Softr App Security Review
Softr warns that an Airtable view or Sheets filter is not a security measure. We test whether user groups and data restrictions actually match what the base or sheet exposes. CREST-certified testers, fixed price from £2,270 for a 2-day single-app scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
By default, Softr’s own documentation says users are unrestricted and can freely view, create, edit and delete records until a Global Data Restriction is added; nothing is scoped until you set the rule.
Softr’s filters run on the server, but the Airtable base or Google Sheet behind them can hold more than the app shows
Softr’s own App Security guide states that user groups, page and block visibility and conditional filters are all evaluated server-side, so they cannot be tricked from the browser, and we do not dispute that. The same guide is just as direct about what does not count as a control: an Airtable view or a Google Sheets filter, and the number of items a block shows per page, are explicitly listed as things not to rely on for security, because Softr reads the whole connected table regardless of any view or filter set up on the source itself.
Softr’s User Groups feature drives most of that server-side evaluation: a default Logged-in Users or Non-logged-in Users group, or a custom static or condition-based group, controls page, block and action visibility, and page or block restrictions are hierarchical, so limiting a page limits everything on it. Global Data Restrictions add a second, app-wide layer of View, Create, Edit and Delete rules scoped to a table and a user group, but Softr’s own documentation is explicit that users are unrestricted by default until a rule is added, and that a Can’t restriction always wins over a conflicting Can only rule from a different group. We test what each user group and restriction combination was actually configured to do, not what the page layout implies.
The connected data source is where Softr’s own guidance turns into a checklist. An Airtable connection can run on OAuth, limited to 5 requests a second, or a Personal Access Token that raises the account-level limit to 50 requests a second while Airtable still caps each individual base at 5, and Softr’s own setup guidance recommends granting a token every scope it lists rather than only the ones a given app needs. A Google Sheet has no equivalent view or field-type layer at all, and Softr needs edit access to it just to maintain its own Record ID column, so whatever the sheet’s own sharing settings allow is exactly what Softr, and anyone else with that link, can reach. It is the same question we test on a Bubble app’s Data API exposure: whether the source behind the interface was locked down to match it.
SCOPE
What we pen test on a Softr app
User groups: default and custom
Every user is automatically in the default Non-logged-in Users or Logged-in Users group, and a custom group on the Professional plan or above is either static, built by adding users manually, or dynamic, built from a condition on a user attribute or a connected Stripe subscription; a user added to a dynamic group by its condition cannot be removed manually, only by editing the condition itself. We test who actually falls into each group against what that group’s pages, blocks and actions were built to allow.
Page, block and action visibility, and how they cascade
Visibility for a page, a block or an action button can be set to All Users, Logged in Users, Non Logged in Users or a specific custom user group, and Softr’s own documentation confirms visibility rules are hierarchical, so restricting a page restricts every block and action inside it too; gated pages and blocks are also excluded from search engine crawling. We test every page and block against the user group it was actually set to, not the one its position in the app implies.
Conditional filters keyed to the logged-in user
A conditional filter can match a field against the Logged-in User’s Email or Email-Domain, or against any field from a data source synced to users, so a task list filtered on Assignee equals Logged-in User’s Email shows each user only their own rows; the same conditional filtering also powers record filters on list, table, grid and kanban blocks. We test every dynamic filter for whether the field it matches against can be relied on to identify the right user.
Global Data Restrictions: view, create, edit, delete, and what happens with none
Global Data Restrictions apply View, Create, Edit or Delete rules, each scoped to Can only or Can’t for a chosen table and user group, and Softr’s own documentation states that users are unrestricted by default, free to view, create, edit and delete records until a restriction is added; where two groups’ rules conflict, a Can’t restriction always takes precedence. Only one restriction rule is allowed per table and user group combination, and Create, Edit and Delete restrictions require the Business plan or above while View is available on every plan; we test whether the restrictions actually configured match what each user group is meant to reach.
What Softr’s own security guidance says not to rely on
Softr’s App Security documentation lists specific don’ts for anyone building member-only or role-specific pages: do not use an Airtable view or a Google Sheets filter as a security measure, do not use a block’s items-per-page limit as a security measure, and do not store public, member-only and role-specific data in the same data source table. We test every app in scope against that exact checklist, since Softr’s own guidance is that its server-side checks cannot be tricked, but a table built the wrong way around them still exposes everything in it.
Connecting Airtable: OAuth, Personal Access Tokens and scope
An Airtable connection authenticates by OAuth, capped at 5 requests a second, or a Personal Access Token, which raises the account-level limit to 50 requests a second while Airtable still enforces a 5-requests-a-second cap on each individual base; Softr’s own setup guidance recommends granting a token every scope it lists and access to all current and future bases, rather than only what a given app uses. We test what scope and which bases the connected token or OAuth grant actually covers.
Connecting Google Sheets: edit access and no source-side filtering
Softr needs edit permission on a connected Google Sheet just to create and maintain its own Record ID column, and unlike Airtable, a Google Sheet has no equivalent view or per-field permission layer at all, so whatever the sheet’s own sharing setting allows is exactly what is reachable through it. We test the sharing settings on every connected sheet or Airtable base against what the Softr app in front of it was built to restrict.
Sign-in methods: email, Google, magic links and sign-up rules
User Authentication can require a password, a one-time code, or both together for two-factor sign-in, alongside optional Google Sign-in and Magic Links, which Softr’s own documentation warns are as good as an email and password since anyone holding the link can sign in as that user; Sign-Up is separately set to Disabled, Open or Domain restricted. We test which authentication methods are actually enabled, and whether a magic link or an open sign-up route reaches further than the rest of the app’s access rules assume.
Google Sign-in setup status and SAML/OpenID SSO
A Google Sign-in OAuth client left in Testing status in Google Cloud only allows the up to 100 accounts on its test-user list to sign in, even when every other setting is correct, and the Internal user type restricts sign-in to a single Google Workspace organisation; SAML and OpenID single sign-on are available as an Enterprise plan feature or a paid Business add-on, and Page Rules redirects do not apply to either. We test which of these is actually live against what Softr Studio’s Authentication tab says is configured.
Session timeouts and account security settings
The Authentication tab’s Security section sets how long a session lasts before a user is logged out on a fixed schedule, and separately how long an idle, open session is allowed to sit before it ends; both apply regardless of which sign-in method a user came in through. We test what these are actually set to against how long the app in scope is meant to trust an unattended session.
OUR PROCESS
Softr App Security Review: From Scope to Attestation
App and Data Source Mapping
We map every user group, page and block visibility rule, Global Data Restriction and connected Airtable base or Google Sheet behind the app in scope.
User Group and Filter Testing
We test from accounts in every user group in scope, checking what each group’s visibility rules, conditional filters and Global Data Restrictions actually allow against live records.
Authentication and Data Source Testing
A CREST-certified tester tests sign-in methods, magic links and session settings, and checks whether the connected Airtable base or Google Sheet’s own sharing matches what the app is meant to restrict.
Reporting and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Softr pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Softr App Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Softr For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Softr App Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Softr app?
A login for each user group you want tested is enough to start. Studio access to see user groups, Global Data Restrictions and the connected Airtable base or Google Sheet speeds up confirming what we find, though it is optional.
Will this touch our live data?
We test read-only against production by default. Where proving a create, edit or delete needs real records, we agree a sandbox base, sheet or specific test data with you first, and anything we create during testing is documented and removed afterwards.
Is this different for Airtable versus Google Sheets as the backend?
Testing adapts to whichever data source is connected, since user groups and Global Data Restrictions are Softr settings either way, but Airtable’s own view and scope permissions and a Google Sheet’s sharing settings are checked separately against what the app is meant to restrict.
Does Softr have a policy for customers testing their own app?
We confirm Softr’s current terms with you during scoping before testing starts.
What is out of scope?
Softr’s own hosting platform and infrastructure, other customers’ apps on shared Softr infrastructure, and denial-of-service testing are all out of scope. We test the app, its user groups, visibility rules, Global Data Restrictions, sign-in settings and connected data source configuration.
How long does a Softr app test take?
A single app sits in our 2-day single-app scope, rising with the number of user groups, pages and connected data sources in scope. We confirm the exact day count once we have seen the app.
Do you need our Studio account or just a published app?
A published app with test accounts in every relevant user group is enough to start. Studio access speeds up root-causing anything we find, particularly around Global Data Restrictions and connected data source permissions that are not visible from outside the app, but it is not required.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Softr application
Softr warns that an Airtable view or Sheets filter is not a security measure. We test whether user groups and data restrictions actually match what the base or sheet exposes. CREST-certified testers, fixed price from £2,270 for a 2-day single-app scope, quoted within 24 hours.



