Skip to content
Pricing

Fixed price. Priced by your app.

No enterprise quote, no six-week wait. Pick by the shape of your app — every tier is human-verified, includes a retest and an attestation letter you can share. Behind each one, a multi-model harness covers the breadth at machine speed and a person reproduces and verifies every finding by hand — so it stays affordable without going shallow. We test websites, web apps and APIs. Prices are one-off and exclude VAT.

Entry check · not an assessment

Security Snapshot

£149

For side projects and first launches on a tight budget: a quick, human-checked look at your app before real users find the gaps.

Outside-in + two test loginsReport in ~2–3 business days
  • Automated outside-in checks: headers, exposed files and secrets, keys in your front-end code
  • Hand-checked test: can one user reach another user’s data?
  • Only verified findings, each with a prompt-ready fix
  • Full £149 credited if you upgrade to Launch or Standard within 30 days

Not an assessment: no business-logic or payment testing, no retest, no attestation letter.

$ Start a Snapshot
Launch
£500

A small site or app — a login or two, no payments or multiple tenants yet.

Outside-in (black-box) + a test loginReport in ~3–5 business days
  • OWASP Top 10 + access control, incl. CSRF
  • Every finding verified by hand
  • Prompt-ready fixes for your AI coding tools
  • Clear report + attestation letter
  • One retest within 30 days
Start a Launch assessment
StandardPopular
£1,200

A typical SaaS — accounts, several roles, a payment or subscription flow, an API.

Inside-as-a-user (grey-box): logins per role + API docsReport in ~5–7 business days
  • Broad OWASP WSTG coverage, incl. CSRF
  • Business logic + multi-tenant isolation
  • Payment / subscription bypass checks
  • API security (OWASP API Top 10)
  • AI feature testing (OWASP LLM Top 10)
  • Optional read-only code access
  • Prompt-ready fixes + attestation letter
  • Three retests within 60 days
Start a Standard assessment
Advanced
from£2,500

Multi-tenant, admin panels, complex logic, OAuth/SSO, several integrations.

Grey-box + optional read-only code accessReport in ~7–10 business days
  • Everything in Standard — run deeper and longer
  • Cross-component exploit chains
  • Cloud, infrastructure and supply-chain review
  • Threat-model and insecure-design review
  • In-depth code-assisted review
  • Priority scheduling
  • Prompt-ready fixes + attestation letter
  • Ten retests within 90 days
Start an Advanced assessment
Custom
Quote

Multiple apps, a larger website, a mobile app, or an unusual setup.

Whatever fits — scoped with youQuoted after scoping
  • Fixed quote from a short scoping form
  • No obligation, no sales call required
  • Same human-verified standard
Request a quote

Not sure which fits? Start the scoping form — we confirm the right tier (or a fixed quote) before you pay anything.

Free

Free External Exposure Check.

outside-in scan£0
Not ready for a full assessment? Submit your own site and we run a quick outside-in scan: security headers, exposed files and secrets, and obvious misconfiguration. You get an honest report of what we found. If it is clean, we say so, no scare tactics.
  • Outside-in only, no login required
  • You submit your own URL and confirm you own it
  • An honest report with real findings, nothing paywalled to scare you
This only covers the outside. The flaws that actually get you breached, broken access control, IDOR, business logic and payment bypass, sit behind login and need a paid assessment. Due to demand, the free check can take up to two weeks.
Compare tiers

What's in each.

FeatureLaunchStandardAdvanced
Access levelBlack-boxGrey-boxGrey-box + code (opt.)
Turnaround~3–5 days~5–7 days~7–10 days
OWASP Top 10 + access control (incl. CSRF)✓✓✓
API security (OWASP API Top 10)–✓✓
Business logic–✓✓
Multi-tenant isolation–✓✓
Payment / subscription checks–✓✓
AI feature testing (LLM Top 10)–✓✓
Cross-component exploit chains––✓
Code-assisted review–OptionalIn depth
Infra, supply-chain and design review––✓
Prompt-ready fixes✓✓✓
Attestation letter✓✓✓
Retests1 (30 days)3 (60 days)10 (90 days)
What if we find nothing?

A clean result is a good result.

You're paying for the assessment, not per bug — so a clean result is a good result, and it costs the same. You still get the full report: what was tested, the vulnerability classes covered, the areas that held up, and hardening recommendations. A clean, recent report is exactly what unblocks a procurement or diligence conversation. (No "cheaper if we find nothing" — that would just reward us for finding bugs.)

What you get

A report you can act on.

Every finding is human-verified and delivered prompt-ready — a plain-English summary for you, and a precise technical entry your developer (or your AI coding tool) can fix straight away. A taste:

EL-01HighCWE-639 · OWASP A01

Broken access control — any user can read another tenant's invoices

A logged-in customer could read any other customer's invoices by changing the numeric id in the URL. Fix: enforce ownership on the server, scoped to the authenticated tenant.

EL-02MediumCWE-640 · OWASP A07

Password-reset token does not expire and can be replayed

Reset links stayed valid indefinitely and worked more than once. Fix: short TTL, single-use, and invalidate sessions on reset.

Elitor is an independent security practice — not a CREST/CHECK-accredited penetration-testing firm. Our assessments help you find and fix real issues affordably; they aren't a substitute for an accredited pentest where one is required for regulatory, insurance or procurement compliance. If that's what you need, we'll tell you. Prices exclude VAT.

Confirm your tier in a few minutes.

The scoping form takes a few minutes, and we confirm the right tier (or a fixed quote) before anything is charged.

Start an assessment

Elitor is an independent security practice — not a CREST/CHECK-accredited penetration-testing firm. Our assessments help you find and fix real issues affordably; they are not a substitute for an accredited pentest where one is required for regulatory, insurance or procurement compliance. If that is what you need, we will tell you.

ElitorSecurity testing for software built at AI speed.