Couchbase Security Review
Self-managed Couchbase leaves traffic between cluster nodes unencrypted until you switch on node-to-node encryption. We test authentication, roles, network encryption, and Capella’s access lists and API key scope. CREST-certified testers, fixed price from £2,620 for a 2-day single-cluster scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Node-to-node encryption is disabled by default in Couchbase Server. Once it is switched on, the cluster encryption level then decides whether only management traffic or all inter-node data is protected, right up to a strict setting that permits nothing unencrypted except loopback traffic on a single node.
Why Couchbase security comes down to roles, network encryption and what Capella exposes
Couchbase Server’s own documentation on roles is explicit that some roles can be scoped down to a specific collection, several collections, a whole scope, or every bucket in the cluster, so the same Data Writer role can mean write access to one bucket for one user and every bucket for another. Couchbase’s documentation on authentication domains adds a further layer: every login is checked against local users first and external users second, and external authentication can be delegated to LDAP, SAML or PAM, so a role that looks tightly scoped in the local domain can be widened again by a group mapping nobody remembers configuring. We test what a given account, local or external, can actually reach once every role, group mapping and scope boundary is added together.
The Full Administrator account is not a shipped default: Couchbase’s documentation on usernames and passwords confirms that username and password are set by whoever initialises the cluster, though Couchbase Web Console still remains reachable over both HTTP and HTTPS unless an administrator explicitly disables one, since disableUIOverHttp and disableUIOverHttps both default to false. Encryption between cluster nodes follows a similar pattern: Couchbase’s guide to node-to-node encryption confirms it is disabled by default, and client connections can independently be made optional or required, with a minimum accepted TLS version that defaults to TLS 1.2. We test which of these settings a deployment has actually applied, rather than assuming the strictest option is live.
Couchbase Capella moves the same questions into the console and the Management API. Its Allowed IP documentation confirms Capella denies any connection attempt from an address that is not on a cluster’s Allowed IP list, which holds up to 75 entries, while cluster access credentials for reading and writing bucket data are kept separate from organisation and project roles, which instead govern the Capella console and Management API. An Organisation Owner automatically holds the Project Owner role for every project in the organisation, and a Management API key inherits whichever organisation and project roles it was created with, so we map every credential type, whichever layer it sits in, against what it can actually reach. For the wider family of cache and streaming platforms this scope splits from, see our NoSQL, cache and streaming security review, and our MongoDB and Atlas security review for the closest documented-database comparison.
SCOPE
What we review in a Couchbase deployment
Role-Based Access Control Scope
Couchbase’s own documentation confirms that some roles can be scoped all the way down to a single collection, several collections, a whole scope, or every bucket in the cluster, so the same named role can mean very different access depending on how narrowly it was granted. We test what each role granted in your cluster actually resolves to at the bucket, scope and collection level, not just the name on the account.
Local and External Authentication Domains
Couchbase Server checks every login against the local authentication domain first and the external domain second, and external authentication can be delegated to LDAP, SAML or PAM rather than a password stored on the cluster. We test which domain each account actually authenticates through, and whether an LDAP group mapping or SAML attribute mapping grants roles nobody intended when it was set up.
Cluster Initialisation and Administrator Credentials
The Full Administrator username and password are set by whoever initialises the cluster rather than shipped as a fixed default, and that account is not listed among the users and groups the Full Administrator later manages. We test how the initial administrator credential was provisioned and rotated, and whether the account it created still holds privileges beyond what day-to-day administration needs.
Couchbase Web Console HTTP and HTTPS Access
Couchbase Web Console can be reached over both HTTP and HTTPS by default, since the settings that disable each protocol, disableUIOverHttp and disableUIOverHttps, both default to false until an administrator changes them. We test which protocols the console actually accepts on the deployment in scope, and whether an unencrypted path to an administrative interface is still open.
Node-to-Node Encryption and Cluster Encryption Level
Node-to-node encryption is disabled by default in Couchbase Server, and the cluster encryption level, which decides whether only management traffic or all inter-node data is protected, only becomes configurable once encryption itself has been switched on. We test whether node-to-node encryption is enabled at all, and which of the control, all or strict levels the cluster is actually running once it is.
Client Connection TLS and Minimum Version
Encryption for client connections to Couchbase can be made optional or required, and the minimum TLS version the cluster accepts defaults to TLS 1.2. We test what a client connecting from outside the cluster is actually permitted to negotiate, rather than assuming the strictest configuration is enforced.
Capella Allowed IP List
Couchbase Capella denies any connection attempt from an address that is not on a cluster’s Allowed IP list, which holds up to 75 entries and can only be viewed or changed by an Organisation Owner, Project Owner or Cluster Manager. We test what is actually on the list against what the deployment needs to reach it, and whether a wide or temporary entry added for a migration was ever removed.
Capella Cluster Access Credentials
Capella deliberately separates cluster access credentials, which read and write bucket data through the Couchbase SDK, from organisation and project roles, which govern the Capella console and Management API instead. We test whether an application’s cluster access credential holds only the access levels it needs, independently of whatever organisation or project role the person who created it happens to hold.
Capella Organisation and Project Roles
An Organisation Owner in Capella automatically holds the Project Owner role for every project in the organisation, whether or not they were ever added to that project directly, and Capella documents this inheritance as intentional. We map every organisation and project role against who actually needs that reach, and flag an account whose organisation-level access was granted for one project but never scoped back down.
Capella Management API Keys
A Capella Management API key inherits whichever organisation roles and, where relevant, project roles it was created with, carries its own expiration date, and is associated with its own allowed IP address list, separately from the cluster’s Allowed IP list. We test what an API key found in a script or CI pipeline is actually scoped to manage, and whether it has outlived the project or task it was created for.
OUR PROCESS
Couchbase Security Review: From Scope to Attestation
Scope and Access
We agree which Couchbase Server clusters, buckets and Capella projects are in scope, plus a local or external user account for every privilege tier you want tested and, where relevant, a Capella organisation or project role to review configuration.
Role and Access Mapping
We map every role, authentication domain and access credential against who or what actually needs that level of access, on self-managed clusters and in Capella.
Manual Testing
A CREST-certified tester manually tests authentication and authorisation, network and node-to-node encryption, Capella’s Allowed IP list and Management API key scope, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Couchbase pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Couchbase Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Couchbase For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Couchbase Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Couchbase deployment?
We need at least one authenticated account for every privilege tier in scope, from an ordinary application-level user through to a role that can query user, group and role configuration on a self-managed cluster, or the equivalent organisation or project role in Capella. Read access to Capella’s organisation and project role assignments speeds up the review, though we can test with bucket-level cluster access credentials alone.
Will testing touch live data?
We test the buckets, scopes and collections you nominate, working against your actual roles, access lists and application queries rather than a copy, so we agree exclusions such as destructive operations or production replica targets before testing starts. We do not export real customer data or run destructive tests without that agreement in writing.
Do you test self-managed Couchbase Server and Capella the same way?
The underlying questions are the same: who can authenticate, what role or access credential they hold, and what the network actually exposes. What differs is the boundary, since Capella manages the host, the underlying infrastructure and features such as node-to-node encryption and auditing, so we confirm during scoping exactly what you control on your Capella tier and test to that boundary.
What is out of scope for a single-cluster Couchbase review?
We never test Couchbase’s own source code, the underlying host or hypervisor of a managed Capella cluster, or Capella’s shared infrastructure, and a separately hosted application that happens to connect to the database is scoped and quoted on its own. We test the authentication, roles, network configuration, access lists and application-level query handling for the cluster you nominate.
Does Couchbase have a policy on customer penetration testing?
Couchbase publishes security and shared-responsibility documentation for Capella covering areas such as auditing and access control policy. We confirm Couchbase’s current terms for testing your own Capella project or self-managed cluster during scoping and test within them.
Does Capella log administrative and access events?
Capella auditing is turned off by default and has to be explicitly enabled, after which a default subset of events is recorded and a further set of filterable events can be switched on individually. We test whether auditing is enabled and capturing the events, such as role and user changes, that would show unauthorised access.
How long does a Couchbase security review take?
A single Couchbase Server cluster or Capella project, with a small number of buckets and a limited set of roles, sits in our 2-day single-cluster scope, with a report typically landing around 5 working days after kickoff. More buckets, multiple Capella projects, or a mix of self-managed and Capella deployments moves into a larger scope with more testing days.
Are your testers CREST certified?
Yes. Every Couchbase engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Couchbase review
Self-managed Couchbase leaves traffic between cluster nodes unencrypted until you switch on node-to-node encryption. We test authentication, roles, network encryption, and Capella’s access lists and API key scope. CREST-certified testers, fixed price from £2,620 for a 2-day single-cluster scope, quoted within 24 hours.



