Trust
Security & data handling
Last updated: 21 September 2026
A security assessment puts us inside your app by design — so how we handle your access, your secrets and your report matters as much as the testing itself. Here is exactly how we do it, in plain terms. These are commitments you can hold us to, not vague assurances.
Your report never sits on our platform
Your findings are the most sensitive thing we produce — a map of where your app is weak. We deliver your report through an expiring, encrypted link, with the password sent separately over a different channel, and we delete our working copy once the engagement is done. It is never posted in a dashboard or sent as a plain email attachment.
We only test what you authorise, in writing
Every engagement runs on a written authorisation: the exact URLs, APIs and accounts in scope, the test types allowed, the time window, and a stop-testing contact. We do not touch anything outside it. That authorisation protects you and us, keeps you in control, and is what makes the testing lawful.
Access is temporary and revocable
We work from test accounts and scoped credentials you can switch off the moment we are done. Source code is never required. If you choose to grant read-only repository access for deeper coverage, it is time-limited and revoked at the end of the engagement, and we ask you to rotate anything you shared with us.
Secrets never go through a form or a chat
Anything sensitive — credentials, API keys, tokens — comes through a secure, one-time channel, never plaintext email and never a message thread. We ask for the minimum we need to do the work, and no more.
Non-destructive by default
No denial-of-service, load or destructive testing unless you ask for it in writing. When we test against production we flag our test data and stop the moment anything looks unstable — the goal is to find issues, never to cause an outage.
We never use your data to train models
Your app, your data and your findings are used only to carry out the assessment you hired us for. They are not used to train, fine-tune or evaluate any model — ours or anyone else’s.
What we are — and what we aren't
Elitor is an independent security practice. We are not a CREST or CHECK-accredited firm, and we are not SOC 2 or ISO 27001 certified — we say so plainly rather than imply otherwise. If you need an accredited pentest for compliance, cyber-insurance or a procurement requirement, we will tell you honestly. What we offer is a thorough, human-verified assessment at a price a startup can actually justify.
Questions before you share anything?
If you need specifics for a security review, or a data-processing agreement (DPA) in place before an engagement, we’re happy to get into the detail. Reach us at team@elitor.ai.
