TECHNOLOGIES: QLIK

Qlik Security Review

A mistyped ACCESS field or the wrong space role in Qlik Cloud can hand a user data nobody meant them to see. We test your spaces, Section Access rules and API access. CREST-certified testers, fixed price from £3,280 for a 2-day single-tenant scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Qlik Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
1 role

Qlik Cloud’s Can publish role lets someone push content into a managed space without ever holding the Can view, Can contribute or Can consume data role needed to open what is inside it, and Qlik’s own documentation confirms it.

In Qlik Cloud, the role that publishes content is not the role that can open it

Qlik Cloud content lives inside one of four space types, personal, shared, managed or data, and each carries an entirely separate set of roles. Qlik’s own documentation on space roles lists Owner, Can manage, Can edit, Can edit data in applications, Can view and Can consume data in a shared space, then adds Can publish, Can contribute, Has restricted view and Can operate for a managed space, plus a separate Is owner, Can edit and Can consume data set for a data space. In a managed space, the Can publish role can push applications in without ever holding the Can view, Can contribute or Can consume data role needed to open what was just published, a deliberate split for teams who build against mock data before production content goes live. We map who actually holds each role in every space against who the business meant to have viewing, editing, publishing or managing rights.

Section Access is the mechanism Qlik’s own support articles call the section access table, a script-loaded table that reduces what a signed-in user can see once an app opens. That documentation is specific about how it fails: a reload is rejected outright if the person running it lacks ADMIN in the table’s ACCESS column, if the ACCESS, USERID or USER.EMAIL column name is wrong, or if the field values are not upper case, and a separate Qlik support article confirms a wildcard star in any other field of that table means every value is visible, so a real value in its place is what actually restricts a row. The same documentation notes Section Access can key off an Active Directory group or user name directly, though certain characters break the match entirely. We test every ACCESS, identity and reduction field in the table against the accounts people actually sign in with today, not the accounts the rule was written for.

Access to the Qlik Cloud APIs runs through OAuth2, JWT or API keys, and Qlik’s own developer documentation draws a hard line between them: an API key authenticates with the same permissions as the user who created it, and because API keys do not support scopes, a key with full user-level access cannot be narrowed to least privilege, only rotated or revoked after the fact. A Machine-to-Machine OAuth2 client is different again, since Qlik states it always carries the Tenant Admin role with no user interaction required, and an Impersonation-enabled M2M client can additionally authenticate as any user by userId or subject. Underneath all three sits one trust boundary: Qlik’s documentation states that an API operation not exposed in the interface is reachable by design once the caller holds the matching scope or role, the same lesson behind hidden fields in our Power BI reviews. We test what every API key, OAuth client and custom role actually reaches, not what the interface chooses to show.

SCOPE

What we review in a Qlik tenant

QK-01

Space roles across Personal, Shared, Managed and Data spaces

Qlik Cloud content sits inside one of four space types, personal, shared, managed or data, and Qlik’s documentation lists a different set of roles for each: a shared space runs from Owner and Can manage down to Can view, a managed space adds Can publish, Can contribute and Can operate, and a data space carries its own Is owner, Can edit and Can consume data roles. We test who actually holds each role in every space against who the business meant to have viewing, editing, publishing or managing rights.

QK-02

Section Access: the ACCESS field and identity columns

Section Access is the table Qlik’s own support documentation calls the section access table, and it needs a correctly named ACCESS column holding a value such as ADMIN for whoever reloads the app, plus an identity column such as USERID or USER.EMAIL matching the signed-in user; get the column name or the case of the values wrong and Qlik’s documentation confirms the reload is rejected outright. We test the actual ACCESS and identity values behind every account against what the business meant that account to hold.

QK-03

Reduction fields and what a wildcard actually restricts

Every other field in the section access table doubles as a reduction field, and Qlik’s own troubleshooting documentation confirms a wildcard star in a field means all values for that field are visible to the row’s user, so any other value narrows what they see once the app opens. We test every reduction field against the data model it is meant to restrict, not just the ACCESS and identity columns.

QK-04

Default roles, custom roles and default permissions

Access in Qlik Cloud runs through default roles, also called security roles, which come out of the box and cannot be edited or deleted, alongside custom roles built from individually assigned permissions and default permissions that apply to every user in the tenant unless narrowed. We test what each role and default permission actually grants against who the business intended to hold administrative, publishing or viewing rights tenant-wide.

QK-05

OAuth2 clients: Web, Machine-to-Machine and Impersonation

Qlik Cloud supports several OAuth2 application types, and its own documentation states that a Machine-to-Machine client always carries the Tenant Admin role with no user interaction, while an Impersonation-enabled M2M client can additionally authenticate as any user by userId or subject. We test what every registered OAuth2 client can actually do against what its application type and allowed origins were meant to permit.

QK-06

API keys: the same permissions as the person who created them

An API key authenticates with the same permissions as the user who generated it, and Qlik’s own documentation warns that because API keys do not support scopes, a key with full user-level access cannot be narrowed to least privilege and can only be rotated or revoked after the fact. We test which accounts hold the Manage API Keys permission, and what every live key can actually reach today.

QK-07

JWT authentication and the groups claim for embedding

For embedded and legacy integrations, Qlik Cloud accepts a signed JWT carrying a sub, name and email for the user, and Qlik’s documentation confirms groups is the only optional claim it currently reads, an array of group names an embedding application’s own logic can use to decide what that user sees. We test what identity and group membership a JWT actually carries into an embed against the user it claims to represent.

QK-08

The API trust boundary: a hidden menu item is not access control

Qlik’s own documentation states plainly that API access to an operation not visible in the interface is by design if the caller holds the matching scope or role, because the trust boundary is the permission model, not what a menu shows, the same principle behind hidden fields in Power BI’s object-level security. We test every OAuth scope, custom role and API key against what it actually reaches, not against what the interface chooses to display.

QK-09

Managed spaces: publishing content without holding access to it

Qlik’s documentation confirms a managed space’s Can publish role can push applications into the space but cannot open anything inside it, a deliberate separation of duties for teams building against mock data before it reaches production content. We test whether that separation actually holds today, and whether a publisher role has quietly picked up view or consume rights nobody intended.

QK-10

Data gateways and API metadata exposure across data spaces

Qlik Data Gateway – Direct Access gives Qlik Cloud a strictly outbound, encrypted and mutually authenticated route to data sources behind a firewall or inside a VPC, and Qlik’s own documentation on data space permissions separately warns that querying a project through the API returns metadata for its connections, databases and tables regardless of whether the caller can access those objects directly. We test what every gateway connection and data space API caller can actually reach, including metadata nobody meant to expose.

OUR PROCESS

Qlik Security Review: From Scope to Attestation

01

Space, Role and Section Access Mapping

We list every space in scope, its roles and members, the section access table behind each app, and current tenant, OAuth client and API key configuration.

02

Space, Role and Section Access Testing

Every space role is tested against real accounts, Section Access ACCESS, identity and reduction fields are tested against actual logins, and we test what each custom role and default role grants in practice.

03

API, OAuth and Embedding Testing

We test OAuth2 clients, API keys, JWT-based embedding and any data gateway connection, confirming what each credential and scope actually reaches against the interface’s stated limits.

04

Reporting and Retest

Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, free retest after remediation and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Qlik pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Qlik Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£3,280–£4,820
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£7,710–£11,740
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Qlik Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need?

Tenant Admin access to the Qlik Cloud tenant under test, or at minimum Can manage access to every space in scope, plus a login for each space role and Section Access identity you want tested. Read access to OAuth client and API key configuration isn’t required to start, but it speeds up confirming what we find.

Will you touch our live data?

We test read-only against production by default. Where proving a Section Access rule, an API key’s reach or a data gateway connection needs real records, we agree a specific dataset or test tenant with you first, and anything we create during testing is documented and removed afterwards.

Is this hosted on our infrastructure or Qlik’s?

Qlik Cloud runs entirely on Qlik’s infrastructure, so there is nothing of the platform itself to host or test. If you run Qlik Sense Enterprise on Windows on your own servers instead, the server and its host form a separate scope we agree with you first; either way this review is scoped to your spaces, roles, Section Access rules, API keys and OAuth clients, not the underlying Qlik product.

Does this cover Qlik Sense Enterprise on Windows the same way?

Not exactly. This page is scoped to a Qlik Cloud tenant, its spaces, roles, Section Access and API access. Qlik Sense Enterprise on Windows uses the same Section Access mechanism inside a site rather than a tenant, with its own Qlik Management Console roles, and we scope that separately once we know which deployment you run.

What is out of scope?

Qlik’s own infrastructure, other tenants sharing the same Qlik Cloud region, denial-of-service testing, and the destination system behind a data gateway connection are all out of scope here; we test the gateway connection itself, not the third-party source or target it reaches.

Is penetration testing our own Qlik Cloud tenant allowed under Qlik’s rules?

We confirm Qlik’s current customer security testing terms with you during scoping and test only within whatever authorisation that process requires.

How long does a Qlik test take?

A single-tenant engagement covering a handful of spaces and Section Access rules typically runs to a 2-day scope. More spaces, embedded scenarios or data gateway connections extend it, and we confirm the exact day count once we have seen the tenant.

Do you need the source of any embedded application?

No, though if reports are embedded for your own customers using a JWT-based integration, having the code that signs the token and sets the groups claim speeds up root-causing anything we find. A source code review is a separate service that pairs well with this one.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Qlik tenant

A mistyped ACCESS field or the wrong space role in Qlik Cloud can hand a user data nobody meant them to see. We test your spaces, Section Access rules and API access. CREST-certified testers, fixed price from £3,280 for a 2-day single-tenant scope, quoted within 24 hours.