CircleCI Security Review
CircleCI’s secrets masking does not hide a value under four characters, or one that is just true or false. We test your contexts, secrets exposure, fork pull request access and API tokens. CREST-certified testers, fixed price from £2,880 for a 2-day single-organization scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CircleCI’s own secrets masking documentation states that a value under 4 characters, or one equal to true, True, false or False, is not masked in your job output at all.
Why CircleCI security comes down to contexts, masking limits and fork PR access
CircleCI’s own contexts documentation sets out three restriction types, security groups, project restrictions and expression restrictions, and states that a context carrying both a security group and a project restriction is only available when both checks pass: group membership never bypasses a project allowlist, and a listed project never bypasses a security group. The same category of question applies on other CI platforms; our GitHub Actions security review covers the equivalent environment and secret scoping question there. We map every context’s actual combination of restrictions against which pipelines and people the business meant to grant it to.
Masking has documented limits. The same contexts documentation states secrets masking will not obscure an environment variable’s value in job output when that value is under 4 characters or equal to true, True, false or False, and CircleCI’s secure secrets handling guidance adds that a shell invoked with -x or -o xtrace can still log an unmasked secret, that masking does not reach values printed to test results or artifacts, and that a value remains visible to anyone using SSH access to debug a running build. We test which of your context and project secrets fall inside those gaps.
OIDC tokens, issued as CIRCLE_OIDC_TOKEN and CIRCLE_OIDC_TOKEN_V2 for authenticating to cloud providers without long-lived credentials, are only generated for forked-repository builds if the Pass secrets to builds from forked pull requests project setting is switched on, per CircleCI’s OpenID Connect documentation. Personal API tokens created manually through the web app carry full read and write permissions by default, project tokens carry one of three fixed scopes, and CircleCI’s orbs documentation confirms an organisation administrator needs to explicitly opt in before an uncertified Partner or Community orb can run in a pipeline at all. We test whether each of these gates is actually switched to the setting the business intended.
SCOPE
What we review in a CircleCI organization
Context Restrictions: How They Combine
CircleCI’s own documentation sets out three restriction types on a context, security groups, project restrictions and expression restrictions, and states plainly that a context with both a security group and a project restriction is available only when both checks pass, since group membership never bypasses a project allowlist and a listed project never bypasses a security group. We test whether every context’s actual combination of restrictions matches which pipelines and people the business meant to grant it to.
Secrets Masking Limits: Short Values and Boolean Strings
CircleCI’s documentation states secrets masking will not obscure an environment variable’s value in job output when that value is under 4 characters or equal to true, True, false or False. We test which of your context and project secrets fall under that threshold or match one of those strings, since those are the values a masked build log will still print in the clear.
What Secrets Masking Does Not Cover
The same documentation is explicit that masking only prevents values appearing in job output, and does not stop a shell invoked with -x or -o xtrace from logging an unmasked secret, does not mask values that appear in test results or artifacts, and does not stop a value being read by someone using SSH access to debug a running build. We test whether your pipeline’s shell scripts, artifacts or SSH debug access expose a secret the masked console output never would.
OIDC Tokens and Forked Pull Requests
CircleCI issues CIRCLE_OIDC_TOKEN and CIRCLE_OIDC_TOKEN_V2 environment variables to jobs for authenticating to cloud providers without long-lived credentials, and its own documentation states these tokens are only generated for forked-repository builds if the Pass secrets to builds from forked pull requests project setting is enabled. We test whether that setting is switched on only where the project genuinely needs it, since enabling it hands a fork’s build the same OIDC and secret access as a build from the base repository.
OIDC Audience and Issuer Scoping
Configuring OIDC with an external identity provider such as GCP Workload Identity Federation means setting the audience to your CircleCI organization ID and the issuer to https://oidc.circleci.com/org/
Personal API Tokens: Full Read and Write by Default
A personal API token created manually through the CircleCI web app grants full read and write permissions and only expires on the date you set when creating it, while tokens issued through OAuth 2.0 Dynamic Client Registration are scoped to Read, Write or Admin instead. We test which personal tokens are still live, whether any manually-created token has no expiry set, and whether its holder still needs that level of access.
Project API Token Scopes
Project API tokens carry one of three scopes, Status for read access to build statuses such as embedded status badges, Read Only for read access to the v1 project API, and Admin for read and write access to the v1 project API, and CircleCI’s documentation notes a token cannot be edited after creation, only deleted and recreated. We test whether every project token’s actual scope matches the integration it was issued for, particularly any Admin-scoped token issued for a task that only ever needed Status.
Command-Line Secret Exposure
CircleCI’s own secure secrets handling guidance warns that a secret passed as a command parameter can be written into a shell history file, that any user on the same system can view a running process’s arguments with a tool as simple as ps -ef, and that command-line tools commonly persist secrets unencrypted on disk in home directory files. We test whether your build steps pass secrets as command-line arguments anywhere these exposure paths apply, rather than through environment variables CircleCI itself masks.
Self-Hosted Runners Move the Trust Boundary
Self-hosted runners execute jobs on infrastructure you provide, and CircleCI’s own documentation lists static IP restrictions, IAM permissions when hosted in AWS, operating system monitoring and connections to private networks among the reasons customers choose them for privileged or limited-access workloads. We confirm during scoping whether your pipelines use CircleCI’s cloud infrastructure, self-hosted runners, or both, and test the boundary and host controls each model actually gives you.
Uncertified Orbs Require an Admin Opt-In
Orbs in the registry carry one of three designations, Certified (written and tested by the CircleCI team), Partner (written by technology partners) or Community (written by the community), and CircleCI’s own documentation states an organisation administrator needs to explicitly opt in to allow uncertified, meaning Partner or Community, orbs on the Org > Security page before they can be used at all. We test whether that opt-in is switched on only where the organisation actually depends on an uncertified orb, and which uncertified orbs are calling into pipelines as a result.
OUR PROCESS
CircleCI Security Review: From Scope to Attestation
Scope and Access
We agree which CircleCI organization, projects and contexts are in scope, plus logins or tokens matching each access tier and any OIDC or self-hosted runner configuration in use.
Context and Token Mapping
We map every context’s security group, project and expression restrictions, every personal and project API token’s actual scope, and how OIDC and orb access are configured.
Manual Testing
A CREST-certified tester manually tests context restriction boundaries, secrets masking gaps, forked pull request access, token privilege and uncertified orb usage, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST CircleCI pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent CircleCI Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test CircleCI For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From CircleCI Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our CircleCI organization?
We need read access to your organization’s contexts, security groups and project settings, or logins matching each access tier you want tested, plus any personal, project or OIDC-issuing configuration in scope. Read access to your pipeline configuration files speeds up scoping but isn’t required to start.
Will testing touch our live builds?
We review configuration, permissions and token scope rather than running or modifying your production pipelines. Where confirming a finding needs a real pipeline run, such as a forked pull request test, we agree the exact scope with you first.
Do you test CircleCI’s own platform or just our organization?
No. We never test CircleCI’s own infrastructure or source code. We test how your organization configures contexts, security groups, project settings, API tokens, OIDC and orb usage.
What is out of scope for a single-organization review?
CircleCI’s own infrastructure, other organizations on the same CircleCI account structure, and denial-of-service testing are out of scope here. A self-hosted runner’s underlying host is scoped and quoted separately as infrastructure testing if you want it included.
Does CircleCI have a policy on customer penetration testing?
We confirm CircleCI’s current terms for testing your own organization and pipelines during scoping, and test only within whatever authorisation that process requires.
How is this different from a GitHub Actions review?
The underlying questions, secret scoping, forked pull request access and token privilege, are the same, but the mechanisms differ: CircleCI uses contexts and security groups where GitHub Actions uses environments and repository permissions. We test to whichever platform’s actual configuration your pipelines run on.
How long does a CircleCI security review take?
A single organization with a typical number of contexts, projects and API tokens sits in our 2-day single-organization scope, with a report landing around 5 working days after kickoff. An organization with many contexts, self-hosted runners or extensive orb usage extends that scope.
Are your testers CREST certified?
Yes. Every CircleCI engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your CircleCI organization
CircleCI’s secrets masking does not hide a value under four characters, or one that is just true or false. We test your contexts, secrets exposure, fork pull request access and API tokens. CREST-certified testers, fixed price from £2,880 for a 2-day single-organization scope, quoted within 24 hours.



