TECHNOLOGIES: CONFLUENCE

Confluence Security Review

Confluence access is set in three separate layers, and a single public link can bypass page restrictions. We review your spaces, restrictions, public access, guests and installed apps. CREST-certified testers, fixed price from £2,840 for a 2-day single-site scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Confluence Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
3

Confluence enforces three layers of permission, global, space and content restrictions, and each layer is configured separately from the other two.

Why Confluence access comes down to three permission layers, not one

Atlassian’s own documentation sets out three levels of permission in Confluence: global permissions, space permissions and content restrictions, with content open to viewing and editing by default until someone restricts it, and a content item never able to hold greater access than the space or page it sits inside. Confluence permissions are also additive, so a person who belongs to two groups gets whichever group’s access is wider, which lets space access expand quietly as group membership changes.

A view restriction on a page cascades down to every child page nested under it, but an edit restriction does not, unless it is set at the space level, where it then applies to the whole space. Atlassian is explicit that a public link ignores every view restriction on the content it points to, so a page nested under a locked-down parent can still be reached in full through its own public link once one has been turned on for it.

Marketplace apps add another surface again, since a Forge or Connect app is granted its own scope into your site the moment it is installed, and a common category of app connects a client’s Microsoft 365 tenant so SharePoint or OneDrive files can be attached to Confluence pages directly. Guest accounts, invited for external collaboration into a single space, start with a narrower default permission set than a licensed user, and an API token can be scoped to limit exactly what a script or integration can reach. We test the permissions, restrictions, apps and tokens you have actually configured on your Confluence Cloud or Data Center site, never Atlassian’s underlying platform.

SCOPE

What we review in a Confluence site

CF-01

Global Permissions and Site-Wide Settings

Global permissions cover site-wide settings such as whether new users get an automatic personal space, who can create a new space and automatically become its admin, and who can view other licensed users’ profiles across the instance. We test which groups hold these instance-wide grants and whether they still match who should be able to act across your whole site rather than one space.

CF-02

Space Roles and Legacy Space Permissions

Confluence grants space access through four default roles, Admin, Manager, Collaborator and Viewer, each carrying its own fixed set of permissions, or through legacy space permissions that map onto the same underlying actions, and permissions are additive across every group a person belongs to. We test whether a role or permission grant in an in-scope space still matches who should hold it, and check for wider access created by overlapping group membership nobody has reviewed.

CF-03

Page and Blog Restrictions on View and Edit

Confluence content is open to viewing and editing by default until someone restricts either action to specific people or groups, and a page can never be given greater access than the space or parent item it sits inside. We test which pages and blog posts carry a restriction, whether the people or groups listed on it are still correct, and whether a page your team assumes is locked down actually is.

CF-04

How Restrictions Inherit Between Pages

A view restriction added to a parent page or folder is inherited by every child page nested underneath it, but an edit restriction is not passed down the same way, unless it is applied at the space level, where it then covers every page in that space. We test how restrictions actually behave once content has been moved, copied or nested, rather than assuming a locked parent protects everything beneath it.

CF-05

Anonymous Access at Instance and Space Level

Anonymous access is controlled at three levels: a Confluence-level toggle only a Confluence admin can enable, a space-level setting that starts switched off for every new space even when the instance-level toggle is on, and content restrictions that apply to anonymous users the same way they apply to logged-in users. We test each level for a public grant that has outlived the reason it was switched on, including a space made public for a single project and never reset.

CF-06

Public Links That Bypass Restrictions

A public link lets anyone on the internet view a read-only version of a page, blog post or whiteboard, and Atlassian’s own documentation confirms that a public link ignores every view restriction on the content it points to, including a restriction inherited from a locked-down parent. We test for active public links on content your team believes is restricted, and for who still has permission to turn a public link on in the first place.

CF-07

Attachments and File Permissions

An attachment takes on the view and edit access of the page it is attached to, and adding an attachment is one of the specific space permissions a space admin can grant or withhold on its own, separately from page creation or commenting rights. We test what a lower-privilege account, including a guest, can attach to a page and retrieve, and whether an attachment stays reachable after the page’s restriction changes.

CF-08

Marketplace Apps and Forge or Connect Scopes

A Forge app declares the scopes it needs in its manifest and a Connect app declares an equivalent scope set in its descriptor, with Confluence’s own OAuth 2.0 scopes ranging from a read-only content summary through to write:confluence-space and manage:confluence-configuration, which can change settings for the whole instance. A common Marketplace category connects a client’s Microsoft 365 tenant so SharePoint or OneDrive files can be attached to Confluence pages directly, and we test whether an installed app’s granted scope reaches further than the function it was actually installed for.

CF-09

Guest Accounts for External Collaboration

A guest is Atlassian’s term for an external collaborator invited into a single space rather than given a full Confluence licence, and by default a guest can only view pages, add pages, comment and add attachments, though a space admin can extend a guest’s access to most other space permissions except Space admin, Export space and Restrictions. We test whether a guest account can reach a second space, and whether a guest’s actual permissions match the narrower default Atlassian intends.

CF-10

Cloud and Data Center Deployment Exposure

Confluence Cloud runs on Atlassian’s shared multi-tenant infrastructure, where customer testing is limited to your own instance under Atlassian’s published rules, while Confluence Data Center runs on infrastructure your own organisation controls, where the surrounding servers, network and access configuration are also in scope. We test to the deployment you actually run and confirm it, along with any shared boundaries, before scoping starts, never Atlassian’s own Cloud platform.

OUR PROCESS

Atlassian Confluence Security Review: From Scope to Attestation

01

Scope and Space Access

We agree which spaces, page trees and Marketplace apps are in scope, plus a role account for every access tier including Viewer, Collaborator and Admin, a guest account if external collaboration is in scope, and any API token or app credentials we need.

02

Permission and Restriction Mapping

We map global permissions, each in-scope space’s roles and legacy permissions, and page or blog restrictions against who should actually hold that access, and catalogue installed Marketplace apps and the scopes they have been granted.

03

Manual Testing

A CREST-certified tester manually tests space and content permissions, restriction inheritance, anonymous and public access, attachment handling, guest account boundaries, and API token or app scope misuse, chaining findings where they compound.

04

Report and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Confluence pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Atlassian Confluence Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,840–£4,390
2 to 4 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,780–£9,520
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Atlassian Confluence Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Confluence site?

We need at least one authenticated account for every access tier in scope, typically a Viewer, a Collaborator and a space or site admin account if you want role and configuration review alongside the manual test. If a guest workflow or a space with anonymous access is in scope we also test those paths using the same restricted access a real guest or member of the public would have.

Will testing touch live data?

We test the spaces and pages you nominate, working against your real content structures rather than a copy, so we agree exclusions such as production automation, outbound integrations or notification triggers before testing starts. We do not run destructive tests, bulk-delete content or export real data without that agreement in writing.

How long does a Confluence security review take?

A single site with a small number of spaces in scope sits in our 2-day single-site scope, with a report typically landing around 5 working days after kickoff. A site with more spaces, guest workflows or Marketplace apps in scope moves into a larger scope with more testing days.

Do you test Confluence Cloud and Confluence Data Center the same way?

The testing questions are the same: space and page permissions, restriction inheritance, anonymous and public access, attachments, guests and app scopes. The boundary of what we can touch is not the same, since on Confluence Cloud we test to Atlassian’s published rules for customer security assessments, while on Confluence Data Center your own infrastructure, network and access controls around the application are also in scope.

What is out of scope for a single-site Confluence test?

We never test Atlassian’s own Cloud platform, shared infrastructure or another customer’s instance, and on Confluence Cloud we do not run denial-of-service, port or protocol flooding, or non-technical attacks such as social engineering, in line with Atlassian’s published rules. We test the spaces, permissions, restrictions, Marketplace apps and public access configured on your site, and a separate connected system such as your identity provider or Microsoft 365 tenant is scoped and quoted separately.

Does Atlassian have a customer security testing policy we need to follow?

Yes. Confluence is one of the Cloud Products listed in Atlassian’s published Security Test Rules, which let customers run security assessments against their own instance without prior approval, provided testing stays inside that instance, any scanner output is triaged into a reproducible proof of concept before being reported, and prohibited activities such as denial-of-service and social engineering are excluded. We confirm the current version of these rules with you during scoping and test to them exactly.

Do you test installed Marketplace apps?

We review the scopes granted to installed Forge and Connect apps, including any app that connects Confluence to SharePoint, OneDrive or another external system, as part of the standard engagement. Testing the third-party app’s own code or infrastructure is out of scope, since Atlassian’s shared responsibility model makes the underlying security of a Marketplace app the developer’s responsibility, not ours or the platform’s.

Are your testers CREST certified?

Yes. Every Confluence engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Confluence review

Confluence access is set in three separate layers, and a single public link can bypass page restrictions. We review your spaces, restrictions, public access, guests and installed apps. CREST-certified testers, fixed price from £2,840 for a 2-day single-site scope, quoted within 24 hours.