The ArgosX assessment methodology
ArgosX is an independent, human plus AI security assessment of your running app. We test the deployed thing the way an attacker would, we confirm what we find with evidence, and we tell you honestly what was and was not covered.
What an ArgosX assessment is
Independent
We are separate from whatever built your app, so a passing report is not the vendor grading its own homework.
Against the live app
We test the running, deployed app, not a static read of your code. We sign in as the roles you give us and exercise real journeys.
AI plus human
Automated testing for breadth and repeatability, a human pass for judgment and to confirm the findings that matter.
The process
- 01
Map
We crawl the app signed out and signed in to find the pages, actions, and data endpoints that actually exist, not just the ones linked in the menu.
- 02
Test
An AI agent signs in and drives your real journeys, then goes after the failures that actually leak data: exposed databases, secrets shipped to the browser, and access that crosses from one account into another.
- 03
Confirm
When it finds an exposure, it confirms it and captures the proof: the exact request and a screenshot of the data that came back. You see what actually happened on your live app, not just a warning that something might be wrong.
- 04
Human-verify
On a human-verified assessment, a tester reviews the findings, confirms the real ones, and probes the high-value paths by hand, so the report is not a false-positive dump. This is the tier that earns the word assessment.
How we grade and evidence findings
- Severity by real impact and exploitability. Each finding is graded critical, high, medium, or low on what an attacker could actually do and how easily, the way industry standards such as OWASP and CVSS reason about risk.
- Evidence on every confirmed finding. It carries the request and a screenshot, the steps to reproduce it, and the fix, so you can verify it yourself and close it.
- Data exposure ranks highest. A confirmed anonymous or cross-account read of real data is graded above a theoretical or posture-only issue.
Coverage and limitations
The honest part, and the part most tools skip. A report is only useful if you can trust what its clean checks actually mean.
- We tell you what was tested and what was not. A clean result is scoped to what we assessed, not a blanket guarantee.
- We name any role we could not sign in as, so you can see the gap rather than mistake it for coverage.
- We test the app an attacker reaches. We do not scan your cloud infrastructure, your dependency tree, or your internal network; those are different tools for a different job.
- This is an independent security assessment, not an accredited audit or a certification. If you need a formal compliance attestation, that is a separate, accredited process.
Want the other side of this, the specific checks we run? See what we test.
Common questions
Is this a penetration test?
It is an independent, human-verified security assessment of your live app. The automated tier is dynamic testing that confirms real exposure and backs it with evidence (the request and a screenshot); the human-verified tier adds a person who reviews findings and probes by hand. It is not an accredited audit or certification.
Do you give me a compliance report?
You get a clear, evidence-backed report you can share with a customer or your team. We do not issue formal compliance certifications or accredited attestations; if a customer requires one of those, you will still need an accredited assessor.
How do you decide severity?
By what an attacker could do and how easily, aligned to how OWASP and CVSS reason about impact and exploitability. A confirmed data exposure is graded highest; a posture or best-practice gap is graded lower.
Why not just trust my platform's built-in security?
A build-time review is the platform checking its own generated code, which is static analysis at generation time. ArgosX tests the running, deployed app from the outside, and it is independent of whatever built the app, so a passing report means something.
See it on your own app, free.
A free scan runs in minutes, no signup, and shows what any visitor can already reach. Upgrade when you want us to sign in and prove what's behind your login.