Airtable Security Review
A public Airtable share link needs no login, so anyone with the URL can view every table inside it. We test share links, tokens, base permissions and what automations do once triggered. CREST-certified testers, fixed price from £2,270 for a 2-day single-base scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Airtable’s own Share to web link creates a publicly accessible base or view that needs no Airtable account to open, restricted only by an optional password or email domain on paid plans.
A shared Airtable base is only as private as its weakest share link, token or automation
Airtable’s collaborator permission levels run from Read-only up through Commenter, Editor, Creator and Owner, set independently at the workspace and at each base, and Airtable is explicit that whichever of the two levels is higher is what a collaborator can actually do. A Creator on the workspace who is only added as an Editor on one base inside it still gets Creator rights there and on every other base in that workspace, so a restriction set at the base level can be overridden by whatever was granted higher up.
A personal access token is scoped by the API endpoints it can call and the specific bases or workspaces added as its resources, and Airtable states a token can never do more than the user who created it is already allowed to do, though an Enterprise Scale admin’s token can adopt the user role permissions of every workspace and base added to the organisation, including ones they were never a direct collaborator on. Tokens do not expire until they are manually regenerated or deleted, so a token issued for a since-departed integration, such as a Bubble app or another front end reading a base through the API, can carry on working long after anyone remembers it exists.
A base’s own share link decides how far its data travels: a public Share to web link needs no Airtable account to view, restricted only by an optional password or email domain on paid plans, and an automation adds a further route in that Airtable’s documentation is direct about, warning that anyone who has the URL for a webhook trigger can trigger the automation and run whatever create, update or delete actions it was configured with. We test every share link, token and automation trigger against what it actually exposes, not just the permission level it was meant to represent.
SCOPE
What we pen test on an Airtable base
Base and workspace permission levels: Owner, Creator, Editor, Commenter, Read-only
Airtable sets collaborator permissions separately at the workspace and at each base, running from Read-only up through Commenter, Editor, Creator and Owner, and always applies whichever of the two levels is higher. A Creator on the workspace who is only added as an Editor on one base still gets Creator rights on that base and every other base in the workspace. We test what every collaborator’s permission actually resolves to once both layers are combined, not just the level shown on the base they were invited to.
Field and table editing permissions on Team, Business and Enterprise Scale plans
An Owner or Creator can restrict who is allowed to edit the values in a specific field, or create and delete records in a table, on Team, Business and Enterprise Scale plans. Airtable’s own documentation is explicit that this does not control who can see information in the base, only who can change it, so a field locked against editing can still be read by anyone with base access. We test whether editing restrictions are being relied on to hide data they were never built to hide.
Personal access tokens: scopes, resources and admin token adoption
A personal access token is scoped by the API endpoints it can call and the specific bases or workspaces added as its resources, and Airtable states a token can never do more than the user who created it is already allowed to do. On Enterprise Scale, an admin’s token can adopt the user role permissions of every workspace and base added to the organisation, including ones the admin was never a direct collaborator on, and a token does not expire until it is manually regenerated or deleted. We test what every token in scope can actually reach against what its owner needs it to do.
Service accounts on Enterprise Scale
Enterprise Scale admins can create service accounts, non-user accounts with no logged-in experience, to run API integrations independently of any one employee, and grant them access to specific workspaces and bases from the admin panel. A service account can hold its own personal access tokens and can even be upgraded to super admin access. We test what every service account in scope was actually given access to, and whether an integration is still using access it no longer needs.
Base share links: invite links, public Share to web and view links
A base invite link grants internal access at a chosen permission level, a public Share to web link needs no Airtable account at all and exposes every table in the base to anyone who has the URL, and a view share link narrows that to a single filtered view. Password protection and an email domain restriction are only available on Team, Business and Enterprise Scale plans, so a base on a lower plan cannot add either control. We test every active share link and invite link in scope, including where a base sits behind a front end such as a Bubble app pulling records through the API.
Sync integrations: one-way data into a base, tiered by plan
Airtable Sync pulls data from an external source such as Google Drive, Jira or Salesforce into a base as a new synced table, always one way, so nothing written back in Airtable ever reaches the source system. Managing which sync integrations a workspace can use requires Owner permission, and higher-risk sources such as Salesforce, Jira Cloud and Emailed Data sit behind Business or Enterprise Scale plans rather than being available on every plan. We test what a synced table actually pulls in and who in the base can see it once it lands.
Automation triggers and the webhook URL that runs them
An automation’s incoming webhook trigger generates a unique URL, and Airtable’s own documentation warns that anyone who has that URL can trigger the automation, running whatever create, update or delete actions were configured for it. The same is true of triggers set to fire on a form submission or a record matching a condition, none of which require the person or system causing the trigger to be an Airtable collaborator at all. We test what every automation in scope is allowed to do once triggered, and how easily its trigger can be reached by someone outside the base.
Run a script automations versus the Scripting extension
A Run a script automation action executes in the background whenever its trigger fires, using whatever access was configured when the automation was built, while the Scripting extension runs in the foreground and, in Airtable’s own words, respects the permission level of the user running it, throwing an error if they lack the create or update rights the script calls for. We test which of the two a base relies on for a given piece of logic, since one enforces the current user’s permissions and the other does not.
API rate limits and monthly call caps
Airtable enforces 5 requests per second per base and 50 requests per second across all personal access tokens for a given user or service account, returning a 429 status and a 30 second cooldown once exceeded. Free and Team plans additionally cap monthly API calls at 1,000 and 100,000 respectively, while Business and Enterprise Scale plans have no equivalent monthly limit. We test how the integrations in scope behave once they hit these limits, not just what they do when every call succeeds.
Enterprise admin roles, SSO and organisation-wide security policies
Enterprise Scale organisations split admin access into Super Admin, Org Unit Admin, User Admin, Integration Admin and Brand Admin roles, each with a different slice of the admin panel, from configuring SSO and SCIM to managing groups or organisation branding. Only a Super Admin can force SSO sign-in, sign a user out of every session, or set organisation-wide security policies. We test who holds each admin role and whether SSO enforcement and session controls are actually switched on, not just available.
OUR PROCESS
Airtable Security Review: From Scope to Attestation
Base, Collaborator and Token Mapping
We catalogue every collaborator, permission level, personal access token, service account and share link across the base and its workspace.
Access and Sharing Testing
We test from accounts at every permission level in scope, checking what base and workspace permissions, field and table editing restrictions, and active share links actually allow.
Automation, Sync and API Testing
A CREST-certified tester tests every automation trigger and action, sync integration, and API call against the token or credential behind it.
Reporting and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Airtable pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Airtable Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Airtable For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Airtable Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Airtable base?
A login for each collaborator permission level you want tested, from Read-only up to Owner, is enough to start. Access to the developer hub to review personal access tokens and their scopes speeds up confirming what we find, though it is optional.
Will this touch our live data?
We test read-only against production by default. Where proving a create, update or delete finding needs real records, we agree a sandbox base or specific test data with you first, and anything we create during testing is documented and removed afterwards.
Does it matter which Airtable plan we’re on?
Yes. Field and table editing permissions and several sync integrations are only available from the Team plan upward, and features such as service accounts and the full enterprise admin panel are Enterprise Scale only, so we confirm your plan and what it actually enables before scoping.
Does Airtable have a policy for customers testing their own base?
We confirm Airtable’s current terms with you during scoping before testing starts.
What is out of scope?
Airtable’s own platform and infrastructure, other customers’ bases and workspaces, and denial-of-service testing are all out of scope. We test the base, collaborators, tokens, share links, automations and sync integrations you have built.
How long does an Airtable base test take?
A single base sits in our 2-day single-base scope, rising with the number of tables, automations, sync integrations and collaborator tiers in scope. We confirm the exact day count once we have seen the base.
Do you need our automation scripts or just a running base?
A running base with test accounts in every relevant permission level is enough to start. Access to automation configurations and any Run a script or Scripting extension code speeds up root-causing anything we find, but it is not required.
Are your testers CREST certified?
Yes. Every Airtable engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Airtable base
A public Airtable share link needs no login, so anyone with the URL can view every table inside it. We test share links, tokens, base permissions and what automations do once triggered. CREST-certified testers, fixed price from £2,270 for a 2-day single-base scope, quoted within 24 hours.



