Application: Customer Portal

Customer Portal Penetration Testing

CREST-accredited penetration testing for customer portals, internal admin dashboards and partner portals built on the same backend. We test whether an invited user, a delegated administrator, your own support staff or a reseller can reach another organisation’s documents, exports or account data. Fixed quote in 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
RBAC
Role & Permission Testing
ISO 27001
Evidence-Ready Reports
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
3

portals we typically test together on one engagement: the customer-facing portal, your internal admin dashboard, and any partner or reseller portal built on the same backend, because a boundary in one often depends on a check in another.

Access Boundaries Are the Test Your Customers Care About

Customer-facing access. Your customer portal, client portal or self-service dashboard is where an invited user becomes an organisation member, owns documents, delegates admin rights to colleagues and exports their own data. We test whether an invite, a role change or an export request can reach further than the organisation that issued it.

Internal admin dashboards. Back-office portals and operations consoles carry the widest permissions in your stack, and in our experience they are the least-tested part of the product. We test admin action abuse, whether impersonation features are logged and bounded, whether audit trails record who did what and when, and support permissions that reach further into customer data than a ticket needs.

Partner and reseller portals. Channel, reseller and supplier portals add a second account hierarchy on top of your customers’ own. We test whether one partner can see another partner’s accounts, whether delegated permissions follow that hierarchy correctly, and whether a partner’s access survives an account change it should not.

Who we test for. SaaS vendors, membership organisations and service providers running a customer portal alongside an internal admin dashboard, a partner portal, or both on the same backend. If your portal is itself a multi-tenant SaaS product, see our multi-tenant SaaS penetration testing page for tenant isolation testing. See our SquareOne case study, covering two government web portals tested by our CREST team, and our SaaS penetration testing page for the wider picture.

SCOPE

What We Test in a Customer Portal

INVITE

Invitations & Account Recovery

Organisation invites, sign-up links, password resets and account recovery flows. Whether an invite token can be reused, guessed or replayed, and whether a reset link can put someone into the wrong organisation.

ROLES

Role-Based Access Control

The role and permission matrix behind every screen and API call, not just the menu items a role can see. Whether a lower-privileged role can reach an action reserved for another, in any portal.

DOCS

Document Ownership & File Access

Which documents, folders and shared files a user, an invited colleague or a partner can reach by changing an ID, guessing a share link or calling the file API directly, and whether an upload can be turned into execution.

EXPORT

Data Exports & Scheduled Reports

CSV, PDF and API exports run on demand or on a schedule. Whether an export can be scoped to the wrong organisation, and whether scheduled reports and webhooks lose the account context they started with.

ADMIN

Internal Admin Dashboards & Support Access

Back-office portals and operations consoles carry your widest permissions. We test admin action abuse, impersonation features, whether audit trails record who did what and when, and support permissions that reach further than a ticket needs.

PARTNER

Partner, Reseller & Channel Portals

Reseller, channel and supplier portals add a second account hierarchy on top of your customers’ own. Whether one partner can see another partner’s accounts, and whether delegated permissions follow the hierarchy correctly.

APIS

Portal & Admin APIs

Broken object-level authorisation across the customer, admin and partner APIs behind every portal screen, including bulk, export and integration endpoints scoped to the wrong account.

OUR PROCESS

From Scope to Attestation in 4-6 Weeks

01

Scoping Call

30-minute call to map your customer portal, admin dashboard and any partner portal, plus the roles and objects each one touches. Fixed-price quote within 24 hours.

02

Test Accounts

You provide at least two organisation accounts in staging, each with an invited user and a delegated admin, plus access to your internal admin dashboard and any partner portal in scope.

03

Active Testing

3-15 days of hands-on testing by CREST-certified UK-based pen testers, crossing every portal, role and organisation boundary. Live findings in your client portal.

04

Report & Retest

CVSS-scored report with a role and portal matrix, walkthrough call, free retest and a letter of attestation for customers and auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST customer portal pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Aligned to Every Framework

Findings map to specific control references in each framework, so your audit team submits the report directly without translation work.

SOC 2

Evidence for the evaluations your auditor reviews under CC4.1.

ISO 27001

Annex A 8.8 technical vulnerability management, once you declare that control applicable.

OWASP ASVS

Access control and session management findings mapped to the Application Security Verification Standard.

OWASP API Top 10

Broken object-level authorisation findings across portal and admin APIs mapped by category.

UK GDPR

Article 32(1)(d) evidence that you regularly test the effectiveness of your security measures.

Customer Questionnaires

An independent report you can attach to enterprise and partner security questionnaires.

PRICING

Transparent Customer Portal Penetration Testing Pricing

Pricing depends on the number of roles, portals and integrations in scope, from a single customer portal to a customer portal, admin dashboard and partner portal tested together. The day count flexes; the included deliverables stay the same across all engagements.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
Free retests, no time limit
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-min walkthrough call
Letter of attestation
SMALL / SMB
£5,000–£8,000
Depends on app complexity

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£18,000–£35,000
Depends on app complexity

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Customer Portal Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What is customer portal penetration testing?

Testing whether an invited user, a delegated administrator, your own support staff or a partner can reach documents, exports or account data that belong to another organisation. We cross every portal, role and boundary through the user interface, the API, file storage and exports, and report each path that leaks.

Do you test our internal admin dashboard as well as the customer-facing portal?

Yes. Back-office portals and operations consoles usually carry your widest permissions and, in our experience, are the least-tested part of the product. We test admin action abuse, impersonation features, whether audit trails record who did what and when, and support permissions that reach further into customer data than a ticket needs.

Can you test our partner or reseller portal in the same engagement?

Yes. Reseller, channel and supplier portals add a second account hierarchy on top of your customers’ own. We test whether one partner can see another partner’s accounts and whether delegated permissions follow that hierarchy correctly.

Can an invitation or password-reset link put someone into the wrong organisation?

That is one of the first things we check. We test whether invite and reset tokens can be reused, guessed, replayed or accepted after expiry, and whether accepting one ever places a user in an organisation they were not invited to.

Do you test role-based access control across the portal, admin dashboard and partner portal?

Yes. We map the role and permission matrix behind every screen and API call, not just the menu items a role can see, and test whether a lower-privileged role, in any of the three portals, can reach an action reserved for another.

Can you test file uploads and document sharing, including share links?

Yes. We test which documents, folders and shared files a user, an invited colleague or a partner can reach by changing an ID, guessing a share link, calling the file API directly, or using an upload to get a file executed rather than stored.

We’re a SaaS vendor with a customer portal built on Supabase, can you test our role and account boundaries ahead of a SOC 2 audit?

Yes. We test Supabase and PostgreSQL row-level security policies alongside the portal’s own roles; see our Supabase page. SOC 2 lists penetration testing as one example of an evaluation under CC4.1, not a requirement, but auditors commonly expect a recent third-party test. If your portal is itself multi-tenant SaaS, see our multi-tenant SaaS penetration testing page too.

What’s in the report?

Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.

Do you sign NDAs?

Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.

How quickly can you start?

From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.

Are your testers UK-based and what certifications do they hold?

Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get my customer portal pen test scope

Tell us how many portals, roles and organisations you run, whether that’s a customer portal on its own or alongside an admin dashboard and a partner portal. A CREST-certified pen tester will contact you within one business day with a fixed price.