ArgosX
Independent security testing for AI-built applications · getargosx.com
Letter of attestation: independent application security test
Application: Acme CRM (app.acme-crm.example)
Prepared for: Acme Software Inc., for presentation to customer security reviewers
Test window: March 3–5, 2026 · Letter issued: March 6, 2026
What was tested
ArgosX performed an independent, dynamic security test of the live, deployed application, followed by a human tester’s verification pass. Testing covered: anonymous (unauthenticated) database and API exposure; cross-account access control, using two customer-role test accounts to attempt access to another account’s private data; authentication and session handling, including session expiry and authorization checks on privileged actions; secrets or API keys exposed to the browser; and transport security, security headers, and CORS configuration.
What was not tested
Cloud infrastructure and internal networks; private source code and dependency composition; social engineering; denial of service. This letter attests to independent testing by ArgosX and is not an accredited audit or certification.
Outcome
The initial test identified 2 findings (1 high, 1 medium). Both were remediated by the vendor and re-tested and verified as resolved on March 12, 2026. At the re-test date, no unresolved findings of any severity remained within the tested scope. Full technical detail, including evidence and reproduction steps for each finding, is held by Acme Software Inc. and available to reviewers at their discretion.
Methodology and reviewer
Testing classes are mapped to OWASP Top 10 (2021) and OWASP WSTG test IDs, and each confirmed finding is scored with a CVSS 3.1 base vector; the full mapping is published at getargosx.com/verified-test/coverage. Findings were verified by ArgosX’s lead reviewer, whose background spans financial-technology systems and cloud infrastructure engineering.
Verification
The authenticity and currency of this letter can be checked at any time at getargosx.com/attest/sample, which confirms the issue date, scope, and whether a newer test supersedes this one.
Signed,
ArgosX Security Review, Founder & Lead Reviewer
support@getargosx.com