Skip to content

External security assessments for AI-built apps

Fast to buildisn't the same assafe to ship.

Independent, human-verified security testing for the apps you shipped fast with AI coding tools. We find the real, exploitable issues — broken access control, authentication, business logic, exposed data — verify every one by hand, and hand you a clear report with the fixes.

Security Snapshot £149 · full assessments from £500 · report in days

Human-verified findingsFixed, transparent pricingReport in days, not weeksRetest included
The threat has changed

Attackers have AI too.

The same tools that let you ship in a weekend let someone probe your app in minutes. Uncensored, jailbroken models are already being pointed at real sites to find the easy, common holes — broken access control, exposed endpoints, injectable inputs — at machine speed and almost no cost. The barrier to finding your weak spots has collapsed.

So we run that same kind of adversarial testing at your app first. A multi-model workflow hunts the exact holes those models find, and a person reproduces and verifies every one by hand — then hands you the fix.

WE FIND THEM FIRST · NOT A FIREWALL

This isn’t a shield and it doesn’t sit in front of your app. It’s an assessment: we find what an attacker’s AI would find, so you can close it before someone malicious does.

Why this matters

You built it fast. Real users are on it now.

AI coding tools ship features in hours; security review has not kept up — and the assistant that wrote your app cannot independently check its own work. Study after study finds the same thing: a large share of AI-generated code ships with real, exploitable flaws.

AI writes fast — and leaves gaps

Roughly half of AI-generated code samples introduce a known OWASP Top 10 weakness (Veracode, 2025). The speed that ships your product ships the mistakes along with it.

Broken access control is the #1 risk

The most common flaw in AI-built apps is a polished, role-aware interface with little or no enforcement on the server. Change an ID or a request and you can often reach data or actions that are not yours.

Your AI cannot grade its own homework

Asking the same assistant that built the app whether it is secure is not an independent check. You need an outside, adversarial look — with a human standing behind every finding.

Common issue classes

What AI-built apps tend to get wrong.

Simplified examples of well-documented weakness classes. Never client code, never client findings.

01

Changing an ID shows someone else’s data

IDOR · CWE-639 · OWASP A01
02

A profile update that also accepts a role

Mass assignment · CWE-915 · OWASP API3:2023
03

Paid features unlocked by the browser

Payment bypass · CWE-807 · OWASP A04
04

An admin key shipped to every visitor

Exposed secret · CWE-200
app/api/invoices/[id]/route.tsexample

Changing an ID shows someone else’s data

The interface only shows your own records, but the server returns any record whose ID you ask for.

IDOR · CWE-639 · OWASP A01
// GET /api/invoices/:id
const invoice = await db.invoice.findFirst({
where: { id: params.id }
where: { id: params.id, orgId: session.orgId }
})
if (!invoice) return notFound()
return Response.json(invoice)
FixScope every lookup to the signed-in user’s organisation.
app/api/profile/route.tsexample

A profile update that also accepts a role

The whole request body is written to the database, so an extra field like role: "admin" goes straight through.

Mass assignment · CWE-915 · OWASP API3:2023
// PATCH /api/profile
const body = await req.json()
await db.user.update({ where: { id: me.id }, data: body })
const { name, avatarUrl } = body
await db.user.update({ where: { id: me.id }, data: { name, avatarUrl } })
return Response.json({ ok: true })
FixWrite only the fields a user is allowed to change.
app/api/upgrade/route.tsexample

Paid features unlocked by the browser

The app trusts what the client says about the plan instead of checking the payment provider on the server.

Payment bypass · CWE-807 · OWASP A04
// POST /api/upgrade
const { plan } = await req.json()
if (plan === 'pro') await grantPro(me.id)
const sub = await stripe.subscriptions.retrieve(me.stripeSubId)
if (sub.status === 'active') await grantPro(me.id)
FixDecide access from the payment provider, never from the request.
lib/supabase.tsexample

An admin key shipped to every visitor

A key that bypasses your database rules is given a public prefix, so it ends up in the JavaScript every browser downloads.

Exposed secret · CWE-200
// imported by a client component
export const supabase = createClient(
process.env.NEXT_PUBLIC_SUPABASE_URL,
process.env.NEXT_PUBLIC_SERVICE_ROLE_KEY
process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY // + row-level security
)
FixKeep privileged keys on the server and enforce row-level security.

Every finding in your report is classified the same way, against OWASP and CWE. Read the sample report

Authorised testing only

We only test what you can prove is yours.

Before any testing starts, we verify you control the target with a quick DNS or file check, and you sign a clear authorisation that sets exactly what we may test. We review and approve every request. There is no self-serve “pay and we start”.

  • Your own targets only. If you can’t show you control the domain or app, we don’t test it.
  • Non-destructive by default. No DoS, load or destructive testing unless you ask in writing.
  • Temporary, revocable access. Test accounts you switch off the moment we’re done.
  • Never in scope. Social engineering of your staff, physical security, and third-party services you don’t control.
pre-engagement checksexample request
01

Ownership verified

A DNS TXT record or a verification file on the domain you want tested

verified
02

Authorisation signed

Scope, test window and rules of engagement, signed by you

signed
03

Request approved

Reviewed and approved by Elitor before you pay

approved
Testing starts only after all three.status: cleared to test
What you get

A real assessment. Not a scanner dump.

Every engagement runs through a structured, multi-model testing workflow and is then verified by a person. You get findings you can act on — reproduced, prioritised and explained — not a wall of unconfirmed scanner noise.

verified findings3 results
[INFO]Server header discloses version: nginx
[LOW]Cookie without SameSite attribute: _ga
[INFO]Missing header: Permissions-Policy
[MED]Possible SQL injection in ?sort= (unconfirmed)
[HIGH]Cross-tenant read on /api/invoices/:id✓ reproduced by hand · control case · CWE-639
[INFO]robots.txt found
[LOW]Autocomplete enabled on password field
[INFO]Timestamp disclosure in response body
[LOW]Missing header: X-Content-Type-Options
[MED]Potential XSS in /search (reflected?)
[INFO]Directory listing check: /static/
[HIGH]Pro plan unlocked by a client flag✓ reproduced by hand · business logic · CWE-807
[LOW]TLS 1.2 CBC cipher suite detected
[INFO]Email address found in page source
[MED]Possible open redirect ?next= (heuristic)
[INFO]Generator meta tag detected
[LOW]X-Frame-Options not set
[MED]Stored XSS in comments✓ reproduced by hand · CWE-79
[INFO]Private IP disclosure (unverified)
[MED]Weak CSP: unsafe-inline
[INFO]Cacheable HTTPS response
[LOW]Session cookie lifetime over 24h
Illustrative: typical scanner output vs. what reaches a report.

Human-verified findings

Every issue is reproduced by hand against your running app, with a control case, before it reaches your report. If it does not reproduce, it does not ship — so you get real problems, not a pile of false positives.

Fixes your AI can apply

Findings come prompt-ready — exact location, impact and a concrete fix — so you can hand them straight to Cursor, Claude Code or Codex and close them fast. The speed that built the app now fixes it.

A report you can act on

A plain-English executive summary for you, and a precise technical section for whoever does the fixing — severity, evidence, reproduction steps and remediation, mapped to OWASP and CWE.

Retest included

Fix the issues and we re-check them — free, within 30 days. You leave with problems verified closed, not just listed on a page.

Proof you can share

An attestation letter you can forward to your customers, investors or SOC 2 auditors — evidence the assessment happened and the issues were fixed, without exposing the sensitive detail.

Standards-aligned and honest

Testing follows the OWASP Web Security Testing Guide and is classified against the OWASP Top 10 and API Security Top 10. We are clear about scope and limits — and never claim your app is ‘100% secure.’

Coverage

What we test.

01Broken access control
02IDOR / BOLA
03Authentication & sessions
04Privilege escalation
05Multi-tenant isolation
06Business-logic flaws
07Payment & subscription bypass
08Account recovery & password reset
09API security (OWASP API Top 10)
10Exposed secrets & endpoints
11Injection · XSS · SQLi
12SSRF & unsafe requests
13Unsafe file upload / handling
14Input handling & validation
15Security headers & misconfiguration
16Client-vs-server trust mistakes

Security headers, misconfiguration, file handling and more — scoped to your app.

How it works

From scoping to fixed, in a few clear steps.

01

Tell us about your app

Pick an assessment and fill out a short, plain-English scoping form — your URL, the user roles, what it handles. No jargon, and no call required.

scoping form · /start
02

Confirm & authorise

We verify you control the target, and you sign a clear authorisation that sets exactly what we may test. Once approved, you pay — no surprises, no scope creep.

DNS or file check · authorised
03

We test — and verify

Your app goes through our multi-model, multi-agent workflow from an attacker's point of view. A person then verifies and prioritises every finding before it reaches you.

multi-model · human-verified
04

Report, fix, retest

You get a clear report with the fixes. Close the issues, request your included retest, and we confirm they are actually resolved.

retest · included
Prompt-ready fixes

The speed that built it now fixes it.

Every finding comes with the exact location, the impact and a concrete fix, so you can hand it straight to your coding assistant and close it fast.

CursorClaude CodeCodex
EL-01.fix.mdsample report
# EL-01 · High · CWE-639 · OWASP A01 # Broken access control: any user can read another tenant’s invoices A logged-in customer could read any other customer’s invoices by changing the numeric id in the URL. Fix: enforce ownership on the server, scoped to the authenticated tenant. In app/api/invoices/[id]/route.ts, look the invoice up by { id, orgId: session.orgId } and return 404 when nothing matches.
From the public sample reportSee the full sample report →
Pricing

Fixed price. Priced by your app.

Pick by the shape of your app — every assessment is human-verified, includes a retest and an attestation letter you can share. Prices are one-off and exclude VAT.

Entry check · not an assessment

Security Snapshot

£149

For side projects and first launches on a tight budget: a quick, human-checked look at your app before real users find the gaps.

Outside-in + two test loginsReport in ~2–3 business days
  • Automated outside-in checks: headers, exposed files and secrets, keys in your front-end code
  • Hand-checked test: can one user reach another user’s data?
  • Only verified findings, each with a prompt-ready fix
  • Full £149 credited if you upgrade to Launch or Standard within 30 days

Not an assessment: no business-logic or payment testing, no retest, no attestation letter.

$ Start a Snapshot
Launch
£500

A small site or app — a login or two, no payments or multiple tenants yet.

Outside-in (black-box) + a test loginReport in ~3–5 business days
  • OWASP Top 10 + access control, incl. CSRF
  • Every finding verified by hand
  • Prompt-ready fixes for your AI coding tools
  • Clear report + attestation letter
  • One retest within 30 days
Start a Launch assessment
StandardPopular
£1,200

A typical SaaS — accounts, several roles, a payment or subscription flow, an API.

Inside-as-a-user (grey-box): logins per role + API docsReport in ~5–7 business days
  • Broad OWASP WSTG coverage, incl. CSRF
  • Business logic + multi-tenant isolation
  • Payment / subscription bypass checks
  • API security (OWASP API Top 10)
  • AI feature testing (OWASP LLM Top 10)
  • Optional read-only code access
  • Prompt-ready fixes + attestation letter
  • Three retests within 60 days
Start a Standard assessment
Advanced
from£2,500

Multi-tenant, admin panels, complex logic, OAuth/SSO, several integrations.

Grey-box + optional read-only code accessReport in ~7–10 business days
  • Everything in Standard — run deeper and longer
  • Cross-component exploit chains
  • Cloud, infrastructure and supply-chain review
  • Threat-model and insecure-design review
  • In-depth code-assisted review
  • Priority scheduling
  • Prompt-ready fixes + attestation letter
  • Ten retests within 90 days
Start an Advanced assessment
Custom
Quote

Multiple apps, a larger website, a mobile app, or an unusual setup.

Whatever fits — scoped with youQuoted after scoping
  • Fixed quote from a short scoping form
  • No obligation, no sales call required
  • Same human-verified standard
Request a quote

Not sure which fits? Start the scoping form — we confirm the right tier (or a fixed quote) before you pay anything. Compare every tier

Find out what you missed — before someone else does.

An independent, human-verified security assessment, priced for startups. You get a clear report and the fixes — usually within days, not weeks.

Elitor is an independent security practice — not a CREST/CHECK-accredited penetration-testing firm. Our assessments help you find and fix real issues affordably; they are not a substitute for an accredited pentest where one is required for regulatory, insurance or procurement compliance. If that is what you need, we will tell you.

ElitorSecurity testing for software built at AI speed.