Skip to content
Halberd Security
Authorised testing only. We test only with the owner's written authorisation, so scope is agreed before testing begins. Unauthorised testing is also illegal under the Computer Fraud and Abuse Act.

Service

Firebase penetration testing for apps that trust the client

Firebase penetration testing checks whether your security rules really protect data. So it focuses on what a user with the app's public configuration can read or change.

  • Named tester before day one
  • One retest within 30 days
  • OWASP WSTG and NIST SP 800-115
Firebase penetration testing: review the rules, test as each user and report and retest

Why Firebase penetration testing matters

Firebase apps talk to the database directly from the client. Therefore security rules are the main defence, not a server in between.

The app's configuration is public by design. As a result, weak rules can expose data to anyone who reads it.

What Firebase penetration testing examines

The test treats each rule as a promise to check. For example, whether one user can read another user's records.

  • Database and storage security rules
  • Authentication settings and providers
  • Cloud Functions and their triggers
  • App Check and abuse controls
  • Exposed keys and service accounts

Firebase penetration testing readiness check

Tick what you can provide.

Your result appears here as you tick, so you can see what is still open.

Scoping Firebase penetration testing

Rules complexity drives effort. However, functions and integrations add to it.

QuestionEffect on scope
How many collections or paths?More rules to verify
How many user roles?Each role needs checks
Cloud Functions in use?Server code is reviewed
Mobile, web or both?Each client adds checks

Authorisation and safety

Testing runs only under your written authorisation, and a test project is preferred. Also, Google's cloud testing guidance applies. So testing targets your project, not the platform.

Findings come with evidence and a fix. The Firebase Security Rules documentation explain the rule model.

Fees and timing

Firebase work is priced after scoping, often with mobile app testing. Most companies land between $10,000 and $30,000, and the exact figure follows scope. One retest within 30 days is included, and a named tester is confirmed before day one.

Also test rules continuously. Because the Firebase emulator can run rule tests in your pipeline, regressions are caught before release. So the penetration test becomes a check on a living process, not a one-off event. In addition, review rules whenever a new collection appears, because new data often ships with temporary open rules.

Firebase penetration testing questions

Is Firebase penetration testing needed if Google secures the platform?

Yes. Google secures the platform, while your rules and code protect your data.

What does Firebase penetration testing focus on?

Security rules, authentication and functions, tested as real users.

Can Firebase penetration testing run on production?

It can, but a test project is safer.

Is a retest included?

Yes. One retest within 30 days is included.

Related guides

Scope your Firebase penetration testing

Tell us about your rules, roles and functions. We reply with a written estimate, usually within four working hours.

Get my estimate