OVHcloud Cloud Security Review
An OVHcloud account is a set of policies, API keys, security groups and permissions, and one left broad is the way in. We test what your team actually configured, not OVHcloud’s platform. CREST-certified testers, fixed price from £2,320 for a 2-day single-estate scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Every application that calls the OVHcloud API is issued three credentials together, an Application Key, an Application Secret and a Consumer Key, and only the Rights entered at creation limit what they can do.
An OVHcloud account is only as secure as the IAM policies, API keys and security groups your team has configured
OVHcloud’s access control is a policy system built from three parts: one or more identities (a local user, a service account, a federated group, or the account itself), one or more resources, and one or more actions. OVHcloud’s own documentation is explicit that the account used to sign in to the Control Panel, the nichandle, acts as a root identity that cannot have its rights restricted, regardless of any policy in place, while local users, service accounts and federated groups are governed entirely by the IAM policies your team wrote. Which permission groups, such as the OVHcloud-managed globalAdmin group, got attached to which identities, and how many people still hold nichandle-level access, is a decision your organisation made.
Outside the Control Panel, every application that calls the OVHcloud API is issued three credentials together, and OVHcloud’s first steps guide confirms that a key’s rights are restricted only by the HTTP methods and paths entered when it was created, from a single endpoint up to a wildcard covering every API. A Consumer Key can also be delegated to a third-party application once the customer approves the request, so a key issued years ago for one integration can sit outside the parts of the account anyone reviews day to day.
We test the OVHcloud account you actually run: the IAM policies and permission groups applied, the OpenStack users and roles on each Public Cloud project, the security groups on every instance, the Object Storage bucket ACLs, the vRack boundaries, and the kubeconfig access on any Managed Kubernetes cluster. We never test OVHcloud’s own infrastructure, in the same way we test client configuration on Heroku apps rather than Heroku’s platform.
SCOPE
What we review in an OVHcloud account
OVHcloud Account and IAM Policies
The OVHcloud account used to sign in to the Control Panel, known as the nichandle, acts as a root identity that cannot have its rights restricted, while IAM policies apply to other identities against specific resources and actions. We test how many people hold nichandle-level access and what each IAM policy actually grants beyond what it should.
Local Users, Service Accounts and Two-Factor Authentication
Local users and service accounts are created for human and machine access respectively, and their rights depend entirely on the IAM policies applied to them rather than any default. We test whether two-factor authentication is enforced for every account able to reach IAM policies or billing.
API Application Keys, Secrets and Consumer Keys
Calling the OVHcloud API requires an Application Key, Application Secret and Consumer Key issued together, and access is restricted only by the Rights entered when the key was created, down to a single HTTP method on a single path. We test which scopes every live key actually holds against what its integration needs.
Public Cloud Project Users and Roles
Access to Horizon and the OpenStack APIs is granted through OpenStack users created inside a Public Cloud project, each assigned the roles that define what they can manage there. We test which roles every OpenStack user actually holds against the access their job requires.
Public Cloud Network Security Groups
OVHcloud’s own documentation shows the default security group applied when an instance is launched permits all IPv4 and IPv6 traffic in both directions, and OVHcloud advises creating a separate group for restrictive rules rather than editing the default one. We test which instances are still running on that default, unrestricted group.
Object Storage Bucket and Object ACLs
Every bucket and object in OVHcloud Object Storage is private by default, with only the creating account holding full control, and a predefined ACL such as public-read grants the AllUsers group read access instead. We test which buckets and objects carry a public-read or public-read-write ACL that should not be open.
vRack Private Network Isolation
vRack routes traffic between dedicated servers, Public Cloud instances and other OVHcloud services outside the public internet, though OVHcloud’s own documentation notes that Public Cloud does not support security groups inside a vRack. We test what is actually reachable across the private network against what should be isolated.
Managed Kubernetes: Default Kubeconfig Access
OVHcloud states that the kubeconfig file issued when a Managed Kubernetes cluster is created grants access to everything in the cluster by default, and RBAC objects such as Roles and RoleBindings are the way to narrow that. We test what a distributed kubeconfig can actually reach against the access it was issued for.
Managed Kubernetes API Server IP Restrictions
An OVHcloud Managed Kubernetes cluster’s API server accepts connections from any IP address until an authorised client range is added, and OVHcloud is explicit that no restriction applies while that list is empty. We test whether the clusters in scope actually have one configured.
Third-Party API Rights Delegation
An external application can request delegated access to an OVHcloud account by asking for a Consumer Key scoped to specific endpoints, which the customer approves through an OVHcloud validation URL before it becomes active. We test which third-party applications hold a live Consumer Key against your account and whether its granted endpoints go further than the integration needs.
OUR PROCESS
OVHcloud Cloud Security Review: From Scope to Attestation
Scope and Access
We agree which Public Cloud projects, OpenStack users, Object Storage buckets, Managed Kubernetes clusters and vRack networks are in scope, plus a login or role for each level tested.
Configuration and Policy Mapping
We map every IAM policy, API key and security group against what it actually grants.
Manual Testing
A CREST-certified tester manually tests security group rules, bucket ACLs, kubeconfig scope and API key rights.
Attestation and Retest
You get a technical report with CVSS scores, a walkthrough call, a free retest, and an attestation letter.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST OVHcloud pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent OVHcloud Cloud Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test OVHcloud For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From OVHcloud Cloud Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our OVHcloud account?
We need at least one OpenStack user for each role in every Public Cloud project in scope, ideally alongside a local user or nichandle-level login for IAM policy review, plus an Application Key, Application Secret and Consumer Key if API-level testing is included.
Will testing touch our live data?
Testing focuses on IAM policies, security groups, bucket ACLs and kubeconfig scope rather than the content of your Object Storage buckets or databases. Where a test record is genuinely needed we agree scope first and remove it afterwards.
Is this hosted on our infrastructure or OVHcloud’s?
Everything runs on OVHcloud’s infrastructure, so there is nothing separate for you to host. The review is scoped to the account configuration you control, not OVHcloud’s underlying platform.
How long does an OVHcloud security review take?
A single account and its Public Cloud projects sit in our 2-day single-estate scope, with a report usually landing around 5 working days after kickoff.
What is out of scope for a single-estate review?
Testing OVHcloud’s own infrastructure, hypervisors or datacentre security is never in scope, and we do not run denial-of-service testing. Application code running inside a Public Cloud instance or on a dedicated server is scoped separately.
Does OVHcloud have a customer penetration-testing policy we need to follow?
OVHcloud does not publish a dedicated customer penetration-testing policy setting out rules of engagement in the way some hyperscale providers do. Its published security contact and vulnerability disclosure programme cover OVHcloud’s own platform rather than customer-run testing of Public Cloud resources, so we confirm OVHcloud’s current terms during scoping before testing begins.
Do you need our source code or admin access?
No. We test with the OpenStack users, local users and API keys you provide, and do not need standing nichandle-level access beyond verifying a specific finding.
Are your testers CREST certified?
Yes. Every engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your OVHcloud account
An OVHcloud account is a set of policies, API keys, security groups and permissions, and one left broad is the way in. We test what your team actually configured, not OVHcloud’s platform. CREST-certified testers, fixed price from £2,320 for a 2-day single-estate scope, quoted within 24 hours.



