Qlik Security Review
A mistyped ACCESS field or the wrong space role in Qlik Cloud can hand a user data nobody meant them to see. We test your spaces, Section Access rules and API access. CREST-certified testers, fixed price from £3,280 for a 2-day single-tenant scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Qlik Cloud’s Can publish role lets someone push content into a managed space without ever holding the Can view, Can contribute or Can consume data role needed to open what is inside it, and Qlik’s own documentation confirms it.
In Qlik Cloud, the role that publishes content is not the role that can open it
Qlik Cloud content lives inside one of four space types, personal, shared, managed or data, and each carries an entirely separate set of roles. Qlik’s own documentation on space roles lists Owner, Can manage, Can edit, Can edit data in applications, Can view and Can consume data in a shared space, then adds Can publish, Can contribute, Has restricted view and Can operate for a managed space, plus a separate Is owner, Can edit and Can consume data set for a data space. In a managed space, the Can publish role can push applications in without ever holding the Can view, Can contribute or Can consume data role needed to open what was just published, a deliberate split for teams who build against mock data before production content goes live. We map who actually holds each role in every space against who the business meant to have viewing, editing, publishing or managing rights.
Section Access is the mechanism Qlik’s own support articles call the section access table, a script-loaded table that reduces what a signed-in user can see once an app opens. That documentation is specific about how it fails: a reload is rejected outright if the person running it lacks ADMIN in the table’s ACCESS column, if the ACCESS, USERID or USER.EMAIL column name is wrong, or if the field values are not upper case, and a separate Qlik support article confirms a wildcard star in any other field of that table means every value is visible, so a real value in its place is what actually restricts a row. The same documentation notes Section Access can key off an Active Directory group or user name directly, though certain characters break the match entirely. We test every ACCESS, identity and reduction field in the table against the accounts people actually sign in with today, not the accounts the rule was written for.
Access to the Qlik Cloud APIs runs through OAuth2, JWT or API keys, and Qlik’s own developer documentation draws a hard line between them: an API key authenticates with the same permissions as the user who created it, and because API keys do not support scopes, a key with full user-level access cannot be narrowed to least privilege, only rotated or revoked after the fact. A Machine-to-Machine OAuth2 client is different again, since Qlik states it always carries the Tenant Admin role with no user interaction required, and an Impersonation-enabled M2M client can additionally authenticate as any user by userId or subject. Underneath all three sits one trust boundary: Qlik’s documentation states that an API operation not exposed in the interface is reachable by design once the caller holds the matching scope or role, the same lesson behind hidden fields in our Power BI reviews. We test what every API key, OAuth client and custom role actually reaches, not what the interface chooses to show.
SCOPE
What we review in a Qlik tenant
Space roles across Personal, Shared, Managed and Data spaces
Qlik Cloud content sits inside one of four space types, personal, shared, managed or data, and Qlik’s documentation lists a different set of roles for each: a shared space runs from Owner and Can manage down to Can view, a managed space adds Can publish, Can contribute and Can operate, and a data space carries its own Is owner, Can edit and Can consume data roles. We test who actually holds each role in every space against who the business meant to have viewing, editing, publishing or managing rights.
Section Access: the ACCESS field and identity columns
Section Access is the table Qlik’s own support documentation calls the section access table, and it needs a correctly named ACCESS column holding a value such as ADMIN for whoever reloads the app, plus an identity column such as USERID or USER.EMAIL matching the signed-in user; get the column name or the case of the values wrong and Qlik’s documentation confirms the reload is rejected outright. We test the actual ACCESS and identity values behind every account against what the business meant that account to hold.
Reduction fields and what a wildcard actually restricts
Every other field in the section access table doubles as a reduction field, and Qlik’s own troubleshooting documentation confirms a wildcard star in a field means all values for that field are visible to the row’s user, so any other value narrows what they see once the app opens. We test every reduction field against the data model it is meant to restrict, not just the ACCESS and identity columns.
Default roles, custom roles and default permissions
Access in Qlik Cloud runs through default roles, also called security roles, which come out of the box and cannot be edited or deleted, alongside custom roles built from individually assigned permissions and default permissions that apply to every user in the tenant unless narrowed. We test what each role and default permission actually grants against who the business intended to hold administrative, publishing or viewing rights tenant-wide.
OAuth2 clients: Web, Machine-to-Machine and Impersonation
Qlik Cloud supports several OAuth2 application types, and its own documentation states that a Machine-to-Machine client always carries the Tenant Admin role with no user interaction, while an Impersonation-enabled M2M client can additionally authenticate as any user by userId or subject. We test what every registered OAuth2 client can actually do against what its application type and allowed origins were meant to permit.
API keys: the same permissions as the person who created them
An API key authenticates with the same permissions as the user who generated it, and Qlik’s own documentation warns that because API keys do not support scopes, a key with full user-level access cannot be narrowed to least privilege and can only be rotated or revoked after the fact. We test which accounts hold the Manage API Keys permission, and what every live key can actually reach today.
JWT authentication and the groups claim for embedding
For embedded and legacy integrations, Qlik Cloud accepts a signed JWT carrying a sub, name and email for the user, and Qlik’s documentation confirms groups is the only optional claim it currently reads, an array of group names an embedding application’s own logic can use to decide what that user sees. We test what identity and group membership a JWT actually carries into an embed against the user it claims to represent.
The API trust boundary: a hidden menu item is not access control
Qlik’s own documentation states plainly that API access to an operation not visible in the interface is by design if the caller holds the matching scope or role, because the trust boundary is the permission model, not what a menu shows, the same principle behind hidden fields in Power BI’s object-level security. We test every OAuth scope, custom role and API key against what it actually reaches, not against what the interface chooses to display.
Managed spaces: publishing content without holding access to it
Qlik’s documentation confirms a managed space’s Can publish role can push applications into the space but cannot open anything inside it, a deliberate separation of duties for teams building against mock data before it reaches production content. We test whether that separation actually holds today, and whether a publisher role has quietly picked up view or consume rights nobody intended.
Data gateways and API metadata exposure across data spaces
Qlik Data Gateway – Direct Access gives Qlik Cloud a strictly outbound, encrypted and mutually authenticated route to data sources behind a firewall or inside a VPC, and Qlik’s own documentation on data space permissions separately warns that querying a project through the API returns metadata for its connections, databases and tables regardless of whether the caller can access those objects directly. We test what every gateway connection and data space API caller can actually reach, including metadata nobody meant to expose.
OUR PROCESS
Qlik Security Review: From Scope to Attestation
Space, Role and Section Access Mapping
We list every space in scope, its roles and members, the section access table behind each app, and current tenant, OAuth client and API key configuration.
Space, Role and Section Access Testing
Every space role is tested against real accounts, Section Access ACCESS, identity and reduction fields are tested against actual logins, and we test what each custom role and default role grants in practice.
API, OAuth and Embedding Testing
We test OAuth2 clients, API keys, JWT-based embedding and any data gateway connection, confirming what each credential and scope actually reaches against the interface’s stated limits.
Reporting and Retest
Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, free retest after remediation and an attestation letter.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Qlik pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Qlik Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Qlik For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Qlik Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need?
Tenant Admin access to the Qlik Cloud tenant under test, or at minimum Can manage access to every space in scope, plus a login for each space role and Section Access identity you want tested. Read access to OAuth client and API key configuration isn’t required to start, but it speeds up confirming what we find.
Will you touch our live data?
We test read-only against production by default. Where proving a Section Access rule, an API key’s reach or a data gateway connection needs real records, we agree a specific dataset or test tenant with you first, and anything we create during testing is documented and removed afterwards.
Is this hosted on our infrastructure or Qlik’s?
Qlik Cloud runs entirely on Qlik’s infrastructure, so there is nothing of the platform itself to host or test. If you run Qlik Sense Enterprise on Windows on your own servers instead, the server and its host form a separate scope we agree with you first; either way this review is scoped to your spaces, roles, Section Access rules, API keys and OAuth clients, not the underlying Qlik product.
Does this cover Qlik Sense Enterprise on Windows the same way?
Not exactly. This page is scoped to a Qlik Cloud tenant, its spaces, roles, Section Access and API access. Qlik Sense Enterprise on Windows uses the same Section Access mechanism inside a site rather than a tenant, with its own Qlik Management Console roles, and we scope that separately once we know which deployment you run.
What is out of scope?
Qlik’s own infrastructure, other tenants sharing the same Qlik Cloud region, denial-of-service testing, and the destination system behind a data gateway connection are all out of scope here; we test the gateway connection itself, not the third-party source or target it reaches.
Is penetration testing our own Qlik Cloud tenant allowed under Qlik’s rules?
We confirm Qlik’s current customer security testing terms with you during scoping and test only within whatever authorisation that process requires.
How long does a Qlik test take?
A single-tenant engagement covering a handful of spaces and Section Access rules typically runs to a 2-day scope. More spaces, embedded scenarios or data gateway connections extend it, and we confirm the exact day count once we have seen the tenant.
Do you need the source of any embedded application?
No, though if reports are embedded for your own customers using a JWT-based integration, having the code that signs the token and sets the groups claim speeds up root-causing anything we find. A source code review is a separate service that pairs well with this one.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Qlik tenant
A mistyped ACCESS field or the wrong space role in Qlik Cloud can hand a user data nobody meant them to see. We test your spaces, Section Access rules and API access. CREST-certified testers, fixed price from £3,280 for a 2-day single-tenant scope, quoted within 24 hours.



