Metabase Security Review
Metabase signs every embedded dashboard with the same secret key, so one leaked key unlocks every embed the instance has published. We test your permission graph, row-level security, embedding and API keys. CREST-certified testers, fixed price from £3,280 for a 2-day single-instance scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Metabase’s own documentation confirms one embedding secret key is shared across every static and guest embed an instance publishes, so whoever holds that key can reach every embedded dashboard and question, not just one.
Why Metabase security comes down to the permission graph and a single embed key
Metabase’s data permissions documentation sets out five View data permission levels on Pro and Enterprise plans, Can view, Granular, Row and column security, Impersonated and Blocked, applied per database, schema or table. Blocked is stricter than it first looks: the same page confirms it makes collection permissions insufficient to view a question that touches that data source, and that blocking even one table disables native, hand-written SQL queries against every table in that database for the group, because Metabase cannot parse SQL to confirm which tables a query actually reaches. Download permissions follow the same logic, offering No, Granular, 10 thousand rows or 1 million rows options, but native query downloads are only allowed where a group holds download permission across the whole database. We map every group’s actual level against what the business meant to grant, since a Granular or Blocked setting that looks tight at the table level can still leave native queries and downloads wider open than intended.
Row and column security filters data using person-level user attributes, and Metabase’s own row and column security documentation is explicit that the user attribute value must be an exact, case-sensitive match for the filter value, otherwise the person gets an empty result rather than their own data. A simple row filter can only restrict rows by a single column, while a custom SQL-based question can restrict rows across multiple columns and also restrict or edit which columns are returned, the same distinction between row-level and object-level restriction we test on our Tableau security review. We test which mechanism actually protects each sensitive table, and whether a mismatched or missing user attribute has quietly broken a filter rather than being caught before launch.
Access into Metabase from outside the permission graph carries its own risk. An API key is created against a named Group and Metabase’s API keys documentation confirms the key carries exactly that group’s permissions, shown in full only once at creation. Static and the newer guest embeds both sign requests with a JSON Web Token, and Metabase’s own guest embedding documentation states that secret key is shared across every embed the instance creates, and that because a guest embed carries no real user session, it cannot enforce row and column security at all, recommending Modular embedding with SSO instead wherever per-viewer restriction matters. We test who holds that shared key and every live API key’s group binding.
SCOPE
What we review in a Metabase instance
View Data Permission Levels
Metabase’s Pro and Enterprise plans offer five View data permission levels, Can view, Granular, Row and column security, Impersonated and Blocked, set per database, schema or table, deciding what a group can see in questions, dashboards, models and metrics. We test which level is actually applied to each group and data source against what the business meant to grant.
Blocked Access and Native Query Cascading
Setting Blocked view data permission for a group makes collection permissions insufficient to view a question that queries that data source, and Metabase’s documentation confirms blocking even a single table disables native SQL queries against every table in that database for the group, since Metabase cannot parse SQL to confirm which tables a query touches. We test whether a group’s actual native query access matches what its Blocked or Row and column security settings were meant to restrict.
Download Permissions and the Whole-Database Rule
Download permissions on Pro and Enterprise plans offer No, Granular, 10 thousand rows or 1 million rows options, but Metabase’s documentation states downloads of native SQL queries are only allowed if a group holds download permission for the entire database, since a granular per-table setting cannot be matched against an unparsed SQL query. We test whether a group with only table-level download rights can still export more than intended through a native question.
Impersonated Access via Database Roles
The Impersonated view data permission, set at the database level, defers entirely to a role defined in the underlying database rather than to any Metabase-side rule, so what a group can see is only ever as tight as that database role’s own grants. We test whether the impersonated role actually matches the access Metabase’s admins believe it enforces.
Row and Column Security: User Attributes
Row and column security filters data using person-level user attributes, and Metabase’s documentation is explicit that the user attribute value must be an exact, case-sensitive match for the filter value or the person gets an empty result instead of their data. We test whether every user attribute driving a filter is set correctly and consistently across the people it applies to.
Row-Only vs Custom Row and Column Restrictions
Metabase documents two approaches: a simple row filter restricting rows on a single column, and a custom SQL-based question that can restrict rows across multiple columns and also restrict or edit which columns are shown. We test which mechanism protects each sensitive table, since the simpler row filter cannot hide a column the way the custom SQL approach can.
Collection Permissions: Curate, View and No Access
Collections carry three permission levels, Curate, View and No access, where only Curate can edit, move, delete or pin items and create sub-collections, and View is read-only. We test whether a group’s collection-level access actually matches its underlying data access, since a Curate grant on a collection does not by itself grant access to the data a saved question inside it queries.
API Keys Inherit a Group’s Full Permissions
Creating an API key means naming a Group, and Metabase’s own documentation states the key will have the same permissions granted to that group, with the full key value shown only once at creation. We test which group every live API key is tied to, since a key created against an admin or overly broad group carries that same reach indefinitely.
The Shared Embedding Secret Key
Static and guest embeds both sign requests with a JSON Web Token, and Metabase’s own documentation confirms that secret key is shared across every embed the instance creates, so whoever holds it can access every embedded dashboard or question, not just one. We test how that secret key is stored and who can reach it, and whether it has ever been rotated.
Guest Embeds Cannot Enforce Row and Column Security
Because a guest embed’s signed JWT does not create a real user session, Metabase’s documentation lists row and column security, database routing and usage analytics among the features a guest embed cannot use, recommending Modular embedding with SSO instead wherever per-viewer data restriction matters. We test whether a guest-embedded dashboard actually needs row-level restriction that its embedding method cannot provide.
OUR PROCESS
Metabase Security Review: From Scope to Attestation
Scope and Access
We agree which Metabase instance, groups and collections are in scope, plus a login for each permission tier and any API keys or embedding secrets in use.
Permission and Embedding Mapping
We map every group’s data, download and collection permissions, every row and column security rule, and how the embedding secret key and API keys are actually used.
Manual Testing
A CREST-certified tester manually tests permission boundaries, Blocked and Impersonated access, row and column security filters, embedding key exposure and API key scope, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Metabase pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Metabase Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Metabase For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Metabase Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Metabase instance?
We need at least one login for each group or permission tier in scope, ideally accounts below Administrator, plus any API keys and the embedding secret key if embedding is in scope. Read access to your current permission graph and row and column security rules speeds up scoping but isn’t required to start.
Will testing touch our live data?
Testing focuses on permissions, row and column security, embedding and API keys rather than the underlying question results themselves. Where proving a download, an impersonated role or an embed’s data exposure needs a real query, we agree the exact scope with you first.
Is this hosted on our infrastructure or Metabase’s?
Metabase runs either self-hosted on your own infrastructure or as a managed instance on Metabase Cloud, and Pro and Enterprise features such as row and column security and download permissions work the same way on both. We confirm which model applies to your instance during scoping and test the configuration you actually control.
How long does a Metabase security review take?
A single instance with a typical number of groups, data sources and collections sits in our 2-day single-instance scope, with a report landing around 5 working days after kickoff. An instance running many groups, extensive row and column security rules, or multiple embedding integrations extends that scope.
What is out of scope for a single-instance review?
Testing Metabase’s own source code, the underlying databases it connects to, or the infrastructure a self-hosted instance runs on is not included, and we do not run denial-of-service testing against the Metabase server. A connected database’s own security review is scoped and quoted separately.
Do you need our source code or admin access?
No. We test with the role accounts, API keys and embedding secret you provide, and we do not need standing Administrator access beyond what is needed to verify a specific finding during the engagement.
Does Metabase have a policy on customer penetration testing?
We confirm Metabase’s current terms for testing your own instance or Metabase Cloud account during scoping, and test only within whatever authorisation that process requires.
Are your testers CREST certified?
Yes. Every Metabase engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Metabase instance
Metabase signs every embedded dashboard with the same secret key, so one leaked key unlocks every embed the instance has published. We test your permission graph, row-level security, embedding and API keys. CREST-certified testers, fixed price from £3,280 for a 2-day single-instance scope, quoted within 24 hours.



