Point-in-Time Penetration Testing
Raxis Strike
A fixed window, full depth, a report you can hand to an auditor.
Best when you have an audit deadline or a first test to get right.
Set to private. Shared with a guest.
One sharing rule flips an object to public, and a community guest with no login reads your customer records. A senior U.S. engineer maps every object against every role and finds the one that leaks. When we reach what matters, we leave a card.
Org-wide defaults, sharing rules, and “without sharing” Apex that quietly bypass record-level security.
Experience Cloud guest access, the vector behind the 2024 account-takeover disclosures.
Overprivileged roles, “View All” and “Modify All Data,” and permission drift over time.
Custom Apex, triggers, and Aura controllers tested for injection and logic flaws.
REST and SOAP endpoints and third-party packages, tested the way an API engagement would.
Insecure defaults and metadata changes that slip past review and expose fields or logic.
01
We chart objects, profiles, permission sets, sharing rules, guest access, and integrations, the full permission surface.
02
AutoRABIT Guard surfaces misconfigurations, weak permissions, and code-quality issues across your metadata.
03
We validate each finding with a proof of concept: guest data access, privilege escalation, SOQL injection, exposed APIs.
“View All” and “Modify All Data” granted far beyond what any role needs.
Community guest access reaching objects and records it was never meant to.
Apex classes that run past record-level security and hand back restricted data.
Unvalidated input in custom Apex and Aura controllers, used to read the database.
Endpoints and site pages that answer without checking who is asking.
Access that accumulated over three releases a year until nobody could say who could see what.
We detect misconfigurations, weak permissions, and exposed data in your Salesforce setup.
A tailored report showing what a penetration test would surface in your own org.
Where your instance may fall short of PCI DSS, HIPAA, or SOC 2, and how testing closes it.
A short call to talk through the results and your Salesforce security needs.
Raxis Strike
A fixed window, full depth, a report you can hand to an auditor.
Best when you have an audit deadline or a first test to get right.
Raxis Attack
Unlimited manual testing all year, findings live the moment we confirm them.
Best when your org changes with every release and every admin.
Each with a proof of concept, the object and permission at fault, and the fix.
A board-readable read on the risk and what it means for your data.
Findings mapped to the control language your auditor uses, with an attestation letter.
We verify your fixes and deliver a clean final report, at no extra cost.
Salesforce secures the infrastructure; you are responsible for configuring it. The permission system, custom Apex, Lightning components, and integrations introduce many opportunities for misconfiguration. Our testing finds the vulnerabilities unique to your implementation, custom code, permission sets, sharing rules, and integrations, that automated tools and Salesforce's own security cannot catch for you.
AutoRABIT Guard is a strong automated scanner: it finds known misconfigurations, permission issues, and code-quality problems in your metadata. Penetration testing goes further. Our engineers manually validate findings, build proof-of-concept exploits, test business logic, attempt privilege escalation, and simulate real attacker techniques automation cannot. Guard tells you what might be vulnerable; a pentest proves how an attacker exploits it and what the business impact is. We use Guard to accelerate discovery, then apply human expertise.
No. Our testing is designed to be safe and non-disruptive. We use read-only queries where possible, create test records that do not interfere with real data, and coordinate timing with your team. We can test in a sandbox first, though we recommend some production testing since sandbox configurations often differ. We have tested live Salesforce environments for large enterprises without incident.
Yes, and you should prioritize it. Communities with Guest User access are among the most exploited Salesforce attack vectors, and the 2024 account-takeover disclosures targeted Guest User misconfigurations specifically. We test guest permissions, community sharing settings, unauthenticated access points, and the boundary between authenticated and unauthenticated functionality.
Yes. Custom code is where the most critical vulnerabilities often hide. We test Apex classes, triggers, controllers, and Visualforce pages for SOQL/SOSL injection, improper input validation, "with sharing" versus "without sharing" mistakes, sensitive data in debug logs, hardcoded credentials, and business logic flaws, along with custom Aura and Lightning Web Components. We do not just read the code; we exploit it to prove real-world impact.
Our testing supports PCI DSS (Requirement 11.4), the HIPAA Security Rule, SOC 2 Type II, GDPR, and ISO 27001. Reports map findings to specific control requirements to make audits straightforward. For PCI DSS, if you store, process, or transmit cardholder data in Salesforce, annual penetration testing is mandatory and must cover your application, custom code, integrations, and external-facing components.
We assess both the AppExchange apps installed in your org and the integrations connecting Salesforce to external systems. For apps, we review requested permissions, test for data leakage, and analyze their API calls. For integrations, we test authentication (OAuth, API keys, JWT), data transmission, endpoint security, webhook validation, and whether a third-party system can be leveraged to compromise Salesforce. A vulnerable integration can become a backdoor into your data.
Yes, which is why periodic testing matters. Salesforce ships three releases a year, and each can change defaults or expose new vectors, while your team makes ongoing configuration and code changes. We test your current state for issues from recent updates, permission drift from accumulated changes, and misconfigurations that were not present at your last assessment.
We notify your team immediately rather than waiting for the report. For high-severity issues like exposed customer data, authentication bypass, or privilege escalation, we provide verbal notification with emergency mitigation guidance. After testing, you receive a detailed report with proof-of-concept exploits, remediation steps, and prioritized actions, plus a complimentary retest once you have implemented fixes.
Senior US-based Raxis engineers holding certifications such as OSCP and OSCE, with hands-on Salesforce platform experience. No outsourcing, and no junior testers learning on your org.
It depends on the complexity of your org: custom objects and fields, lines of Apex, number of integrations and APIs, whether you run Communities or Experience Cloud, the number of profiles and permission sets, and your compliance requirements. A focused assessment typically starts around $15,000 to $35,000 and takes one to four weeks. Comprehensive testing of a complex enterprise org with extensive customization runs $35,000 to $75,000 or more and takes four weeks or longer. The free AutoRABIT Guard scan is a good way to gauge your posture first. Contact us for a quote sized to your implementation.