TECHNOLOGIES: FRESHSERVICE

Freshservice Security Review

A Freshservice role’s scope level decides which tickets and assets an agent can see, separate from what the role can do. We test your roles, workspaces, API keys and marketplace app access. CREST-certified testers, fixed price from £4,180 for a 3-day single-tenant scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Freshservice Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Scope

Every Freshservice role carries a scope level, from every group in the account down to only the items assigned to that agent, and the scope decides what data the role’s permissions actually reach.

Why a Freshservice finding is a role scope or workspace setting, not a platform flaw

Freshservice assigns every agent a role that decides which features they can use, and separately a scope level that decides which tickets, problems, changes and assets that role can actually see: across every group in the account, only the agent’s member or observer groups, specific named groups, or only items assigned to them directly. We test whether every agent’s scope actually matches the groups their job needs, not just whether the role name sounds right.

Accounts on a multi-workspace plan split the business into separate areas, commonly one each for IT, HR and Facilities, and an agent’s workspace_ids attribute controls which of them they are actually added to. Freshservice’s own documentation on APIs and marketplace apps in a multi-workspace setup confirms that an integration which never passes a workspace ID keeps acting on the primary workspace only once a second workspace is added, so a custom app or automation built before that point can end up reading or writing the wrong workspace’s data. We test which workspace every integration, workflow automation and marketplace app in scope actually reaches.

Every API call authenticates as a specific agent using that agent’s own API key over Basic Authentication, so a leaked key inherits exactly that agent’s role and scope rather than a separate service-account permission set. Enterprise accounts can also create a Sandbox that copies most workspace data into a separate staging instance, gated behind a permission literally named Play God, and sign-in can be restricted to trusted IP ranges for agents and requesters separately, or handed to a SAML identity provider such as Microsoft Entra ID instead. It is the same question of what a credential or a copied environment can actually reach that we test on Salesforce and other role-based SaaS platforms, applied to Freshservice’s own scope and workspace model.

SCOPE

What we pen test on a Freshservice tenant

FR-01

Default Agent Roles and Permission Tiers

Freshservice ships default roles such as SD Agent, SD Supervisor, Admin and Account Admin, each with a fixed set of what they can create, edit or delete across tickets, problems, changes and the CMDB, and higher plans add custom roles on top. We test whether every agent’s assigned role, default or custom, actually matches what their job needs rather than what was quickest to assign.

FR-02

Role Scope and Data Visibility Levels

A role’s scope level is set separately from its permissions and decides how much data it can see: every group in the account, only the agent’s member or observer groups, specific named groups, or only items assigned to that agent. We test whether the scope on every role in use actually restricts ticket, asset and CMDB visibility to what your group structure intends.

FR-03

Workspace Boundaries and Cross-Workspace Access

Workspaces split a multi-department account into dedicated areas, commonly one each for IT, HR and Facilities, and an agent’s workspace_ids attribute controls which ones they are actually added to, with roles assignable per workspace. We test whether an agent, an API key or an automation scoped to one workspace can reach tickets, assets or custom objects that belong to another.

FR-04

Requester Self-Service Portal Boundary

A requester is an employee raising tickets through the self-service portal rather than an agent working them, and Freshservice’s own API even exposes an operation to convert an agent into a requester, underlining how distinct the two access levels are meant to be. We test whether the requester portal ever exposes an agent-only action, another requester’s ticket, or a knowledge article that should sit behind a login.

FR-05

API Key Authentication and Key Control

Every API call authenticates as a specific agent using that agent’s personal API key over Basic Authentication rather than a shared service credential, and each agent record carries a flag your admins can use to disable that key. We test where API keys are stored by the integrations using them, and what a leaked key would let someone reach given that agent’s exact role and scope.

FR-06

Marketplace and Custom App Behaviour Across Workspaces

Freshservice’s own documentation confirms that a marketplace app or custom integration built for a single-workspace account keeps acting on the primary workspace only once a second workspace is added, unless it is updated to pass a workspace ID explicitly. We test every marketplace app and custom integration in scope for that gap, and for what each one can create, read or update given the credentials it holds.

FR-07

IP Range Restriction for Sign-In

Service Desk Security settings let an administrator restrict the IP ranges people can sign in from, and that restriction can be applied to agents and requesters separately rather than as a single account-wide rule. We test whether an enabled IP restriction actually blocks sign-in from outside the allowed ranges, and whether it is applied consistently across every workspace in a multi-workspace account.

FR-08

SAML Single Sign-On Configuration

Freshservice supports SAML-based single sign-on, documented for providers such as Microsoft Entra ID, configured per portal and restricted to agents holding the Organization Admin role. We test whether every portal and workspace in scope is actually covered by the SSO configuration, and whether a direct username-and-password login path is still reachable alongside it.

FR-09

Sandbox Environment Isolation

Enterprise-plan accounts can create one free Sandbox that copies most workspace data into a separate staging instance for testing, gated behind a permission named Play God, with no expiry once created. We test who can actually create or access a Sandbox, and whether the copied data inside it is protected to the same standard as production.

FR-10

Ticket, Asset and CMDB API Enforcement

Because an API request authenticates as the agent whose key was used, the ticket, asset, CMDB and custom object endpoints should enforce that same agent’s role and scope on every call, not just in the browser interface. We test whether the API actually applies the same restriction the interface does, or whether it returns more than the calling agent could see by clicking around.

OUR PROCESS

Freshservice Tenant and Integration Security Review: From Scope to Attestation

01

Scope and Access

We agree the tenant, an admin test account, agent accounts covering a couple of your roles and scope levels, plus which workspaces, marketplace apps and custom integrations are in scope.

02

Role and Scope Mapping

We map agent roles, scope levels, workspace membership and API key access across your tenant before manual testing starts.

03

Manual Testing

A CREST-certified tester manually tests role and scope boundaries, workspace isolation, API key exposure and marketplace app behaviour, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Freshservice pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Freshservice Tenant and Integration Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£4,180–£5,860
3 to 5 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£8,470–£11,320
7 to 9 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Freshservice Tenant and Integration Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Freshservice tenant?

We need an admin test account, plus at least one agent account for each role and scope tier you use, so we can test what each level can actually reach. If you use marketplace apps, custom apps or workspace-specific integrations, tell us during scoping so we can agree which ones are in scope.

Will testing touch our live data?

We test the tenant you nominate. An Enterprise-plan Sandbox, which copies most of your workspace data into a separate staging instance, avoids any risk to production tickets and assets, and if we test your production tenant, we agree exclusions such as sending real notification emails before testing starts.

How long does a Freshservice security review take?

A single Freshservice tenant sits in our 3-day single-tenant scope, with a report typically landing around 6 to 8 working days after kickoff. A tenant with several workspaces, a large marketplace app footprint or extensive Workflow Automator scripts can move into a wider scope.

Freshservice is a hosted SaaS platform. Does that change what you test?

It changes where the risk sits rather than reducing it. There is no Freshservice infrastructure or hosting layer for us to review, since that belongs to Freshworks; every role, scope level, workspace, API key and marketplace app configuration is a setting your team controls, and that is what we test in full.

Do you test across multiple workspaces?

Yes. If your tenant uses more than one workspace, we test whether an agent, API key, automation or marketplace app scoped to one workspace can reach tickets, assets or custom objects belonging to another, as part of the same engagement.

What is out of scope for a single-tenant Freshservice review?

Freshservice’s own infrastructure and multi-tenant hosting are never in scope. A separate system that only happens to integrate with your tenant, such as an identity provider or an asset discovery tool, is scoped and quoted separately.

Do you need our source code or admin access?

No. Testing is black-box by default against the agent and requester accounts you provide. A grey-box option, where we review custom app code, Workflow Automator scripts and marketplace app configuration, is available if you want faster or deeper coverage.

Does Freshworks have a customer penetration-testing policy we need to follow?

We confirm Freshworks’ current testing terms and any notification requirements for your account during scoping, before testing starts. Testing is always scoped to your tenant’s configuration, agents, workspaces and integrations, never to Freshworks’ own infrastructure or multi-tenant platform.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Freshservice tenant

A Freshservice role’s scope level decides which tickets and assets an agent can see, separate from what the role can do. We test your roles, workspaces, API keys and marketplace app access. CREST-certified testers, fixed price from £4,180 for a 3-day single-tenant scope, quoted within 24 hours.