Salesforce Penetration Testing

Set to private. Shared with a guest.

One sharing rule flips an object to public, and a community guest with no login reads your customer records. A senior U.S. engineer maps every object against every role and finds the one that leaks. When we reach what matters, we leave a card.

What We Test

Salesforce secures the platform. Everything above it is yours: the objects, the profiles, the sharing rules, the Apex, and every app you installed. That is what we test.

Sharing Rules & OWD

Org-wide defaults, sharing rules, and “without sharing” Apex that quietly bypass record-level security.

Guest Users & Communities

Experience Cloud guest access, the vector behind the 2024 account-takeover disclosures.

Profiles & Permission Sets

Overprivileged roles, “View All” and “Modify All Data,” and permission drift over time.

Apex & SOQL Injection

Custom Apex, triggers, and Aura controllers tested for injection and logic flaws.

APIs & AppExchange

REST and SOAP endpoints and third-party packages, tested the way an API engagement would.

Config & Metadata Drift

Insecure defaults and metadata changes that slip past review and expose fields or logic.

How We Test

Automation finds the known misconfigurations fast; a senior engineer proves which of them an attacker can actually use.

01

Map the Org

We chart objects, profiles, permission sets, sharing rules, guest access, and integrations, the full permission surface.

02

Scan with Guard

AutoRABIT Guard surfaces misconfigurations, weak permissions, and code-quality issues across your metadata.

03

Exploit by Hand

We validate each finding with a proof of concept: guest data access, privilege escalation, SOQL injection, exposed APIs.

04

Report & Retest

Findings land in Raxis One with proof and a fix. You remediate, we verify.

Findings We See in the Wild

Not one of these is a flaw in Salesforce. Every one of them is in orgs we test.

Overprivileged Profiles

“View All” and “Modify All Data” granted far beyond what any role needs.

Guest User Exposure

Community guest access reaching objects and records it was never meant to.

Without-Sharing Apex

Apex classes that run past record-level security and hand back restricted data.

SOQL Injection

Unvalidated input in custom Apex and Aura controllers, used to read the database.

Unauthenticated APIs

Endpoints and site pages that answer without checking who is asking.

Permission Drift

Access that accumulated over three releases a year until nobody could say who could see what.

Try a Free Salesforce Assessment

For qualified organizations, we run an AutoRABIT Guard scan of your org and walk you through what a full Raxis penetration test would uncover, using real findings from your environment. No pressure, no commitment.

Free Guard Scan

We detect misconfigurations, weak permissions, and exposed data in your Salesforce setup.

Real Findings

A tailored report showing what a penetration test would surface in your own org.

Compliance Gap Analysis

Where your instance may fall short of PCI DSS, HIPAA, or SOC 2, and how testing closes it.

A Walkthrough Call

A short call to talk through the results and your Salesforce security needs.

Two Ways to Test Your Org

Same senior engineers, same manual tradecraft, same live findings. The difference is when you want us on it: once, for a fixed window, or all year.

What You Get

Written by the engineer who mapped your org, for the admins and developers who have to change it. Track findings in real time with Raxis One.

Technical Findings

Each with a proof of concept, the object and permission at fault, and the fix.

Executive Summary

A board-readable read on the risk and what it means for your data.

Compliance Mapping

Findings mapped to the control language your auditor uses, with an attestation letter.

Included Retest

We verify your fixes and deliver a clean final report, at no extra cost.

FAQ: Salesforce Penetration Testing

Why does Salesforce need penetration testing if it’s a secure cloud platform?

Salesforce secures the infrastructure; you are responsible for configuring it. The permission system, custom Apex, Lightning components, and integrations introduce many opportunities for misconfiguration. Our testing finds the vulnerabilities unique to your implementation, custom code, permission sets, sharing rules, and integrations, that automated tools and Salesforce's own security cannot catch for you.

What’s the difference between an AutoRABIT Guard scan and full penetration testing?

AutoRABIT Guard is a strong automated scanner: it finds known misconfigurations, permission issues, and code-quality problems in your metadata. Penetration testing goes further. Our engineers manually validate findings, build proof-of-concept exploits, test business logic, attempt privilege escalation, and simulate real attacker techniques automation cannot. Guard tells you what might be vulnerable; a pentest proves how an attacker exploits it and what the business impact is. We use Guard to accelerate discovery, then apply human expertise.

Will penetration testing disrupt our Salesforce production environment?

No. Our testing is designed to be safe and non-disruptive. We use read-only queries where possible, create test records that do not interfere with real data, and coordinate timing with your team. We can test in a sandbox first, though we recommend some production testing since sandbox configurations often differ. We have tested live Salesforce environments for large enterprises without incident.

Can you test Salesforce Communities and Guest User configurations?

Yes, and you should prioritize it. Communities with Guest User access are among the most exploited Salesforce attack vectors, and the 2024 account-takeover disclosures targeted Guest User misconfigurations specifically. We test guest permissions, community sharing settings, unauthenticated access points, and the boundary between authenticated and unauthenticated functionality.

Do you test custom Apex code and Visualforce pages?

Yes. Custom code is where the most critical vulnerabilities often hide. We test Apex classes, triggers, controllers, and Visualforce pages for SOQL/SOSL injection, improper input validation, "with sharing" versus "without sharing" mistakes, sensitive data in debug logs, hardcoded credentials, and business logic flaws, along with custom Aura and Lightning Web Components. We do not just read the code; we exploit it to prove real-world impact.

What Salesforce compliance requirements can penetration testing help with?

Our testing supports PCI DSS (Requirement 11.4), the HIPAA Security Rule, SOC 2 Type II, GDPR, and ISO 27001. Reports map findings to specific control requirements to make audits straightforward. For PCI DSS, if you store, process, or transmit cardholder data in Salesforce, annual penetration testing is mandatory and must cover your application, custom code, integrations, and external-facing components.

How do you test Salesforce AppExchange apps and third-party integrations?

We assess both the AppExchange apps installed in your org and the integrations connecting Salesforce to external systems. For apps, we review requested permissions, test for data leakage, and analyze their API calls. For integrations, we test authentication (OAuth, API keys, JWT), data transmission, endpoint security, webhook validation, and whether a third-party system can be leveraged to compromise Salesforce. A vulnerable integration can become a backdoor into your data.

Can you find issues introduced by recent Salesforce updates or configuration changes?

Yes, which is why periodic testing matters. Salesforce ships three releases a year, and each can change defaults or expose new vectors, while your team makes ongoing configuration and code changes. We test your current state for issues from recent updates, permission drift from accumulated changes, and misconfigurations that were not present at your last assessment.

What happens if you find critical vulnerabilities during testing?

We notify your team immediately rather than waiting for the report. For high-severity issues like exposed customer data, authentication bypass, or privilege escalation, we provide verbal notification with emergency mitigation guidance. After testing, you receive a detailed report with proof-of-concept exploits, remediation steps, and prioritized actions, plus a complimentary retest once you have implemented fixes.

Who performs the testing?

Senior US-based Raxis engineers holding certifications such as OSCP and OSCE, with hands-on Salesforce platform experience. No outsourcing, and no junior testers learning on your org.

How much does Salesforce penetration testing cost and how long does it take?

It depends on the complexity of your org: custom objects and fields, lines of Apex, number of integrations and APIs, whether you run Communities or Experience Cloud, the number of profiles and permission sets, and your compliance requirements. A focused assessment typically starts around $15,000 to $35,000 and takes one to four weeks. Comprehensive testing of a complex enterprise org with extensive customization runs $35,000 to $75,000 or more and takes four weeks or longer. The free AutoRABIT Guard scan is a good way to gauge your posture first. Contact us for a quote sized to your implementation.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.