Claris FileMaker Security Review
A FileMaker solution only restricts what its privilege sets and extended privileges are configured to restrict. We test accounts, privilege sets, extended privileges and container storage against what your solution should allow. CREST-certified testers, fixed price from £2,740 for a 2-day single-system scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Every privilege set in a FileMaker file decides which extended privileges, records, layouts, value lists and scripts an account can reach, and FileMaker enforces exactly what has been configured, nothing more and nothing less.
Why FileMaker access comes down to privilege sets and what you have switched on
Claris’s own documentation sets out how FileMaker access is built in layers: every file authenticates users through accounts, which are then assigned a privilege set, and every new file starts with three predefined sets, Full Access, Data Entry Only and Read-Only Access, where Full Access switches on every extended privilege except the sleep re-authentication timer. A custom privilege set narrows this down further, but only where someone has actually turned Full Access off and rebuilt the record, layout, value list and script access it grants.
How a file can be reached at all is a separate, additional layer again. Claris documents ten extended privileges, from fmwebdirect for browser access through FileMaker WebDirect and fmxdbc for ODBC or JDBC connections, to fmrest for the FileMaker Data API and fmodata for OData, and each one has to be switched on for the privilege set attempting to use it. A privilege set can look tightly scoped on records and layouts while still carrying an extended privilege nobody remembers enabling, which is exactly the gap between what a developer intended and what a client, script or API call can actually reach.
Where the solution is hosted changes what falls to you to secure. On FileMaker Server, the default SSL certificate is signed by Claris and does not verify your server name, and is intended only for test purposes, so a production deployment needs a certificate you have requested and installed yourself. FileMaker Cloud is managed by Claris on AWS infrastructure instead, which moves patching and the underlying operating system out of scope but leaves your accounts, privilege sets, extended privileges and container storage exactly as much yours to secure as on a self-hosted deployment. For an estate that mixes FileMaker with other database engines, see our wider database security review.
SCOPE
What we test in a FileMaker solution
Accounts and the Admin and Guest Defaults
Every new FileMaker file starts with two accounts, Admin and Guest, and Claris’s own guidance treats a separate account per user as the security baseline rather than a shared login. We test whether the default Admin and Guest accounts have been renamed, disabled or left active with predictable credentials, and whether every real user authenticates as themselves rather than through a shared account.
Predefined Privilege Sets and the Full Access Default
Every new file ships with three fixed privilege sets, Full Access, Data Entry Only and Read-Only Access, and Full Access is the only one where every extended privilege is switched on except the sleep re-authentication timer. We test how far a custom privilege set has actually narrowed access from Full Access, and whether an account meant to be Data Entry Only or Read-Only can still reach Full Access features because the predefined set was never duplicated and cut down.
Record, Layout, Value List and Script Access
A privilege set can set record access to Yes, No or Limited, with Limited enforced by a calculation checked against every record on that table, and a user without view access simply sees a placeholder in place of the field data. We test whether Limited calculations actually isolate the records they are meant to, and whether layout, value list and script privileges are set to match the record access around them rather than left at a broader default.
Extended Privileges for WebDirect, Network and ODBC/JDBC Access
Claris documents fmwebdirect, fmapp and fmxdbc as the extended privileges controlling access via FileMaker WebDirect in a browser, via FileMaker Pro or Go over the network, and as an ODBC or JDBC data source, and each has to be switched on for the privilege set attempting to use it. We test which of these routes into your solution are actually enabled, and whether an account can reach data through ODBC or JDBC that it was never given the extended privilege to use through the normal interface.
FileMaker Data API and OData Access
fmrest and fmodata are the extended privileges that let a privilege set reach a file through the FileMaker Data API or an OData-capable client, and Claris’s own Admin Console guidance warns that these settings should only change while the API is not in active use. We test which privilege sets carry fmrest or fmodata, and whether an API credential can read or write records that its equivalent FileMaker Pro session would never be allowed to.
Custom Web Publishing With PHP and XML
fmphp and fmxml are the extended privileges for reaching a file through PHP or XML web publishing, and FileMaker Server enables each independently from the command line with its own cwpconfig setting. We test whether a Custom Web Publishing deployment applies the same record and field restrictions your FileMaker Pro clients see, or exposes a wider surface through a script or query built for the web tier.
Network Ports and SSL/TLS Configuration
FileMaker Server installs its own website on ports 80 and 443 on the primary and secondary machines, and ships with a default SSL certificate signed by Claris that does not verify your server name and is intended only for test purposes. We test which ports are actually reachable from outside your network, and whether a production deployment is still running on that default test certificate rather than one you requested and installed yourself.
External Server Authentication via Directory Services
FileMaker Server can authenticate hosted files against Apple Open Directory, a Windows domain, or on Linux a Windows domain via Active Directory Federation Services, comparing the groups an external server returns for a user against the group names configured in the file and assigning the privilege set from the first valid match. We test how that group-to-privilege-set mapping has been configured, and whether a broad or nested directory group ends up matched to a privilege set wider than the file owner intended.
Container Fields and External Container Storage
Container data stored externally is held in secure storage by default, which FileMaker encrypts, though a solution can be set to open storage instead, keeping files in their native, unencrypted format on disk. We test which storage mode a solution’s container fields actually use, and whether a container data folder is reachable, backed up or exported outside the access controls the file itself enforces.
Scripts That Run With Full Access Privileges
A script can be marked to run with full access privileges, letting a user with a limited privilege set perform actions such as exporting or deleting records that their own privilege set would otherwise block, though that elevation never carries over to an external file or to a sub-script unless it is enabled there too. We test every script marked this way for logic that could be triggered in a context its developer did not intend, since only Full Access users can create or edit such scripts but any permitted account may be able to run them.
OUR PROCESS
Claris FileMaker Security Review: From Scope to Attestation
Scope and Access
We agree which FileMaker files, privilege sets and hosting environment, FileMaker Server or FileMaker Cloud, are in scope, plus at least one account for every privilege tier you want tested.
Privilege and Configuration Mapping
We map every privilege set’s record, layout, value list and script access, and catalogue which extended privileges, such as WebDirect, ODBC/JDBC, the Data API and OData, are switched on for each.
Manual Testing
A CREST-certified tester manually tests authentication, privilege set boundaries, full-access scripts, container storage and API access, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Claris FileMaker pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Claris FileMaker Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 8 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Claris FileMaker For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Claris FileMaker Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our FileMaker solution?
We need at least one authenticated account for every privilege tier in scope, from a custom Data Entry Only or Read-Only style set through to Full Access. If we are also reviewing hosting configuration, such as extended privilege settings, SSL certificates or container data folders, we need Admin Console access to the relevant FileMaker Server or FileMaker Cloud instance too.
Will testing touch live data?
We test against the files, accounts and privilege sets you nominate, working with the data already in those files rather than a separate copy, so we agree exclusions such as destructive script runs, container field deletions or production record changes before testing starts. We do not run destructive tests without that agreement in writing.
How long does a FileMaker security review take?
A single FileMaker solution hosted on one FileMaker Server or FileMaker Cloud instance sits in our 2-day single-system scope, with a report typically landing around 5 working days after kickoff. Multiple files, a wider set of privilege sets, or hosting spread across several environments moves into a larger scope with more testing days.
Do you test FileMaker Server and FileMaker Cloud the same way?
The testing questions are the same: accounts, privilege sets, extended privileges, script security and container storage. What differs is the boundary, since FileMaker Cloud is managed by Claris on AWS infrastructure, moving the operating system and underlying patching out of scope, while FileMaker Server puts that configuration in your hands, so we confirm during scoping exactly what you control on your deployment.
What is out of scope for a single-system FileMaker review?
We never test Claris’s own FileMaker Server or FileMaker Cloud platform code, or the underlying AWS infrastructure behind FileMaker Cloud, and a separate connected system, such as a directory service or a backup platform, is scoped and quoted separately. We test the accounts, privilege sets, extended privileges, scripts and container storage configured in the solution you nominate.
Do you need approval from Claris before testing our FileMaker solution?
Testing a FileMaker solution you own and host, whether on your own FileMaker Server or on Claris-managed FileMaker Cloud, is your decision as the account holder, but hosting terms and any vendor sign-off can change over time. We confirm the current testing terms for your specific hosting arrangement during scoping and test only to what has been agreed with you and, where relevant, your hosting provider.
Do you need our FileMaker source files, scripts or Admin Console access?
No. Testing is black-box by default against the accounts and privilege sets you provide. A grey-box option, where we review privilege set definitions, scripts marked to run with full access privileges, and Admin Console settings such as extended privileges and SSL certificates, is available if you want faster or deeper coverage.
Are your testers CREST certified?
Yes. Every Claris FileMaker engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your FileMaker review
A FileMaker solution only restricts what its privilege sets and extended privileges are configured to restrict. We test accounts, privilege sets, extended privileges and container storage against what your solution should allow. CREST-certified testers, fixed price from £2,740 for a 2-day single-system scope, quoted within 24 hours.



