TECHNOLOGIES: SOFTR

Softr App Security Review

Softr warns that an Airtable view or Sheets filter is not a security measure. We test whether user groups and data restrictions actually match what the base or sheet exposes. CREST-certified testers, fixed price from £2,270 for a 2-day single-app scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Softr Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Open

By default, Softr’s own documentation says users are unrestricted and can freely view, create, edit and delete records until a Global Data Restriction is added; nothing is scoped until you set the rule.

Softr’s filters run on the server, but the Airtable base or Google Sheet behind them can hold more than the app shows

Softr’s own App Security guide states that user groups, page and block visibility and conditional filters are all evaluated server-side, so they cannot be tricked from the browser, and we do not dispute that. The same guide is just as direct about what does not count as a control: an Airtable view or a Google Sheets filter, and the number of items a block shows per page, are explicitly listed as things not to rely on for security, because Softr reads the whole connected table regardless of any view or filter set up on the source itself.

Softr’s User Groups feature drives most of that server-side evaluation: a default Logged-in Users or Non-logged-in Users group, or a custom static or condition-based group, controls page, block and action visibility, and page or block restrictions are hierarchical, so limiting a page limits everything on it. Global Data Restrictions add a second, app-wide layer of View, Create, Edit and Delete rules scoped to a table and a user group, but Softr’s own documentation is explicit that users are unrestricted by default until a rule is added, and that a Can’t restriction always wins over a conflicting Can only rule from a different group. We test what each user group and restriction combination was actually configured to do, not what the page layout implies.

The connected data source is where Softr’s own guidance turns into a checklist. An Airtable connection can run on OAuth, limited to 5 requests a second, or a Personal Access Token that raises the account-level limit to 50 requests a second while Airtable still caps each individual base at 5, and Softr’s own setup guidance recommends granting a token every scope it lists rather than only the ones a given app needs. A Google Sheet has no equivalent view or field-type layer at all, and Softr needs edit access to it just to maintain its own Record ID column, so whatever the sheet’s own sharing settings allow is exactly what Softr, and anyone else with that link, can reach. It is the same question we test on a Bubble app’s Data API exposure: whether the source behind the interface was locked down to match it.

SCOPE

What we pen test on a Softr app

SF-01

User groups: default and custom

Every user is automatically in the default Non-logged-in Users or Logged-in Users group, and a custom group on the Professional plan or above is either static, built by adding users manually, or dynamic, built from a condition on a user attribute or a connected Stripe subscription; a user added to a dynamic group by its condition cannot be removed manually, only by editing the condition itself. We test who actually falls into each group against what that group’s pages, blocks and actions were built to allow.

SF-02

Page, block and action visibility, and how they cascade

Visibility for a page, a block or an action button can be set to All Users, Logged in Users, Non Logged in Users or a specific custom user group, and Softr’s own documentation confirms visibility rules are hierarchical, so restricting a page restricts every block and action inside it too; gated pages and blocks are also excluded from search engine crawling. We test every page and block against the user group it was actually set to, not the one its position in the app implies.

SF-03

Conditional filters keyed to the logged-in user

A conditional filter can match a field against the Logged-in User’s Email or Email-Domain, or against any field from a data source synced to users, so a task list filtered on Assignee equals Logged-in User’s Email shows each user only their own rows; the same conditional filtering also powers record filters on list, table, grid and kanban blocks. We test every dynamic filter for whether the field it matches against can be relied on to identify the right user.

SF-04

Global Data Restrictions: view, create, edit, delete, and what happens with none

Global Data Restrictions apply View, Create, Edit or Delete rules, each scoped to Can only or Can’t for a chosen table and user group, and Softr’s own documentation states that users are unrestricted by default, free to view, create, edit and delete records until a restriction is added; where two groups’ rules conflict, a Can’t restriction always takes precedence. Only one restriction rule is allowed per table and user group combination, and Create, Edit and Delete restrictions require the Business plan or above while View is available on every plan; we test whether the restrictions actually configured match what each user group is meant to reach.

SF-05

What Softr’s own security guidance says not to rely on

Softr’s App Security documentation lists specific don’ts for anyone building member-only or role-specific pages: do not use an Airtable view or a Google Sheets filter as a security measure, do not use a block’s items-per-page limit as a security measure, and do not store public, member-only and role-specific data in the same data source table. We test every app in scope against that exact checklist, since Softr’s own guidance is that its server-side checks cannot be tricked, but a table built the wrong way around them still exposes everything in it.

SF-06

Connecting Airtable: OAuth, Personal Access Tokens and scope

An Airtable connection authenticates by OAuth, capped at 5 requests a second, or a Personal Access Token, which raises the account-level limit to 50 requests a second while Airtable still enforces a 5-requests-a-second cap on each individual base; Softr’s own setup guidance recommends granting a token every scope it lists and access to all current and future bases, rather than only what a given app uses. We test what scope and which bases the connected token or OAuth grant actually covers.

SF-07

Connecting Google Sheets: edit access and no source-side filtering

Softr needs edit permission on a connected Google Sheet just to create and maintain its own Record ID column, and unlike Airtable, a Google Sheet has no equivalent view or per-field permission layer at all, so whatever the sheet’s own sharing setting allows is exactly what is reachable through it. We test the sharing settings on every connected sheet or Airtable base against what the Softr app in front of it was built to restrict.

SF-08

Sign-in methods: email, Google, magic links and sign-up rules

User Authentication can require a password, a one-time code, or both together for two-factor sign-in, alongside optional Google Sign-in and Magic Links, which Softr’s own documentation warns are as good as an email and password since anyone holding the link can sign in as that user; Sign-Up is separately set to Disabled, Open or Domain restricted. We test which authentication methods are actually enabled, and whether a magic link or an open sign-up route reaches further than the rest of the app’s access rules assume.

SF-09

Google Sign-in setup status and SAML/OpenID SSO

A Google Sign-in OAuth client left in Testing status in Google Cloud only allows the up to 100 accounts on its test-user list to sign in, even when every other setting is correct, and the Internal user type restricts sign-in to a single Google Workspace organisation; SAML and OpenID single sign-on are available as an Enterprise plan feature or a paid Business add-on, and Page Rules redirects do not apply to either. We test which of these is actually live against what Softr Studio’s Authentication tab says is configured.

SF-10

Session timeouts and account security settings

The Authentication tab’s Security section sets how long a session lasts before a user is logged out on a fixed schedule, and separately how long an idle, open session is allowed to sit before it ends; both apply regardless of which sign-in method a user came in through. We test what these are actually set to against how long the app in scope is meant to trust an unattended session.

OUR PROCESS

Softr App Security Review: From Scope to Attestation

01

App and Data Source Mapping

We map every user group, page and block visibility rule, Global Data Restriction and connected Airtable base or Google Sheet behind the app in scope.

02

User Group and Filter Testing

We test from accounts in every user group in scope, checking what each group’s visibility rules, conditional filters and Global Data Restrictions actually allow against live records.

03

Authentication and Data Source Testing

A CREST-certified tester tests sign-in methods, magic links and session settings, and checks whether the connected Airtable base or Google Sheet’s own sharing matches what the app is meant to restrict.

04

Reporting and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Softr pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Softr App Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,270–£3,340
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£5,330–£8,130
4 to 6 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Softr App Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Softr app?

A login for each user group you want tested is enough to start. Studio access to see user groups, Global Data Restrictions and the connected Airtable base or Google Sheet speeds up confirming what we find, though it is optional.

Will this touch our live data?

We test read-only against production by default. Where proving a create, edit or delete needs real records, we agree a sandbox base, sheet or specific test data with you first, and anything we create during testing is documented and removed afterwards.

Is this different for Airtable versus Google Sheets as the backend?

Testing adapts to whichever data source is connected, since user groups and Global Data Restrictions are Softr settings either way, but Airtable’s own view and scope permissions and a Google Sheet’s sharing settings are checked separately against what the app is meant to restrict.

Does Softr have a policy for customers testing their own app?

We confirm Softr’s current terms with you during scoping before testing starts.

What is out of scope?

Softr’s own hosting platform and infrastructure, other customers’ apps on shared Softr infrastructure, and denial-of-service testing are all out of scope. We test the app, its user groups, visibility rules, Global Data Restrictions, sign-in settings and connected data source configuration.

How long does a Softr app test take?

A single app sits in our 2-day single-app scope, rising with the number of user groups, pages and connected data sources in scope. We confirm the exact day count once we have seen the app.

Do you need our Studio account or just a published app?

A published app with test accounts in every relevant user group is enough to start. Studio access speeds up root-causing anything we find, particularly around Global Data Restrictions and connected data source permissions that are not visible from outside the app, but it is not required.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Softr application

Softr warns that an Airtable view or Sheets filter is not a security measure. We test whether user groups and data restrictions actually match what the base or sheet exposes. CREST-certified testers, fixed price from £2,270 for a 2-day single-app scope, quoted within 24 hours.