and within the scope you approve.

03Do you test a sandbox or production?

Either. A full-copy sandbox is usually preferred, because it mirrors production configuration and data without touching the live org. Where a finding can only be proven in production, we test it under written rules of engagement, read-only where possible, and never in a way that changes or exposes real customer data beyond proving the issue.

04What is AppExchange security review prep?

For ISVs building a managed package, it is the work that gets the package ready to pass Salesforce’s AppExchange security review on the first attempt. It includes a Salesforce Code Analyzer scan with the violations triaged, the Partner Security Portal source scan, a DAST scan (OWASP ZAP or Burp Suite) of any external endpoints, a manual review against the security review checklist, and a false-positive document for the items the automated tools got wrong. It is $5,200. Salesforce runs the official review and charges its own fee, $999 per attempt for a paid solution. We prepare the submission; we do not submit for you.

05Is this different from an automated Salesforce security scan?

Yes. A scan reads settings and flags deviations from a benchmark. This test proves what those settings expose, with accounts in each role and as a guest, and reviews the custom Apex a scanner cannot judge.

06How much does Salesforce penetration testing cost?

An org test is from $6,800 for one production org or full-copy sandbox, fixed before work begins, with a free retest. Two or more Experience Cloud sites, a larger codebase, or Agentforce and Einstein features in scope is $10,500. AppExchange security review prep for ISVs is $5,200. Several orgs or complex multi-business-unit sharing are quoted from the scope. Our Salesforce testing cost page explains what moves the price.

07What access do you need?

A read-only admin role so we can review the configuration, sharing model, and code, plus a test user in each role that matters so we can prove access across roles, and a guest or external test user for Experience Cloud. For an org test we agree the exact accounts during scoping; for AppExchange prep we need the managed package, a test org with it installed, and any external endpoint credentials.

08Do you test managed packages and Agentforce?

Yes. Installed and managed packages are reviewed for the permissions and access they hold in the org test. Agentforce and Einstein features, and larger custom codebases, are covered at the larger org-test tier, and a package you are shipping to the AppExchange is covered by the review-prep engagement.

Ready to test your defenses?

Talk to our team about scoping Salesforce penetration testing.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.