Neo4j Security Review
Every Neo4j user automatically holds the PUBLIC role, which can execute procedures and load data by default. We test the roles, privileges and authentication built on it, self-managed and in Aura. CREST-certified testers, fixed price from £2,620 for a 2-day single-instance scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Neo4j’s own documentation confirms PUBLIC is the default role assigned to every user, and that by default it grants procedure execution, user-defined function execution and data loading on the home database before any other role is added.
Why Neo4j and Aura security comes down to roles, privileges and what Aura exposes
Neo4j’s built-in roles documentation lists PUBLIC, the role every user holds automatically, and five hierarchical roles running from reader at the bottom to admin at the top with every privilege, with a user’s overall access always the union of every role they hold. Its guide to role-based access control describes privileges as a combined allow and deny mechanism, and the read privileges reference splits reading further into TRAVERSE, READ and MATCH, each of which Neo4j’s own access control tutorial shows scoped down to a single label, relationship type or property, such as excluding one field from an otherwise readable record.
That fine-grained model is Enterprise Edition functionality, with Community Edition limited to a smaller set of user management functions instead, so we confirm which edition a self-managed instance is running before assuming role-based access control applies at all. Authentication runs through Neo4j’s native username and password provider or through user auth providers that link an externally-defined LDAP or OIDC identity to the internal user model, and Neo4j’s single sign-on documentation lists OIDC support for identity providers including Okta, Microsoft Entra ID and Google. On the application side, Neo4j’s own driver documentation is explicit that dynamic values belong in Cypher parameters, never concatenated into the query string, a rule the Cypher parameter reference repeats for every driver and shell.
Aura moves some of the same questions into the console. Its IP filtering documentation restricts access to trusted IP addresses or CIDR ranges, and only checks new connections once the list is edited, while the Aura API authenticates with OAuth 2.0 client credentials rather than a database username and password. Organisation and project roles separate who can invite users, take a snapshot, restore one or export it, and Aura’s multi-factor authentication setting only applies once a member is logging in with email and password rather than through single sign-on. For the wider question of how this database sits inside your architecture, see our database security review.
SCOPE
What we review in a Neo4j deployment
Role-Based Access Control and Built-in Roles
Neo4j ships six built-in roles: PUBLIC, which every user holds automatically and which grants procedure execution, function execution and data loading on the home database, plus five hierarchical roles running from reader at the bottom to admin at the top with every privilege. Because a user’s access is always the union of every role assigned to them, a broad role granted early is never withdrawn just because a narrower one is added later, so we map what each account can actually do against what it was meant to hold.
Fine-Grained and Property-Based Access Control
Neo4j’s privilege model splits read access into TRAVERSE, which lets a role find specific nodes and relationships, and READ, which lets it read the properties of what it can already find, with MATCH combining both, and Neo4j’s own access control tutorial shows every one of these scoped down to a single label, relationship type or property, such as excluding one field from an otherwise readable record. We test whether a role built for one part of the graph has been reused more widely than that scoping was meant to allow.
Enterprise Edition Requirement for Role-Based Access Control
Neo4j’s own documentation is explicit that role-based access control and fine-grained access control are Enterprise Edition functionality, and that Community Edition ships only a limited set of user management functions instead. We confirm during scoping which edition a self-managed instance is actually running and which authentication and authorisation settings are enabled, rather than assuming the access control your team designed on paper is the access control the running instance enforces.
Native Authentication, LDAP and OIDC Single Sign-On
Alongside Neo4j’s native username and password provider, user auth providers let you link an externally-defined LDAP or OIDC identity to the internal Neo4j user model, and Neo4j’s single sign-on documentation lists OIDC support for identity providers including Okta, Microsoft Entra ID and Google, with each concurrently configured provider needing its own settings prefix. We test which auth providers are actually attached to which accounts, and whether a user who should authenticate through your identity provider can still reach the database through a native password instead.
Cypher Injection via String-Built Queries
Neo4j’s own driver documentation is direct about this: do not hardcode or concatenate parameters directly into a query, and always supply dynamic values as Cypher parameters instead, a rule the Cypher language reference repeats for every driver and shell. We test the application’s own query-building code for places a request value reaches a Cypher string through concatenation rather than a parameter, the same class of flaw SQL injection describes in a relational database.
Aura IP Filtering and Private Endpoints
Aura’s IP filtering restricts access to an instance over the public internet to trusted IP addresses or CIDR ranges, up to 20 on AuraDB Business Critical and up to 100 on Virtual Dedicated Cloud and AuraDS Enterprise, and Aura only checks new connections against an updated list, leaving existing sessions from a removed address unaffected until they end. We test what is actually on the allow list against what needs to reach the instance, and whether a Private Endpoint would close off public internet access altogether.
Aura API Keys and the OAuth2 Management API
The Aura API authenticates with OAuth 2.0 client credentials, a client ID and client secret exchanged for a Bearer token, and lets you create, pause, resume or delete an Aura instance without logging into the console, entirely separately from the username and password your application uses to query the database itself. We test what an API key is actually scoped to manage, and whether a key generated for one integration has since been given the run of every instance in a project.
Aura Organisation and Project Roles
Aura’s organisation-level roles, Organization Owner, Organization Admin and Organization Member, determine who can invite users and manage settings across every project in an organisation, while project-level roles, Project Admin, Project Member, Project Viewer and Metrics Reader, are assigned per project, and both levels always keep at least one owner or admin in place. We map every organisation and project role holder against who actually needs that reach, and flag an account that holds organisation-level access it only ever uses for one project.
Aura Multi-Factor Authentication Enforcement
Aura lets an account turn on mandatory multi-factor authentication for every member through an authenticator app, but Neo4j’s own documentation notes that setting up and using MFA depends on logging in with email and password rather than through single sign-on or Google sign-in. We test whether that boundary leaves an SSO-authenticated account outside the mandatory MFA setting, and whether individual accounts that never joined the SSO rollout still authenticate with a password alone.
Aura Snapshot, Backup and Export Access
Aura backs up an instance through snapshots: scheduled snapshots run automatically, daily on Professional and AuraDS tiers and hourly on Business Critical and Virtual Dedicated Cloud, while an on-demand snapshot is the only backup a Free instance ever gets, and Aura’s project roles separate who can take a snapshot from who can restore one and who can download or export it. We test who actually holds each of those roles against who needs it, and whether an exported snapshot could leave your data outside the access controls you rely on inside Aura.
OUR PROCESS
Neo4j Security Review: From Scope to Attestation
Scope and Access
We agree which Neo4j instances, Aura projects and databases are in scope, plus a database user for every privilege tier you want tested and, where relevant, an Aura organisation or project role to review configuration.
Role and Privilege Mapping
We map every built-in role, custom role and fine-grained privilege against who or what actually needs that level of access, on self-managed instances and in Aura.
Manual Testing
A CREST-certified tester manually tests authentication and authorisation, Cypher injection paths in the application layer, Aura network exposure and API key scope, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Neo4j pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Neo4j Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Neo4j For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Neo4j Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Neo4j deployment?
We need at least one authenticated Neo4j user for every privilege tier in scope, from an ordinary application account through to a role that can query role and privilege configuration on a self-managed instance, or the equivalent Project Admin access in Aura. Read access to your organisation and project roles in Aura speeds up the review, though we can test with database-level access alone.
Will testing touch live data?
We test the databases and instances you nominate, working against your actual roles, privileges and application queries rather than a copy, so we agree exclusions such as destructive Cypher commands or production replica targets before testing starts. We do not export real customer data or run destructive tests without that agreement in writing.
Do you test self-managed Neo4j and Aura the same way?
The underlying questions are the same: who can authenticate, what role and privileges they hold, and what a query built from user input can reach. What differs is the boundary, since Aura manages the host, networking and features such as snapshots and private endpoints, so we confirm during scoping exactly what you control on your Aura tier and test to that boundary.
What is out of scope for a single-instance Neo4j review?
We never test Neo4j’s own source code, the underlying host or hypervisor of a managed Aura instance, or Aura’s shared infrastructure, and a separately hosted application that happens to query the database is scoped and quoted on its own. We test the authentication, roles, privileges and query handling for the instance you nominate.
Does Neo4j have a policy on customer penetration testing?
Neo4j publishes a Trust Center covering its own security programme, including Core Database and Aura penetration test reports and a responsible disclosure policy for vulnerabilities in the platform itself. That covers Neo4j’s testing of its own product, so we confirm Neo4j’s current terms for you testing your own self-managed deployment or Aura project during scoping and test within them.
Is the Aura Management API in scope?
Yes, when you want it tested. The Aura API manages instances, projects and organisation settings through OAuth 2.0 client credentials, entirely separate from the database credentials your application uses, so we scope API key and service account access alongside the database itself rather than assuming it was covered.
How long does a Neo4j security review take?
A single Neo4j instance or Aura deployment, with a small number of databases and a limited set of roles, sits in our 2-day single-instance scope, with a report typically landing around 5 working days after kickoff. More databases, multiple Aura projects, or a mix of self-managed and Aura deployments moves into a larger scope with more testing days.
Are your testers CREST certified?
Yes. Every Neo4j engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Neo4j review
Every Neo4j user automatically holds the PUBLIC role, which can execute procedures and load data by default. We test the roles, privileges and authentication built on it, self-managed and in Aura. CREST-certified testers, fixed price from £2,620 for a 2-day single-instance scope, quoted within 24 hours.



