Freshservice Security Review
A Freshservice role’s scope level decides which tickets and assets an agent can see, separate from what the role can do. We test your roles, workspaces, API keys and marketplace app access. CREST-certified testers, fixed price from £4,180 for a 3-day single-tenant scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Every Freshservice role carries a scope level, from every group in the account down to only the items assigned to that agent, and the scope decides what data the role’s permissions actually reach.
Why a Freshservice finding is a role scope or workspace setting, not a platform flaw
Freshservice assigns every agent a role that decides which features they can use, and separately a scope level that decides which tickets, problems, changes and assets that role can actually see: across every group in the account, only the agent’s member or observer groups, specific named groups, or only items assigned to them directly. We test whether every agent’s scope actually matches the groups their job needs, not just whether the role name sounds right.
Accounts on a multi-workspace plan split the business into separate areas, commonly one each for IT, HR and Facilities, and an agent’s workspace_ids attribute controls which of them they are actually added to. Freshservice’s own documentation on APIs and marketplace apps in a multi-workspace setup confirms that an integration which never passes a workspace ID keeps acting on the primary workspace only once a second workspace is added, so a custom app or automation built before that point can end up reading or writing the wrong workspace’s data. We test which workspace every integration, workflow automation and marketplace app in scope actually reaches.
Every API call authenticates as a specific agent using that agent’s own API key over Basic Authentication, so a leaked key inherits exactly that agent’s role and scope rather than a separate service-account permission set. Enterprise accounts can also create a Sandbox that copies most workspace data into a separate staging instance, gated behind a permission literally named Play God, and sign-in can be restricted to trusted IP ranges for agents and requesters separately, or handed to a SAML identity provider such as Microsoft Entra ID instead. It is the same question of what a credential or a copied environment can actually reach that we test on Salesforce and other role-based SaaS platforms, applied to Freshservice’s own scope and workspace model.
SCOPE
What we pen test on a Freshservice tenant
Default Agent Roles and Permission Tiers
Freshservice ships default roles such as SD Agent, SD Supervisor, Admin and Account Admin, each with a fixed set of what they can create, edit or delete across tickets, problems, changes and the CMDB, and higher plans add custom roles on top. We test whether every agent’s assigned role, default or custom, actually matches what their job needs rather than what was quickest to assign.
Role Scope and Data Visibility Levels
A role’s scope level is set separately from its permissions and decides how much data it can see: every group in the account, only the agent’s member or observer groups, specific named groups, or only items assigned to that agent. We test whether the scope on every role in use actually restricts ticket, asset and CMDB visibility to what your group structure intends.
Workspace Boundaries and Cross-Workspace Access
Workspaces split a multi-department account into dedicated areas, commonly one each for IT, HR and Facilities, and an agent’s workspace_ids attribute controls which ones they are actually added to, with roles assignable per workspace. We test whether an agent, an API key or an automation scoped to one workspace can reach tickets, assets or custom objects that belong to another.
Requester Self-Service Portal Boundary
A requester is an employee raising tickets through the self-service portal rather than an agent working them, and Freshservice’s own API even exposes an operation to convert an agent into a requester, underlining how distinct the two access levels are meant to be. We test whether the requester portal ever exposes an agent-only action, another requester’s ticket, or a knowledge article that should sit behind a login.
API Key Authentication and Key Control
Every API call authenticates as a specific agent using that agent’s personal API key over Basic Authentication rather than a shared service credential, and each agent record carries a flag your admins can use to disable that key. We test where API keys are stored by the integrations using them, and what a leaked key would let someone reach given that agent’s exact role and scope.
Marketplace and Custom App Behaviour Across Workspaces
Freshservice’s own documentation confirms that a marketplace app or custom integration built for a single-workspace account keeps acting on the primary workspace only once a second workspace is added, unless it is updated to pass a workspace ID explicitly. We test every marketplace app and custom integration in scope for that gap, and for what each one can create, read or update given the credentials it holds.
IP Range Restriction for Sign-In
Service Desk Security settings let an administrator restrict the IP ranges people can sign in from, and that restriction can be applied to agents and requesters separately rather than as a single account-wide rule. We test whether an enabled IP restriction actually blocks sign-in from outside the allowed ranges, and whether it is applied consistently across every workspace in a multi-workspace account.
SAML Single Sign-On Configuration
Freshservice supports SAML-based single sign-on, documented for providers such as Microsoft Entra ID, configured per portal and restricted to agents holding the Organization Admin role. We test whether every portal and workspace in scope is actually covered by the SSO configuration, and whether a direct username-and-password login path is still reachable alongside it.
Sandbox Environment Isolation
Enterprise-plan accounts can create one free Sandbox that copies most workspace data into a separate staging instance for testing, gated behind a permission named Play God, with no expiry once created. We test who can actually create or access a Sandbox, and whether the copied data inside it is protected to the same standard as production.
Ticket, Asset and CMDB API Enforcement
Because an API request authenticates as the agent whose key was used, the ticket, asset, CMDB and custom object endpoints should enforce that same agent’s role and scope on every call, not just in the browser interface. We test whether the API actually applies the same restriction the interface does, or whether it returns more than the calling agent could see by clicking around.
OUR PROCESS
Freshservice Tenant and Integration Security Review: From Scope to Attestation
Scope and Access
We agree the tenant, an admin test account, agent accounts covering a couple of your roles and scope levels, plus which workspaces, marketplace apps and custom integrations are in scope.
Role and Scope Mapping
We map agent roles, scope levels, workspace membership and API key access across your tenant before manual testing starts.
Manual Testing
A CREST-certified tester manually tests role and scope boundaries, workspace isolation, API key exposure and marketplace app behaviour, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Freshservice pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Freshservice Tenant and Integration Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
3 to 5 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote7 to 9 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Freshservice For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Freshservice Tenant and Integration Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Freshservice tenant?
We need an admin test account, plus at least one agent account for each role and scope tier you use, so we can test what each level can actually reach. If you use marketplace apps, custom apps or workspace-specific integrations, tell us during scoping so we can agree which ones are in scope.
Will testing touch our live data?
We test the tenant you nominate. An Enterprise-plan Sandbox, which copies most of your workspace data into a separate staging instance, avoids any risk to production tickets and assets, and if we test your production tenant, we agree exclusions such as sending real notification emails before testing starts.
How long does a Freshservice security review take?
A single Freshservice tenant sits in our 3-day single-tenant scope, with a report typically landing around 6 to 8 working days after kickoff. A tenant with several workspaces, a large marketplace app footprint or extensive Workflow Automator scripts can move into a wider scope.
Freshservice is a hosted SaaS platform. Does that change what you test?
It changes where the risk sits rather than reducing it. There is no Freshservice infrastructure or hosting layer for us to review, since that belongs to Freshworks; every role, scope level, workspace, API key and marketplace app configuration is a setting your team controls, and that is what we test in full.
Do you test across multiple workspaces?
Yes. If your tenant uses more than one workspace, we test whether an agent, API key, automation or marketplace app scoped to one workspace can reach tickets, assets or custom objects belonging to another, as part of the same engagement.
What is out of scope for a single-tenant Freshservice review?
Freshservice’s own infrastructure and multi-tenant hosting are never in scope. A separate system that only happens to integrate with your tenant, such as an identity provider or an asset discovery tool, is scoped and quoted separately.
Do you need our source code or admin access?
No. Testing is black-box by default against the agent and requester accounts you provide. A grey-box option, where we review custom app code, Workflow Automator scripts and marketplace app configuration, is available if you want faster or deeper coverage.
Does Freshworks have a customer penetration-testing policy we need to follow?
We confirm Freshworks’ current testing terms and any notification requirements for your account during scoping, before testing starts. Testing is always scoped to your tenant’s configuration, agents, workspaces and integrations, never to Freshworks’ own infrastructure or multi-tenant platform.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Freshservice tenant
A Freshservice role’s scope level decides which tickets and assets an agent can see, separate from what the role can do. We test your roles, workspaces, API keys and marketplace app access. CREST-certified testers, fixed price from £4,180 for a 3-day single-tenant scope, quoted within 24 hours.



