01Do I need to prove I own the app?
Yes, always. Before any testing, including a Security Snapshot, we verify you control the target with a quick DNS or file check, and you sign a clear authorisation that sets exactly what we may test. If you can’t show you control the domain or app, we don’t test it. That’s what makes the testing lawful, and it stops anyone using us to probe a site that isn’t theirs.
02What’s the Security Snapshot?
A £149 entry check for side projects and first launches. We run automated outside-in checks (security headers, exposed files and secrets, keys in your front-end code) plus a hand-checked test of whether one user can reach another user’s data, using two test logins you give us. You get only verified findings, each with a prompt-ready fix, in about 2–3 business days. It isn’t an assessment: there’s no business-logic or payment testing, no retest and no attestation letter. If you upgrade to Launch or Standard within 30 days, the full £149 counts toward it.
03Do you need my source code?
No. Most assessments are done from the outside or with test logins — source code is optional. If you want the deepest coverage you can give us read-only, time-limited repo access, but you should never feel you have to hand over your whole codebase to get help.
04Can you test production?
Usually yes, carefully. Most AI-built apps don’t have a faithful staging copy, so we test production with dedicated test accounts and non-destructive techniques, tag any test data for easy cleanup, route notifications and payments to sandbox keys where possible, and stop the moment anything looks unstable. If you have a real staging mirror, we’ll use it.
05Will you break my application?
It’s very unlikely. We don’t do denial-of-service, load or destructive testing by default, we throttle our requests, and we monitor as we go. Testing any live system carries some inherent risk, so we ask that you have current backups — but our whole approach is built to be safe on production.
06Do I need a staging environment?
No. It’s helpful if you have a faithful one, and we’ll use it for anything higher-risk, but it isn’t required — we test production safely when there’s no mirror.
07What if you find nothing?
That’s a good result, and it costs the same — you’re paying for the assessment, not per bug. You still get the full report: what was tested, the vulnerability classes we covered, the areas that held up, and hardening recommendations. A clean, recent report is exactly what unblocks a procurement or diligence conversation.
08What happens after you find vulnerabilities?
You get a clear report: a plain-English summary for you and a precise technical section for whoever does the fixing — severity, evidence, reproduction steps and a concrete fix for each issue, mapped to OWASP and CWE. You (or your developer, or your AI coding tool) apply the fixes, then we retest to confirm they’re resolved.
09Can you fix the vulnerabilities for us?
We don’t rewrite your app — our role is to find, verify, explain, recommend and retest. But we make the fixes as easy as possible: findings come “prompt-ready,” so you can hand them straight to Cursor, Claude Code or Codex, or to your developer, and act on them directly.
10How does retesting work?
One retest is included with every assessment, within 30 days. You fix the reported issues, tell us they’re ready, and we re-check those specific findings and confirm they’re closed — then issue an attestation letter. (A retest re-validates the reported issues; hunting for brand-new issues, or testing a big new feature, is a fresh assessment or a smaller “Security Checkpoint.”)
11Is this a penetration test?
It’s a security assessment that uses penetration-testing techniques — testing your app like an attacker and verifying real, exploitable issues. It is not a formally accredited (CREST/CHECK) penetration test. For most startups that’s exactly what they need; if your requirement is compliance-driven, see the next question.
12Are you CREST accredited?
No, and we won’t pretend to be. Elitor is an independent security practice. If you need a CREST/CHECK-accredited pentest — for PCI DSS validation, certain insurance or procurement requirements, or financial-services rules — our report isn’t a substitute, and we’ll tell you so and point you to accredited providers.
13How long does an assessment take?
Typically a report in about 3–5 business days for a Launch assessment, 5–7 for Standard, and 7–10 for Advanced, from the point testing starts. We’ll confirm timing when we confirm scope.
14Can I speak to somebody?
Yes, whenever you want — a call is always available. It’s just never required. The whole process is designed to run smoothly over a form, a clear authorisation and honest status updates, so you don’t have to sit on sales calls to get your app tested.
15Is my source code safe?
Yes. If you choose code-assisted testing, access is read-only and time-limited, you can revoke it the moment we’re done, and we delete our copy after the engagement. We hold as little as possible for as short as possible.
16What data do you retain?
As little as we can. Your report is delivered through a secure, expiring link and we delete our copy after the engagement; test credentials are used and then destroyed, and we ask you to rotate anything you shared. We collect the minimum evidence needed to prove a finding, store it encrypted, and never keep more than we need.
17What if I built my app with AI?
That’s exactly who this is for. Tools like Cursor, Claude, Replit, Lovable and Bolt ship features incredibly fast, and security review hasn’t kept up — broken access control, missing server-side checks and logic flaws are common. An independent assessment catches what the AI that built the app can’t check on its own.
18Can you test APIs?
Yes — APIs are often where the real issues are. We test them against the OWASP API Security Top 10 (BOLA, broken function-level authorisation, and the rest). Sharing your API docs makes this faster and more thorough.
19Can you test mobile apps?
Mobile is available as a custom-scoped engagement — tell us about it via the scoping form and we’ll quote it. Our core, fixed-price service is focused on web apps and their APIs.
20Can you test AI / LLM features?
We can look at the security around your AI features — how they’re exposed, what they can access, prompt-injection into privileged actions, and data leakage — as part of a scoped assessment. Tell us what your app’s AI can do and we’ll factor it in.
Still curious what we’d find?
Start the scoping form — no payment until scope is confirmed.
Elitor is an independent security practice — not a CREST/CHECK-accredited penetration-testing firm. Our assessments help you find and fix real issues affordably; they are not a substitute for an accredited pentest where one is required for regulatory, insurance or procurement compliance. If that is what you need, we will tell you.