Fixed price. Priced by your app.
No enterprise quote, no six-week wait. Pick by the shape of your app — every tier is human-verified, includes a retest and an attestation letter you can share. Behind each one, a multi-model harness covers the breadth at machine speed and a person reproduces and verifies every finding by hand — so it stays affordable without going shallow. We test websites, web apps and APIs. Prices are one-off and exclude VAT.
Security Snapshot
£149For side projects and first launches on a tight budget: a quick, human-checked look at your app before real users find the gaps.
- Automated outside-in checks: headers, exposed files and secrets, keys in your front-end code
- Hand-checked test: can one user reach another user’s data?
- Only verified findings, each with a prompt-ready fix
- Full £149 credited if you upgrade to Launch or Standard within 30 days
Not an assessment: no business-logic or payment testing, no retest, no attestation letter.
$ Start a SnapshotA small site or app — a login or two, no payments or multiple tenants yet.
- OWASP Top 10 + access control, incl. CSRF
- Every finding verified by hand
- Prompt-ready fixes for your AI coding tools
- Clear report + attestation letter
- One retest within 30 days
A typical SaaS — accounts, several roles, a payment or subscription flow, an API.
- Broad OWASP WSTG coverage, incl. CSRF
- Business logic + multi-tenant isolation
- Payment / subscription bypass checks
- API security (OWASP API Top 10)
- AI feature testing (OWASP LLM Top 10)
- Optional read-only code access
- Prompt-ready fixes + attestation letter
- Three retests within 60 days
Multi-tenant, admin panels, complex logic, OAuth/SSO, several integrations.
- Everything in Standard — run deeper and longer
- Cross-component exploit chains
- Cloud, infrastructure and supply-chain review
- Threat-model and insecure-design review
- In-depth code-assisted review
- Priority scheduling
- Prompt-ready fixes + attestation letter
- Ten retests within 90 days
Multiple apps, a larger website, a mobile app, or an unusual setup.
- Fixed quote from a short scoping form
- No obligation, no sales call required
- Same human-verified standard
Not sure which fits? Start the scoping form — we confirm the right tier (or a fixed quote) before you pay anything.
Free External Exposure Check.
- Outside-in only, no login required
- You submit your own URL and confirm you own it
- An honest report with real findings, nothing paywalled to scare you
What's in each.
| Feature | Launch | Standard | Advanced |
|---|---|---|---|
| Access level | Black-box | Grey-box | Grey-box + code (opt.) |
| Turnaround | ~3–5 days | ~5–7 days | ~7–10 days |
| OWASP Top 10 + access control (incl. CSRF) | ✓ | ✓ | ✓ |
| API security (OWASP API Top 10) | – | ✓ | ✓ |
| Business logic | – | ✓ | ✓ |
| Multi-tenant isolation | – | ✓ | ✓ |
| Payment / subscription checks | – | ✓ | ✓ |
| AI feature testing (LLM Top 10) | – | ✓ | ✓ |
| Cross-component exploit chains | – | – | ✓ |
| Code-assisted review | – | Optional | In depth |
| Infra, supply-chain and design review | – | – | ✓ |
| Prompt-ready fixes | ✓ | ✓ | ✓ |
| Attestation letter | ✓ | ✓ | ✓ |
| Retests | 1 (30 days) | 3 (60 days) | 10 (90 days) |
A clean result is a good result.
You're paying for the assessment, not per bug — so a clean result is a good result, and it costs the same. You still get the full report: what was tested, the vulnerability classes covered, the areas that held up, and hardening recommendations. A clean, recent report is exactly what unblocks a procurement or diligence conversation. (No "cheaper if we find nothing" — that would just reward us for finding bugs.)
A report you can act on.
Every finding is human-verified and delivered prompt-ready — a plain-English summary for you, and a precise technical entry your developer (or your AI coding tool) can fix straight away. A taste:
Broken access control — any user can read another tenant's invoices
A logged-in customer could read any other customer's invoices by changing the numeric id in the URL. Fix: enforce ownership on the server, scoped to the authenticated tenant.
Password-reset token does not expire and can be replayed
Reset links stayed valid indefinitely and worked more than once. Fix: short TTL, single-use, and invalidate sessions on reset.
Elitor is an independent security practice — not a CREST/CHECK-accredited penetration-testing firm. Our assessments help you find and fix real issues affordably; they aren't a substitute for an accredited pentest where one is required for regulatory, insurance or procurement compliance. If that's what you need, we'll tell you. Prices exclude VAT.
Confirm your tier in a few minutes.
The scoping form takes a few minutes, and we confirm the right tier (or a fixed quote) before anything is charged.
Elitor is an independent security practice — not a CREST/CHECK-accredited penetration-testing firm. Our assessments help you find and fix real issues affordably; they are not a substitute for an accredited pentest where one is required for regulatory, insurance or procurement compliance. If that is what you need, we will tell you.