Make Integration Security Review
A shared Make scenario link exposes its module settings and mapped values to anyone who opens it. We test scenario sharing, connections, webhooks and team roles for what each one actually reaches. CREST-certified testers, fixed price from £2,670 for a 2-day single-team scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Make’s own scenario sharing feature turns on a public link that anyone can open without signing in, and that link shows the scenario’s modules and mapped values, not just its title.
A scenario is only as private as the link, the connection and the team role behind it
Make runs two layers of default roles. Organisation roles set what a user can manage across the whole organisation, running from Owner, the only role that can transfer ownership or delete it, down to Member, Accountant, App Developer and Guest, and both Owner and Admin also carry implicit Team Admin access in every standard team on top of their own permissions. Team roles then decide what that same user can do with the scenarios, connections, webhooks, keys and data stores that belong to one specific team, and an Enterprise organisation can replace any default role with a custom role built from a permission list, where every permission applies to every resource of that type in the team rather than a chosen few.
What sits inside a team is not always visible to the rest of it. Every member of an organisation, other than a guest, can be given their own private space for scenarios and connections that teammates cannot open, and an admin can only view another member’s private space in read-only mode on an Enterprise plan; on any other plan that space stays invisible to the rest of the organisation. Connections themselves belong to a team once created, and Make’s credential requests feature lets a Team Admin or Team Member ask someone else in the organisation to authorise a connection without ever exposing the password, API key or OAuth token behind it, after which everyone in that team can use the resulting connection to build scenarios.
A scenario’s own boundary is just as easy to miss. Turning on a scenario’s Public scenario page toggle creates a link that anyone can open without signing in, and while it never shows a connection’s credentials, it does show every module, module setting and mapped value the scenario holds. A custom webhook‘s URL works to a similar default, since API key authentication is something you add to it rather than something that is already there. It is the same ownership question we test on n8n’s own scenarios, applied to Make’s teams, connections and shared links instead.
SCOPE
What we review in a Make team
Organisation roles: Owner, Admin, Member, Accountant, App Developer and Guest
Make’s organisation roles set what a user can manage at the organisation level: Owner has full access and is the only role that can transfer ownership or delete the organisation, Admin administers users, teams, custom roles and billing without that transfer right, and Member, Accountant, App Developer and Guest each hold a narrower slice again, with Guest mainly there to receive credential requests. Owner and Admin also carry implicit Team Admin access in every standard team, and a custom organisation role granted View all teams gets the same reach even though its name suggests read-only visibility. We test who holds Owner and Admin, and whether that implicit team-wide access was ever accounted for.
Team roles and what actually belongs to a team
Every scenario, connection, webhook, key, device, data store, data structure, custom function and credential request belongs to exactly one team, and a team role decides what a member can do with them: Team Admin has full access including member management and team deletion, Team Member can create and edit but not manage members, Team Operator holds read-only access with the ability to activate and schedule scenarios, and Team Monitoring is read-only across scenarios, execution logs and usage. We test whether a user’s team role, not just their organisation role, matches what that team’s own resources actually need them to have.
Private spaces hidden from the rest of the organisation
Every member of an organisation other than a guest can be given a private space for scenarios and connections that teammates cannot open, and an organisation admin can only view another member’s private space in read-only mode on an Enterprise plan; on any other plan, that space is invisible to everyone else including other admins. Private spaces are enabled organisation-wide by an Admin, with an optional credit limit per member. We test whether a private space in scope holds a scenario or connection that should have been reviewed alongside the rest of the team’s work.
Connections and credential requests
A connection is created once and belongs to a team, and Make’s credential requests feature lets a Team Member ask anyone in their own team, or a Team Admin ask anyone in the organisation, to authorise a connection without ever exposing the password, API key or OAuth token behind it. Once a request is authorised, everyone in that team can use the resulting connection to build scenarios, and an organisation Admin or Owner can also send a credential request to someone outside the organisation entirely. We test which connections were obtained this way, and whether the team using one still needs it.
Custom webhook authentication and data structure validation
A custom webhook’s URL is unique to that webhook and accepts requests from anyone who has it, because API key authentication is optional rather than the default: adding one or more keys through a keychain requires the caller to send it back in the X-Make-Apikey header, and once saved a key cannot be viewed again. Defining the webhook’s data structure is also optional, and without one Make accepts any incoming query string, form data or JSON without validating it against expected values. We test whether a live webhook actually requires its API key, and what an unvalidated payload can still reach.
Scenario history, run details and the bundles they store
The History tab of a scenario records run entries, including status, duration, operations completed and credits consumed, alongside change log entries for scheduling changes, edits and activation, and how many days of that history are kept depends on your pricing plan. The Details view of any run lets you inspect the actual bundles a module processed, and organisations on Pro plans and above can run a full-text search across that execution history. We test what a scenario’s run details and bundles actually contain for the workflows in scope, and who in the team can open them.
Incomplete executions keep the data behind the failure
When a scenario run fails, Make can store an incomplete execution containing both the scenario’s blueprint and the data a module was processing at the point of failure, and a resolved incomplete execution is only deleted automatically after 30 days, while an unresolved one stays in storage until someone retries or resolves it. The Store incomplete executions setting can turn this off for a scenario entirely, and a separate Enable data loss setting decides whether Make keeps scheduling a scenario once its incomplete execution storage is full. We test what a live incomplete execution actually holds, and how long it has been sitting there.
Scenario sharing exposes mapped values behind a public link
Turning on a scenario’s Public scenario page toggle creates a link that anyone can open and copy from without signing in, and Make’s own documentation is specific about what that link shows: the scenario’s modules, module settings including mapped values, metadata and notes, though never the connections or the API keys and passwords behind them. Disabling the toggle stops the link working, but re-enabling it brings back the same link showing whatever is currently saved. We test every shared scenario link in scope for what its mapped values actually reveal about your systems.
Two-factor authentication enforcement and single sign-on
Enterprise organisation Owners and Admins can force two-factor authentication for every user, but that enforcement only applies to accounts signing in with Make’s native email and password; a user signing in through Google or an SSO identity provider needs 2FA enforced at that provider instead. Single sign-on, also Enterprise-only, supports OpenID Connect and SAML 2.0 against providers including Okta, Microsoft Entra ID and Google, is configured separately for each organisation, and can be paired with a claimed email domain to stop new self-service sign-ups. We test which of these is actually configured against who can still sign in without it.
Webhook queues, logs and the IP addresses Make will and won’t restrict
Make queues incoming webhook data until it is processed, keeps webhook logs for 3 days by default and 30 days on Enterprise, automatically deactivates a webhook not attached to any scenario after 5 days, and rate-limits incoming requests at 300 per 10-second interval. Make publishes fixed egress IP addresses per zone so you can allow its outbound calls through your own firewall, but its own inbound traffic uses dynamic IPs, so unlike n8n’s Webhook node there is no IP allowlist setting to restrict who can call a Make webhook by address. We test what a webhook’s logs and queue actually retain, and whatever access control stands in for that missing allowlist.
OUR PROCESS
Make Integration Security Review: From Scope to Attestation
Organisation, Team and Role Mapping
We map every organisation role, team role, custom role and private space in scope, and which scenarios, connections and webhooks each team actually owns.
Connection and Sharing Testing
We test connection sharing, credential requests, scenario sharing links and team membership for gaps between who has access and who should.
Webhook, Execution and Retention Testing
We test custom webhook authentication directly, review scenario history, bundles and incomplete execution retention, and check 2FA enforcement and SSO configuration.
Reporting and Retest
Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest after remediation and an attestation letter.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Make pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Make Integration Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Make For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Make Integration Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Make team?
At least one login for every organisation role and team role in scope, plus Org Admin or Owner access where we’re reviewing organisation-wide settings, 2FA enforcement or SSO configuration directly. Read access to exported scenario blueprints and the connections list, not the connection credentials themselves, speeds up scoping but is not required to start.
Will testing touch live data?
We test read-only against your live team by default, and where a scenario writes, updates or deletes real records we agree a sandbox environment or specific test data with you first. Anything we create during testing to prove a finding is documented and removed afterwards.
Do you test every team in our organisation, or just one?
Our single-team scope covers one team and the scenarios, connections and webhooks that belong to it, since Make keeps those resources separated by team. Additional teams, or organisation-wide settings such as SSO and 2FA enforcement, are scoped and quoted alongside it.
Does Make have a customer penetration-testing policy we need to follow?
Make publishes its own security and compliance information, but we confirm Make’s current terms of service and any notification requirement with you during scoping before testing starts, since that policy can change independently of this page.
What is out of scope?
Make’s own platform infrastructure, other organisations on shared Make Cloud infrastructure, and the third-party services your connections authenticate to are all out of scope. We test your team’s scenarios, connections, webhooks, roles and private spaces; a separate system on the other end of a connection is scoped and quoted as its own engagement.
How long does a Make security review take?
A single team with a handful of scenarios sits in our 2-day single-team scope, with more scenarios, connections, custom roles or a wider integration surface extending it. We confirm the exact day count once we’ve seen the team.
Do you need our scenario blueprints or admin access?
No, testing is black-box by default against the role accounts you provide. Read access to exported scenario blueprints and webhook configurations speeds up root-causing anything we find, and pairs well with a separate source code review.
Are your testers CREST certified?
Yes. Every Make engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Make team
A shared Make scenario link exposes its module settings and mapped values to anyone who opens it. We test scenario sharing, connections, webhooks and team roles for what each one actually reaches. CREST-certified testers, fixed price from £2,670 for a 2-day single-team scope, quoted within 24 hours.



