TECHNOLOGIES: MAKE

Make Integration Security Review

A shared Make scenario link exposes its module settings and mapped values to anyone who opens it. We test scenario sharing, connections, webhooks and team roles for what each one actually reaches. CREST-certified testers, fixed price from £2,670 for a 2-day single-team scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Make Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Public

Make’s own scenario sharing feature turns on a public link that anyone can open without signing in, and that link shows the scenario’s modules and mapped values, not just its title.

A scenario is only as private as the link, the connection and the team role behind it

Make runs two layers of default roles. Organisation roles set what a user can manage across the whole organisation, running from Owner, the only role that can transfer ownership or delete it, down to Member, Accountant, App Developer and Guest, and both Owner and Admin also carry implicit Team Admin access in every standard team on top of their own permissions. Team roles then decide what that same user can do with the scenarios, connections, webhooks, keys and data stores that belong to one specific team, and an Enterprise organisation can replace any default role with a custom role built from a permission list, where every permission applies to every resource of that type in the team rather than a chosen few.

What sits inside a team is not always visible to the rest of it. Every member of an organisation, other than a guest, can be given their own private space for scenarios and connections that teammates cannot open, and an admin can only view another member’s private space in read-only mode on an Enterprise plan; on any other plan that space stays invisible to the rest of the organisation. Connections themselves belong to a team once created, and Make’s credential requests feature lets a Team Admin or Team Member ask someone else in the organisation to authorise a connection without ever exposing the password, API key or OAuth token behind it, after which everyone in that team can use the resulting connection to build scenarios.

A scenario’s own boundary is just as easy to miss. Turning on a scenario’s Public scenario page toggle creates a link that anyone can open without signing in, and while it never shows a connection’s credentials, it does show every module, module setting and mapped value the scenario holds. A custom webhook‘s URL works to a similar default, since API key authentication is something you add to it rather than something that is already there. It is the same ownership question we test on n8n’s own scenarios, applied to Make’s teams, connections and shared links instead.

SCOPE

What we review in a Make team

MK-01

Organisation roles: Owner, Admin, Member, Accountant, App Developer and Guest

Make’s organisation roles set what a user can manage at the organisation level: Owner has full access and is the only role that can transfer ownership or delete the organisation, Admin administers users, teams, custom roles and billing without that transfer right, and Member, Accountant, App Developer and Guest each hold a narrower slice again, with Guest mainly there to receive credential requests. Owner and Admin also carry implicit Team Admin access in every standard team, and a custom organisation role granted View all teams gets the same reach even though its name suggests read-only visibility. We test who holds Owner and Admin, and whether that implicit team-wide access was ever accounted for.

MK-02

Team roles and what actually belongs to a team

Every scenario, connection, webhook, key, device, data store, data structure, custom function and credential request belongs to exactly one team, and a team role decides what a member can do with them: Team Admin has full access including member management and team deletion, Team Member can create and edit but not manage members, Team Operator holds read-only access with the ability to activate and schedule scenarios, and Team Monitoring is read-only across scenarios, execution logs and usage. We test whether a user’s team role, not just their organisation role, matches what that team’s own resources actually need them to have.

MK-03

Private spaces hidden from the rest of the organisation

Every member of an organisation other than a guest can be given a private space for scenarios and connections that teammates cannot open, and an organisation admin can only view another member’s private space in read-only mode on an Enterprise plan; on any other plan, that space is invisible to everyone else including other admins. Private spaces are enabled organisation-wide by an Admin, with an optional credit limit per member. We test whether a private space in scope holds a scenario or connection that should have been reviewed alongside the rest of the team’s work.

MK-04

Connections and credential requests

A connection is created once and belongs to a team, and Make’s credential requests feature lets a Team Member ask anyone in their own team, or a Team Admin ask anyone in the organisation, to authorise a connection without ever exposing the password, API key or OAuth token behind it. Once a request is authorised, everyone in that team can use the resulting connection to build scenarios, and an organisation Admin or Owner can also send a credential request to someone outside the organisation entirely. We test which connections were obtained this way, and whether the team using one still needs it.

MK-05

Custom webhook authentication and data structure validation

A custom webhook’s URL is unique to that webhook and accepts requests from anyone who has it, because API key authentication is optional rather than the default: adding one or more keys through a keychain requires the caller to send it back in the X-Make-Apikey header, and once saved a key cannot be viewed again. Defining the webhook’s data structure is also optional, and without one Make accepts any incoming query string, form data or JSON without validating it against expected values. We test whether a live webhook actually requires its API key, and what an unvalidated payload can still reach.

MK-06

Scenario history, run details and the bundles they store

The History tab of a scenario records run entries, including status, duration, operations completed and credits consumed, alongside change log entries for scheduling changes, edits and activation, and how many days of that history are kept depends on your pricing plan. The Details view of any run lets you inspect the actual bundles a module processed, and organisations on Pro plans and above can run a full-text search across that execution history. We test what a scenario’s run details and bundles actually contain for the workflows in scope, and who in the team can open them.

MK-07

Incomplete executions keep the data behind the failure

When a scenario run fails, Make can store an incomplete execution containing both the scenario’s blueprint and the data a module was processing at the point of failure, and a resolved incomplete execution is only deleted automatically after 30 days, while an unresolved one stays in storage until someone retries or resolves it. The Store incomplete executions setting can turn this off for a scenario entirely, and a separate Enable data loss setting decides whether Make keeps scheduling a scenario once its incomplete execution storage is full. We test what a live incomplete execution actually holds, and how long it has been sitting there.

MK-08

Scenario sharing exposes mapped values behind a public link

Turning on a scenario’s Public scenario page toggle creates a link that anyone can open and copy from without signing in, and Make’s own documentation is specific about what that link shows: the scenario’s modules, module settings including mapped values, metadata and notes, though never the connections or the API keys and passwords behind them. Disabling the toggle stops the link working, but re-enabling it brings back the same link showing whatever is currently saved. We test every shared scenario link in scope for what its mapped values actually reveal about your systems.

MK-09

Two-factor authentication enforcement and single sign-on

Enterprise organisation Owners and Admins can force two-factor authentication for every user, but that enforcement only applies to accounts signing in with Make’s native email and password; a user signing in through Google or an SSO identity provider needs 2FA enforced at that provider instead. Single sign-on, also Enterprise-only, supports OpenID Connect and SAML 2.0 against providers including Okta, Microsoft Entra ID and Google, is configured separately for each organisation, and can be paired with a claimed email domain to stop new self-service sign-ups. We test which of these is actually configured against who can still sign in without it.

MK-10

Webhook queues, logs and the IP addresses Make will and won’t restrict

Make queues incoming webhook data until it is processed, keeps webhook logs for 3 days by default and 30 days on Enterprise, automatically deactivates a webhook not attached to any scenario after 5 days, and rate-limits incoming requests at 300 per 10-second interval. Make publishes fixed egress IP addresses per zone so you can allow its outbound calls through your own firewall, but its own inbound traffic uses dynamic IPs, so unlike n8n’s Webhook node there is no IP allowlist setting to restrict who can call a Make webhook by address. We test what a webhook’s logs and queue actually retain, and whatever access control stands in for that missing allowlist.

OUR PROCESS

Make Integration Security Review: From Scope to Attestation

01

Organisation, Team and Role Mapping

We map every organisation role, team role, custom role and private space in scope, and which scenarios, connections and webhooks each team actually owns.

02

Connection and Sharing Testing

We test connection sharing, credential requests, scenario sharing links and team membership for gaps between who has access and who should.

03

Webhook, Execution and Retention Testing

We test custom webhook authentication directly, review scenario history, bundles and incomplete execution retention, and check 2FA enforcement and SSO configuration.

04

Reporting and Retest

Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest after remediation and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Make pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Make Integration Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,670–£3,920
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,270–£9,560
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Make Integration Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Make team?

At least one login for every organisation role and team role in scope, plus Org Admin or Owner access where we’re reviewing organisation-wide settings, 2FA enforcement or SSO configuration directly. Read access to exported scenario blueprints and the connections list, not the connection credentials themselves, speeds up scoping but is not required to start.

Will testing touch live data?

We test read-only against your live team by default, and where a scenario writes, updates or deletes real records we agree a sandbox environment or specific test data with you first. Anything we create during testing to prove a finding is documented and removed afterwards.

Do you test every team in our organisation, or just one?

Our single-team scope covers one team and the scenarios, connections and webhooks that belong to it, since Make keeps those resources separated by team. Additional teams, or organisation-wide settings such as SSO and 2FA enforcement, are scoped and quoted alongside it.

Does Make have a customer penetration-testing policy we need to follow?

Make publishes its own security and compliance information, but we confirm Make’s current terms of service and any notification requirement with you during scoping before testing starts, since that policy can change independently of this page.

What is out of scope?

Make’s own platform infrastructure, other organisations on shared Make Cloud infrastructure, and the third-party services your connections authenticate to are all out of scope. We test your team’s scenarios, connections, webhooks, roles and private spaces; a separate system on the other end of a connection is scoped and quoted as its own engagement.

How long does a Make security review take?

A single team with a handful of scenarios sits in our 2-day single-team scope, with more scenarios, connections, custom roles or a wider integration surface extending it. We confirm the exact day count once we’ve seen the team.

Do you need our scenario blueprints or admin access?

No, testing is black-box by default against the role accounts you provide. Read access to exported scenario blueprints and webhook configurations speeds up root-causing anything we find, and pairs well with a separate source code review.

Are your testers CREST certified?

Yes. Every Make engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Make team

A shared Make scenario link exposes its module settings and mapped values to anyone who opens it. We test scenario sharing, connections, webhooks and team roles for what each one actually reaches. CREST-certified testers, fixed price from £2,670 for a 2-day single-team scope, quoted within 24 hours.