Skip to content
How it works

From scoping to a fixed, verified report.

No sales call. A short form, a clear authorisation, and honest status updates — then a human-verified report with the fixes. Here’s the whole thing: the process, what we test, how much access you give us, our methodology, the standards we align to, and how your data is handled.

The process

Six clear steps.

Mostly asynchronous, and you always know where you are. A call is available whenever you want one — it’s just never required.

  1. 01

    Tell us about your app

    Pick an assessment and fill out a short, plain-English scoping form — your URL, the roles, what it handles. No jargon, no call required.

  2. 02

    Confirm & authorise

    We verify you control the target (a quick DNS or file check) and you sign a clear authorisation. We review and approve every request — no self-serve “pay and we start”.

  3. 03

    Pay

    Once approved, you pay a fixed price for the confirmed tier. No hourly surprises; anything new is agreed in writing first.

  4. 04

    We test — and verify

    Your app goes through our multi-model, multi-agent workflow. A person reproduces and prioritises every finding before it reaches you.

  5. 05

    You get the report

    A plain-English summary for you and a precise technical section for whoever fixes it — evidence, steps and fixes. Delivered securely, never as a plain email attachment.

  6. 06

    Fix, then retest

    Close the issues, request your included retest within 30 days, and we confirm they’re resolved — then issue an attestation letter you can share.

What we test

The vulnerability classes we go after.

Broken access controlIDOR / BOLAAuthentication & sessionsPrivilege escalationMulti-tenant isolationBusiness-logic flawsPayment & subscription bypassAccount recovery & password resetAPI security (OWASP API Top 10)Exposed secrets & endpointsInjection · XSS · SQLiSSRF & unsafe requestsUnsafe file upload / handlingInput handling & validationSecurity headers & misconfigurationClient-vs-server trust mistakes

Attackers now point uncensored, jailbroken AI models at apps to find the easy, common holes fast and cheap — so we go after those first. Scanners catch known patterns; the issues that really hurt AI-built apps — broken access control, logic flaws, tenant leaks — take a human thinking like an attacker. We cover both.

How much access you give us

More access, more found per pound.

Source code is not required. You should never feel you have to hand over your whole codebase to get help.

Black-box

Outside only

A URL and a test login. We work like an external attacker with no inside knowledge — simplest to set up.

Grey-box · recommended

Inside as a user

Logins for each role, your API docs and a short architecture note. Where most real issues live — far more found per pound.

Code-assisted · optional

With the code

Read-only, time-limited repo access. Deepest coverage, never required, revocable the moment we’re done.

Our methodology

A workflow, not a chatbot with a security prompt.

You already have AI. The difference is the process around it: many models and agents in parallel, independently cross-checking, with a human reproducing and standing behind every finding. We keep the specifics of our prompts and orchestration private — but the shape is exactly this.

The pipeline
  1. 01

    Map the attack surface

    We enumerate what your app exposes — routes, roles, APIs, auth flows, data — so testing is grounded in how your app actually works.

  2. 02

    Test from many angles at once

    Multiple AI models and agents probe the surface in parallel, each focused on a different class of weakness. Breadth first, then depth on the promising leads.

  3. 03

    Cross-check independently

    Findings are challenged by a separate pass whose job is to disprove them. Anything a model is merely “confident” about, but can’t demonstrate, is thrown out.

  4. 04

    Reproduce by hand

    A person reproduces every surviving candidate against your running app, with a control case. If it doesn’t reproduce, it doesn’t exist — and it doesn’t go in your report.

  5. 05

    Prioritise & write it up

    Confirmed issues are scored, ranked by real business impact, and written with evidence, reproduction steps and a concrete fix.

Standards we align to

Alignment isn’t certification — we don’t claim to be accredited against these, we use them to be thorough and to speak your developer’s language.

  • OWASP WSTG

    The Web Security Testing Guide is our methodology backbone — we cite the test areas we covered.

  • OWASP Top 10 (2021)

    Findings are classified against the ten most critical web-app risk categories, starting with Broken Access Control.

  • OWASP API Security Top 10 (2023)

    Because most modern apps are API-driven — BOLA, broken function-level auth, and the rest.

  • CWE

    Every finding is tagged with a Common Weakness Enumeration id, mapping to a stable, recognised taxonomy.

  • CVSS v3.1

    Severity is scored with CVSS (vector strings included), then ordered by real-world exposure — not just the base number.

Your data & your app

Handled the way a security company should.

Your report never sits on our platform

Delivered via an expiring, encrypted link; we delete our copy after the engagement.

Temporary, revocable access

Test accounts you switch off the moment we’re done — we ask you to rotate anything you shared.

Secrets never go in a form or chat

Anything sensitive comes through a secure, one-time channel — never plaintext email or a message thread.

Non-destructive by default

No DoS, load or destructive testing unless you ask in writing. On production we tag test data and stop the moment anything looks unstable.

What we don’t do (unless you ask, in writing)
—

Denial-of-service, load or stress testing

—

Destructive or irreversible actions

—

Social engineering / phishing of your staff

—

Physical security

—

Third-party services you don’t control (Stripe, Auth0, your host)

And everything runs on your written authorisation — the exact URLs, APIs and accounts in scope, the allowed test types, the window, and a stop-testing contact. It protects you and us, and it’s what makes the testing lawful.

Ready to see what you missed?

Elitor is an independent security practice — not a CREST/CHECK-accredited firm. Our assessments find and fix real issues affordably; if you need an accredited pentest for compliance, we’ll tell you.

Elitor is an independent security practice — not a CREST/CHECK-accredited penetration-testing firm. Our assessments help you find and fix real issues affordably; they are not a substitute for an accredited pentest where one is required for regulatory, insurance or procurement compliance. If that is what you need, we will tell you.

ElitorSecurity testing for software built at AI speed.