Form.io Application Security Review
Form.io disables submission access by default, until a role is granted create access. We test which roles hold that access, and whether webhooks or JWT tokens extend it further. CREST-certified testers, fixed price from £2,270 for a 2-day single-application scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Every Form.io project ships four default Roles, and Submission Access is switched off for every form until a role is deliberately granted create_own or create_all.
Why Form.io findings sit in your role configuration, not the form builder
Form.io’s Roles and Permissions model grants every new project four default Roles, including Anonymous and Everyone, and Submission Access is disabled on every form until a role is explicitly given create_own or create_all. We test which roles actually hold that access on each form, and check for the documented interaction where a role granted update_all also receives create_all on the same Submission collection, whether or not that was intended. Form definitions themselves are readable by every role by default, so we check what a form’s own JSON schema discloses about validation logic and hidden fields before a submission is ever made.
Actions run server-side on submission, and a Webhook Action forwards a configurable payload to an external Request URL with an optional Basic Auth header or additional custom headers, transformable with custom JavaScript before it leaves Form.io. We test where each webhook actually points, whether the receiving endpoint enforces the authentication the action was configured with, and whether the transform script leaks more of the submission than the destination needs. Role Assignment Actions that add or remove a Role automatically on submission, commonly used for approval-style registration flows, get the same scrutiny, since the trigger condition is what decides who ends up privileged.
Authentication is delegated: OAuth, SAML or LDAP logins are mapped onto Form.io Roles after the external provider authenticates the user, and each Form.io session runs on a JWT carrying a session ID in its jti claim, invalidated project-wide on logout. We test whether that role mapping can be forced to a higher role than the provider intended, and how the API’s temporary-token pattern for exporting submission data is scoped. Field Level Encryption at rest is part of Form.io’s separately licensed Security Module rather than a default, so we confirm whether it is active before judging how sensitive fields are stored.
SCOPE
What we pen test on a Form.io application
Form and Submission Access Roles
Submission Access is disabled on every form until a role is granted create_own or create_all. We test every role’s actual grants against what the form is meant to allow.
create_all, create_own and the update_all Interaction
A role granted update_all also receives create_all on the same Submission collection. We test for a role that ended up able to create records it was only meant to edit.
Public Form Definition Exposure
Forms allow every role to read their own JSON definition by default. We test what that schema discloses about validation rules, hidden fields and conditional logic before any data is submitted.
JWT Sessions and Logout Invalidation
Each authenticated session runs on a JWT carrying a session ID in its jti claim, stored client-side as formioToken. We test whether logout genuinely invalidates every outstanding token tied to that session.
OAuth, SAML and LDAP Role Mapping
External login providers authenticate the user, then Form.io maps the result onto a project Role. We test whether that mapping step can be manipulated into a higher-privilege role than the provider intended.
Webhook Action Destinations and Payloads
A Webhook Action posts a configurable payload to an external URL, with optional Basic Auth or custom headers and an optional JavaScript payload transform. We test where each webhook points and whether the receiving side actually enforces the configured authentication.
Role Assignment Actions on Submission
Role Assignment Actions add or remove a Role automatically when a submission meets a trigger condition, commonly used in approval workflows. We test whether that trigger can be met without the approval step it was meant to represent.
Temporary Token Submission Export
The API issues temporary tokens for exporting submission data outside the normal session flow. We test how long a temporary token remains valid and what it can still reach once issued.
Field Level Encryption and the Security Module
Field Level Encryption at rest is part of Form.io’s separately licensed Security Module, not a default. We confirm whether it is active on your project and test how sensitive submission data is actually stored if it is not.
Self-Hosted vs Form.io-Hosted Deployment
Form.io is offered both as a hosted service and as a self-hosted developer platform. We scope the underlying server and database configuration into the test where your deployment is self-hosted.
OUR PROCESS
Form.io Application Security Review: From Scope to Attestation
Scope and Access Setup
You provide the project URL and credentials for the roles you want tested, from Anonymous through to Administrator.
Role and Permission Mapping
We enumerate every Role and its Form and Submission Access grants before testing a single form.
Manual Testing
Testers work role boundaries, Actions, webhooks and API endpoints against the mapped permission model.
Reporting and Retest
Findings are mapped to the specific Role or Action responsible, with a free retest once fixes are in.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Form.io pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Form.io Application Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Form.io For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Form.io Application Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
Do you need Administrator access to test our Form.io project?
We typically ask for an Administrator-role JWT plus credentials for at least one lower-privilege role, so we can test cross-role access rather than only what an admin can already reach. Exact access requirements are confirmed during scoping.
Does testing touch live submission data?
We test against a project you nominate for the engagement. If it holds live customer submissions, we agree data-handling rules with you before testing starts, and we can test against a cloned project instead if you prefer.
Do you test self-hosted and Form.io-hosted projects the same way?
The Role, Action and API model is the same in both cases. A self-hosted deployment adds the underlying server and database configuration to scope, which we agree with you upfront.
Is the Form.io Security Module in scope?
Only if you have licensed it. We test the Role, Action and API surface either way, and confirm during scoping whether Field Level Encryption is active on sensitive fields.
Does Form.io have a policy on penetration testing customer projects?
Form.io’s published security process asks anyone who finds a vulnerability to disclose it privately to security@form.io before going public, but it does not set out a separate customer pen-testing authorisation process. We confirm current terms during scoping.
What’s out of scope?
Form.io’s own multi-tenant hosting infrastructure is out of scope. We test your project: its Roles, forms, Actions, webhooks and API access.
How long does a Form.io review take?
The standard scope is 2 days for a single Form.io application. Projects with several environments or a large number of custom Actions may need more time, confirmed at scoping.
Can you test our OAuth, SAML or LDAP login integration?
Yes. We test how the external provider’s authentication result gets mapped onto Form.io Roles, and whether that mapping can be forced to a role the provider never intended to grant.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Form.io application
Form.io disables submission access by default, until a role is granted create access. We test which roles hold that access, and whether webhooks or JWT tokens extend it further. CREST-certified testers, fixed price from £2,270 for a 2-day single-application scope, quoted within 24 hours.



