TECHNOLOGIES: SALESFORCE EXPERIENCE CLOUD

Salesforce Experience Cloud Penetration Testing

An Experience Cloud guest reaches whatever the guest profile and its Apex controllers allow, with no login involved. We test the profile, sharing rules and every controller a guest can call. CREST-certified testers, fixed price from £4,180 for a 3-day single-site scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Experience Cloud Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Guest

Everything an anonymous visitor can reach on an Experience Cloud site runs through the guest user profile and the Apex controllers exposed to it, so we test both together rather than either in isolation.

Experience Cloud risk concentrates in the guest user access path

A guest user profile is the only access boundary between the public internet and an Experience Cloud site, since nobody using it has authenticated. Object permissions, field-level security and any sharing rule that applies to the guest profile all combine to decide what that anonymous visitor can see, and each of those settings is configured separately. We test the profile’s object and field permissions together with every sharing rule that touches it, rather than assuming one setting alone tells the whole story.

Salesforce’s own Apex documentation sets out three sharing modes for a class: with sharing, without sharing and inherited sharing, and a class without an explicit declaration defaults to with sharing. Salesforce’s own guidance is explicit that a without sharing class can access records the current user could not otherwise reach, and that an inherited sharing class run as an Aura component controller or an @AuraEnabled Lightning web component method executes in with sharing mode. We test every Apex controller a guest or external user can call, what sharing mode it actually runs in, and whether it enforces object and field-level security on top of that.

Public file sharing, a self-registration flow and any custom page or component built for the site each add another way for someone outside your organisation to reach data or create an account without a prior login. We test what a shared file exposes beyond the record it was attached to, what a self-registration handler creates and with which profile, and whether a custom page or component enforces the same permission checks as the rest of the org.

SCOPE

What we pen test on an Experience Cloud site

EC-01

Guest User Profile Object and Field Permissions

The guest user profile is the only access boundary for anyone visiting your site without logging in, holding its own object and field-level permissions independent of any other profile in the org. We test exactly what that profile can view, create, edit or delete across every object it touches.

EC-02

Guest Sharing Rules

A sharing rule can extend the guest user profile’s access to records it would not otherwise see, layered on top of the profile’s own permissions rather than replacing them. We test every sharing rule that includes the guest profile and whether it grants more than the site’s public pages need.

EC-03

External User Sharing Sets and Community Roles

An authenticated Experience Cloud member sits under a role built for external users, and a sharing set can grant that member access to records based on criteria such as account or contact matching rather than ownership. We test whether a member can reach records outside the sharing sets and roles their membership was meant to grant.

EC-04

Apex Sharing Mode on Exposed Controllers

Salesforce’s documentation sets three sharing modes for an Apex class: with sharing, without sharing and inherited sharing, and an inherited sharing class runs in with sharing mode when it is an Aura component controller or an @AuraEnabled method called from a Lightning web component. We test which mode every controller a guest or member can call actually runs in, and what that mode lets it read or write.

EC-05

Object and Field-Level Security Inside Apex

A without sharing class can access records the calling user could not otherwise reach, which Salesforce’s own documentation flags as a reason to reserve it for code that genuinely needs system-level access. We test whether every controller exposed to a guest or external user enforces object and field-level security itself, rather than relying on the sharing mode alone.

EC-06

Public File and Content Sharing

A file or piece of content shared to a public or guest audience can be reachable beyond the specific record or page it was attached to, depending on how the share was configured. We test what a shared file actually exposes and whether it can be reached without going through the page it was meant to be shown on.

EC-07

Self-Registration Handler

A self-registration flow creates a new external user and assigns it a profile and role without staff involvement, and the Apex handler behind that flow decides which fields the new account can set on itself. We test what a self-registered account can access immediately after signup and whether it can set fields it should not control.

EC-08

Custom Pages, Components and Templates

Custom Experience Builder pages, Aura components and Lightning web components built for the site each carry their own visibility and data access logic, separate from the standard Salesforce page layouts they replace. We test whether custom pages and components enforce the same permission checks as the objects and fields they display.

EC-09

Guest Session and Form-Level Controls

A guest session persists across a visitor’s time on the site without a login, and any anti-automation control such as a CAPTCHA on forms is configured separately from the underlying object permissions. We test what a guest session can do over its lifetime and whether form-level controls actually stop automated abuse.

EC-10

Integration With the Core Salesforce Org

An Experience Cloud site runs on the same org as your internal Salesforce data, so a permission gap on the guest or external user side can expose records that were only meant for internal users. We test the boundary between what the site exposes and what the wider org holds.

OUR PROCESS

Salesforce Experience Cloud Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree the site URL, guest and member profiles, and which self-registration, portal or custom Apex functionality is in scope for testing.

02

Guest and Sharing Configuration Mapping

We map guest profile permissions, sharing rules, external user sharing sets and the sharing mode of every Apex controller exposed to the site.

03

Manual Testing

CREST-certified testers manually test guest and member access, Apex controller boundaries, public file sharing and self-registration, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Experience Cloud pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Salesforce Experience Cloud Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£4,180–£5,860
3 to 5 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£8,470–£11,320
7 to 9 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Salesforce Experience Cloud Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Experience Cloud site?

We need the site URL and, if self-registration is not in scope, at least one test account for each external user role and profile you want covered. If any Apex controllers are custom-built for the site, knowing which Aura or Lightning web components call them speeds up scoping.

Will testing touch our live data?

We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as self-registration creating real accounts or emails firing to real addresses, and we do not run destructive tests against real records without that agreement in writing.

How long does an Experience Cloud penetration test take?

A single Experience Cloud site sits in our 3-day single-site scope, with a report typically landing around 8 working days after kickoff. A site with a large number of custom Apex controllers, multiple external user roles or heavy integration work moves into a wider scope.

Do you test the guest user path even if the majority of the site sits behind a login?

Yes. The guest user profile is in scope by default, since it is the access boundary for anyone reaching the site without an account, and it is tested regardless of how much of the site sits behind a login.

What is out of scope for a single-site Experience Cloud test?

The core internal Salesforce org behind the site, where it is not directly reachable through the site’s guest or member access, is out of scope for this test and quoted separately as our wider Salesforce penetration testing. A completely separate site on the same org is also scoped and quoted independently.

Do you need our Apex source code?

No. Testing is black-box against the running site by default. A grey-box option, where we review the sharing mode and permission checks in Apex controllers exposed to the site alongside testing, is available if you want faster or deeper coverage.

Are custom Lightning web components and Aura components covered?

Yes. We test every custom Aura component and Lightning web component built for the site, including the Apex controllers behind them and the sharing mode each one runs in.

Does Salesforce have a customer penetration-testing policy we need to follow?

Yes. Salesforce’s Security Assessment Agreement sets out how a customer may perform a security assessment of their own account, including restrictions on testing any account other than your own and your responsibilities around reporting. We confirm its current terms during scoping and test within the permission it grants.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Experience Cloud site

An Experience Cloud guest reaches whatever the guest profile and its Apex controllers allow, with no login involved. We test the profile, sharing rules and every controller a guest can call. CREST-certified testers, fixed price from £4,180 for a 3-day single-site scope, quoted within 24 hours.