TECHNOLOGIES: OVHCLOUD

OVHcloud Cloud Security Review

An OVHcloud account is a set of policies, API keys, security groups and permissions, and one left broad is the way in. We test what your team actually configured, not OVHcloud’s platform. CREST-certified testers, fixed price from £2,320 for a 2-day single-estate scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
OVHcloud Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
3

Every application that calls the OVHcloud API is issued three credentials together, an Application Key, an Application Secret and a Consumer Key, and only the Rights entered at creation limit what they can do.

An OVHcloud account is only as secure as the IAM policies, API keys and security groups your team has configured

OVHcloud’s access control is a policy system built from three parts: one or more identities (a local user, a service account, a federated group, or the account itself), one or more resources, and one or more actions. OVHcloud’s own documentation is explicit that the account used to sign in to the Control Panel, the nichandle, acts as a root identity that cannot have its rights restricted, regardless of any policy in place, while local users, service accounts and federated groups are governed entirely by the IAM policies your team wrote. Which permission groups, such as the OVHcloud-managed globalAdmin group, got attached to which identities, and how many people still hold nichandle-level access, is a decision your organisation made.

Outside the Control Panel, every application that calls the OVHcloud API is issued three credentials together, and OVHcloud’s first steps guide confirms that a key’s rights are restricted only by the HTTP methods and paths entered when it was created, from a single endpoint up to a wildcard covering every API. A Consumer Key can also be delegated to a third-party application once the customer approves the request, so a key issued years ago for one integration can sit outside the parts of the account anyone reviews day to day.

We test the OVHcloud account you actually run: the IAM policies and permission groups applied, the OpenStack users and roles on each Public Cloud project, the security groups on every instance, the Object Storage bucket ACLs, the vRack boundaries, and the kubeconfig access on any Managed Kubernetes cluster. We never test OVHcloud’s own infrastructure, in the same way we test client configuration on Heroku apps rather than Heroku’s platform.

SCOPE

What we review in an OVHcloud account

OV-01

OVHcloud Account and IAM Policies

The OVHcloud account used to sign in to the Control Panel, known as the nichandle, acts as a root identity that cannot have its rights restricted, while IAM policies apply to other identities against specific resources and actions. We test how many people hold nichandle-level access and what each IAM policy actually grants beyond what it should.

OV-02

Local Users, Service Accounts and Two-Factor Authentication

Local users and service accounts are created for human and machine access respectively, and their rights depend entirely on the IAM policies applied to them rather than any default. We test whether two-factor authentication is enforced for every account able to reach IAM policies or billing.

OV-03

API Application Keys, Secrets and Consumer Keys

Calling the OVHcloud API requires an Application Key, Application Secret and Consumer Key issued together, and access is restricted only by the Rights entered when the key was created, down to a single HTTP method on a single path. We test which scopes every live key actually holds against what its integration needs.

OV-04

Public Cloud Project Users and Roles

Access to Horizon and the OpenStack APIs is granted through OpenStack users created inside a Public Cloud project, each assigned the roles that define what they can manage there. We test which roles every OpenStack user actually holds against the access their job requires.

OV-05

Public Cloud Network Security Groups

OVHcloud’s own documentation shows the default security group applied when an instance is launched permits all IPv4 and IPv6 traffic in both directions, and OVHcloud advises creating a separate group for restrictive rules rather than editing the default one. We test which instances are still running on that default, unrestricted group.

OV-06

Object Storage Bucket and Object ACLs

Every bucket and object in OVHcloud Object Storage is private by default, with only the creating account holding full control, and a predefined ACL such as public-read grants the AllUsers group read access instead. We test which buckets and objects carry a public-read or public-read-write ACL that should not be open.

OV-07

vRack Private Network Isolation

vRack routes traffic between dedicated servers, Public Cloud instances and other OVHcloud services outside the public internet, though OVHcloud’s own documentation notes that Public Cloud does not support security groups inside a vRack. We test what is actually reachable across the private network against what should be isolated.

OV-08

Managed Kubernetes: Default Kubeconfig Access

OVHcloud states that the kubeconfig file issued when a Managed Kubernetes cluster is created grants access to everything in the cluster by default, and RBAC objects such as Roles and RoleBindings are the way to narrow that. We test what a distributed kubeconfig can actually reach against the access it was issued for.

OV-09

Managed Kubernetes API Server IP Restrictions

An OVHcloud Managed Kubernetes cluster’s API server accepts connections from any IP address until an authorised client range is added, and OVHcloud is explicit that no restriction applies while that list is empty. We test whether the clusters in scope actually have one configured.

OV-10

Third-Party API Rights Delegation

An external application can request delegated access to an OVHcloud account by asking for a Consumer Key scoped to specific endpoints, which the customer approves through an OVHcloud validation URL before it becomes active. We test which third-party applications hold a live Consumer Key against your account and whether its granted endpoints go further than the integration needs.

OUR PROCESS

OVHcloud Cloud Security Review: From Scope to Attestation

01

Scope and Access

We agree which Public Cloud projects, OpenStack users, Object Storage buckets, Managed Kubernetes clusters and vRack networks are in scope, plus a login or role for each level tested.

02

Configuration and Policy Mapping

We map every IAM policy, API key and security group against what it actually grants.

03

Manual Testing

A CREST-certified tester manually tests security group rules, bucket ACLs, kubeconfig scope and API key rights.

04

Attestation and Retest

You get a technical report with CVSS scores, a walkthrough call, a free retest, and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST OVHcloud pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent OVHcloud Cloud Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,320–£3,410
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£5,450–£8,310
4 to 6 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From OVHcloud Cloud Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our OVHcloud account?

We need at least one OpenStack user for each role in every Public Cloud project in scope, ideally alongside a local user or nichandle-level login for IAM policy review, plus an Application Key, Application Secret and Consumer Key if API-level testing is included.

Will testing touch our live data?

Testing focuses on IAM policies, security groups, bucket ACLs and kubeconfig scope rather than the content of your Object Storage buckets or databases. Where a test record is genuinely needed we agree scope first and remove it afterwards.

Is this hosted on our infrastructure or OVHcloud’s?

Everything runs on OVHcloud’s infrastructure, so there is nothing separate for you to host. The review is scoped to the account configuration you control, not OVHcloud’s underlying platform.

How long does an OVHcloud security review take?

A single account and its Public Cloud projects sit in our 2-day single-estate scope, with a report usually landing around 5 working days after kickoff.

What is out of scope for a single-estate review?

Testing OVHcloud’s own infrastructure, hypervisors or datacentre security is never in scope, and we do not run denial-of-service testing. Application code running inside a Public Cloud instance or on a dedicated server is scoped separately.

Does OVHcloud have a customer penetration-testing policy we need to follow?

OVHcloud does not publish a dedicated customer penetration-testing policy setting out rules of engagement in the way some hyperscale providers do. Its published security contact and vulnerability disclosure programme cover OVHcloud’s own platform rather than customer-run testing of Public Cloud resources, so we confirm OVHcloud’s current terms during scoping before testing begins.

Do you need our source code or admin access?

No. We test with the OpenStack users, local users and API keys you provide, and do not need standing nichandle-level access beyond verifying a specific finding.

Are your testers CREST certified?

Yes. Every engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your OVHcloud account

An OVHcloud account is a set of policies, API keys, security groups and permissions, and one left broad is the way in. We test what your team actually configured, not OVHcloud’s platform. CREST-certified testers, fixed price from £2,320 for a 2-day single-estate scope, quoted within 24 hours.