From scoping to a fixed, verified report.
No sales call. A short form, a clear authorisation, and honest status updates — then a human-verified report with the fixes. Here’s the whole thing: the process, what we test, how much access you give us, our methodology, the standards we align to, and how your data is handled.
Six clear steps.
Mostly asynchronous, and you always know where you are. A call is available whenever you want one — it’s just never required.
- 01
Tell us about your app
Pick an assessment and fill out a short, plain-English scoping form — your URL, the roles, what it handles. No jargon, no call required.
- 02
Confirm & authorise
We verify you control the target (a quick DNS or file check) and you sign a clear authorisation. We review and approve every request — no self-serve “pay and we start”.
- 03
Pay
Once approved, you pay a fixed price for the confirmed tier. No hourly surprises; anything new is agreed in writing first.
- 04
We test — and verify
Your app goes through our multi-model, multi-agent workflow. A person reproduces and prioritises every finding before it reaches you.
- 05
You get the report
A plain-English summary for you and a precise technical section for whoever fixes it — evidence, steps and fixes. Delivered securely, never as a plain email attachment.
- 06
Fix, then retest
Close the issues, request your included retest within 30 days, and we confirm they’re resolved — then issue an attestation letter you can share.
The vulnerability classes we go after.
Attackers now point uncensored, jailbroken AI models at apps to find the easy, common holes fast and cheap — so we go after those first. Scanners catch known patterns; the issues that really hurt AI-built apps — broken access control, logic flaws, tenant leaks — take a human thinking like an attacker. We cover both.
More access, more found per pound.
Source code is not required. You should never feel you have to hand over your whole codebase to get help.
Outside only
A URL and a test login. We work like an external attacker with no inside knowledge — simplest to set up.
Inside as a user
Logins for each role, your API docs and a short architecture note. Where most real issues live — far more found per pound.
With the code
Read-only, time-limited repo access. Deepest coverage, never required, revocable the moment we’re done.
A workflow, not a chatbot with a security prompt.
You already have AI. The difference is the process around it: many models and agents in parallel, independently cross-checking, with a human reproducing and standing behind every finding. We keep the specifics of our prompts and orchestration private — but the shape is exactly this.
- 01
Map the attack surface
We enumerate what your app exposes — routes, roles, APIs, auth flows, data — so testing is grounded in how your app actually works.
- 02
Test from many angles at once
Multiple AI models and agents probe the surface in parallel, each focused on a different class of weakness. Breadth first, then depth on the promising leads.
- 03
Cross-check independently
Findings are challenged by a separate pass whose job is to disprove them. Anything a model is merely “confident” about, but can’t demonstrate, is thrown out.
- 04
Reproduce by hand
A person reproduces every surviving candidate against your running app, with a control case. If it doesn’t reproduce, it doesn’t exist — and it doesn’t go in your report.
- 05
Prioritise & write it up
Confirmed issues are scored, ranked by real business impact, and written with evidence, reproduction steps and a concrete fix.
Alignment isn’t certification — we don’t claim to be accredited against these, we use them to be thorough and to speak your developer’s language.
OWASP WSTG
The Web Security Testing Guide is our methodology backbone — we cite the test areas we covered.
OWASP Top 10 (2021)
Findings are classified against the ten most critical web-app risk categories, starting with Broken Access Control.
OWASP API Security Top 10 (2023)
Because most modern apps are API-driven — BOLA, broken function-level auth, and the rest.
CWE
Every finding is tagged with a Common Weakness Enumeration id, mapping to a stable, recognised taxonomy.
CVSS v3.1
Severity is scored with CVSS (vector strings included), then ordered by real-world exposure — not just the base number.
Handled the way a security company should.
Your report never sits on our platform
Delivered via an expiring, encrypted link; we delete our copy after the engagement.
Temporary, revocable access
Test accounts you switch off the moment we’re done — we ask you to rotate anything you shared.
Secrets never go in a form or chat
Anything sensitive comes through a secure, one-time channel — never plaintext email or a message thread.
Non-destructive by default
No DoS, load or destructive testing unless you ask in writing. On production we tag test data and stop the moment anything looks unstable.
Denial-of-service, load or stress testing
Destructive or irreversible actions
Social engineering / phishing of your staff
Physical security
Third-party services you don’t control (Stripe, Auth0, your host)
Ready to see what you missed?
Elitor is an independent security practice — not a CREST/CHECK-accredited firm. Our assessments find and fix real issues affordably; if you need an accredited pentest for compliance, we’ll tell you.
Elitor is an independent security practice — not a CREST/CHECK-accredited penetration-testing firm. Our assessments help you find and fix real issues affordably; they are not a substitute for an accredited pentest where one is required for regulatory, insurance or procurement compliance. If that is what you need, we will tell you.