Configuration & Access Review
We audit profiles, permission sets, sharing rules, and Object/Field/Record-Level Security to find where data is reachable by users, or the API, that should never see it.
Your Salesforce org holds your customers, pipeline, and revenue. Most breaches start with a misconfiguration, not a zero-day. IntegSec's offensive team pressure-tests your org, Apex, and Experience Cloud to find the exploitable flaws before attackers do.
Led by an offensive-security team whose founder holds CISSP, OSCP, and OSCE, with two decades breaking into enterprise systems at IBM X-Force Red, Trustwave SpiderLabs, and IntegSec.
Not a scanner reselling a dashboard. Experienced operators manually chain misconfigurations into proven attack paths a tool will never produce.
We know the Salesforce sharing model, Apex sharing semantics, and Experience Cloud pitfalls, not just a generic web-app checklist.
Salesforce secures its platform, but everything you build and configure on top of it is your responsibility. Under the shared responsibility model, the highest-impact risks come from configuration and custom code, not the infrastructure.
Sensitive custom objects and fields hidden from the UI but still reachable through the API, over-permissioned profiles, and permissive sharing rules routinely expose data no one intended to share.
Public Experience Cloud sites and guest user access are a leading source of real-world Salesforce data leaks when object and sharing settings aren't locked down.
Custom Apex that skips CRUD/FLS enforcement or concatenates user input into SOQL queries opens the door to injection and unauthorized data access, classic app-layer flaws on a SaaS platform.
Over-scoped connected apps, third-party integrations, and unmanaged OAuth tokens expand your attack surface and create paths for data exfiltration well beyond the login page.
Effective Salesforce testing spans both the configuration (SaaS) layer and the custom-development (PaaS) layer. We assess your org the way an external attacker, a malicious insider, and an over-permissioned integration each would.
Salesforce Security Assessment Policy
OLS, FLS, and record-level sharing
Experience Cloud, guest users, public pages
Apex, Visualforce, LWC, SOQL injection
Connected apps, OAuth, APIs, tokens
SSO, MFA, session and login policies
We audit profiles, permission sets, sharing rules, and Object/Field/Record-Level Security to find where data is reachable by users, or the API, that should never see it.
Starting from a standard low-privilege user, we chain misconfigurations and code flaws to demonstrate privilege escalation and unauthorized access to sensitive records.
We review custom Apex, Visualforce, and Lightning components for SOQL injection, missing CRUD/FLS checks, insecure sharing keywords, and unsafe API exposure.
We probe Experience Cloud sites and guest access the way an unauthenticated outsider would, surfacing exposed objects and data before they end up in a breach headline.
Short answer: no. Since January 31, 2023, Salesforce no longer requires customers to request prior approval, or even give advance notice, before performing a penetration test or security assessment of their own org. This changed the old process many teams still remember, where you had to submit a request and wait for authorization before any testing could begin.
Testing is now governed by Salesforce's Security Assessment Agreement, which sets the rules of engagement: production data handling, prohibited techniques like denial-of-service, and how to report confirmed findings. IntegSec tests fully within those terms, so there's no authorization queue between you and a real assessment. We handle the agreement details and can scope and begin quickly.
Ask us about testing your orgOffensive expertise applied to the platform that runs your customer relationships. We don't just run the Health Check, we demonstrate what a real attacker can reach and how to shut it down.
Expert-led, manual penetration testing that simulates external attackers, malicious insiders, and abused integrations against your Salesforce org.
What You Get: Documented attack chains with proof-of-exploit, business-impact risk ratings, and prioritized, admin- and developer-ready remediation guidance.
A deep configuration and posture review of your org against Salesforce and industry best practices, ideal ahead of an audit, a new rollout, or a security review.
Audit & Compliance Support: Evidence and reporting that support SOC 2, ISO 27001, and internal audit, and satisfy customer and vendor security requirements.
Our testers understand the Salesforce security model end to end: the sharing architecture, Apex sharing semantics, and Experience Cloud pitfalls that generic web pentesters miss.
Automated scanners and the built-in Health Check list settings. They do not chain them into a breach. We do, proving by hand exactly which records a guest user, insider, or over-scoped integration can reach.
No Salesforce approval queue, no operational disruption. We scope tightly, coordinate with your team, and test within Salesforce's assessment terms.
Clear technical detail for your team plus an executive summary and evidence your auditors, customers, and leadership can act on immediately.
Common questions from security, Basis, and audit teams evaluating an SAP penetration test.
Offensive testing of your org and custom development, targeting risks unique to the platform: misconfigured Object-, Field-, and Record-Level Security, over-permissioned profiles, exposed guest and Experience Cloud users, vulnerable Apex and Visualforce, SOQL injection, and insecure connected apps and OAuth integrations.
Offensive testing of your org and custom development, targeting risks unique to the platform: misconfigured Object-, Field-, and Record-Level Security, over-permissioned profiles, exposed guest and Experience Cloud users, vulnerable Apex and Visualforce, SOQL injection, and insecure connected apps and OAuth integrations.
Offensive testing of your org and custom development, targeting risks unique to the platform: misconfigured Object-, Field-, and Record-Level Security, over-permissioned profiles, exposed guest and Experience Cloud users, vulnerable Apex and Visualforce, SOQL injection, and insecure connected apps and OAuth integrations.
Offensive testing of your org and custom development, targeting risks unique to the platform: misconfigured Object-, Field-, and Record-Level Security, over-permissioned profiles, exposed guest and Experience Cloud users, vulnerable Apex and Visualforce, SOQL injection, and insecure connected apps and OAuth integrations.
Offensive testing of your org and custom development, targeting risks unique to the platform: misconfigured Object-, Field-, and Record-Level Security, over-permissioned profiles, exposed guest and Experience Cloud users, vulnerable Apex and Visualforce, SOQL injection, and insecure connected apps and OAuth integrations.
IntegSec provides specialized offensive security testing across the platforms and industries that run your business.
Penetration testing for S/4HANA, NetWeaver, RFC, Fiori, and HANA environments.
Penetration testing for E-Business Suite, PeopleSoft, JD Edwards, and Fusion Cloud ERP.
Testing for D365 Finance & Operations, Business Central, legacy AX/NAV/GP, and Power Platform.
SOC 2-ready vulnerability assessments and penetration testing for software companies.
Find the exploitable gaps in your Salesforce configuration and custom code before an attacker does. No Salesforce approval queue: we can scope this week and start in days. Book a 30-minute call with IntegSec's Salesforce security experts.