Skip to main content

Flag of CanadaCanadian-owned and operated

(289) 800‑1722
EluxAI

Agents that run and protect

AI penetration testing that confirms findings and hands you the fix

Our AI penetration testing starts with your written authorization and never tries to break anything. Agents map what you expose online, confirm each weakness is real, and write a fix you can deploy. Then they keep checking every day. It is an innovative approach for Canadian businesses that cannot justify a full-time security team.

Canadian-owned. Runs on NVIDIA GPUs.

Engagement: portal.northshorecu.caAuthorized scope
  • HighAdmin login accepts unlimited password attemptsConfirmed
  • MediumOutdated plugin with a published vulnerabilityConfirmed
  • MediumStrict transport security header missingFix ready
  • LowSession cookie missing SameSite attributeFix ready

0

Destructive tests

4

Confirmed findings

2

Fixes ready
Illustration of an AI penetration testing report. Target is fictional.
Scope
Only systems you own and authorize in writing, with exclusions listed
Method
Non-destructive testing, with no attempt to take services down
Deliverables
Confirmed findings, fixes ready to deploy and an executive summary
Between tests
Daily self-test, and every patch watched for three days
On this page

What is AI penetration testing?

AI penetration testing has two meanings. One is using AI to test your own websites, servers and apps for weaknesses. The other is testing AI systems, such as chatbots, for ways to trick them. EluxAI delivers the first: AI-assisted testing of your systems, done without damage and only with your written authorization. Every finding is confirmed before you see it.

To be clear, we do not sell testing of AI chatbots. This service protects the websites, servers and apps you run, and nothing is tested until you sign a written authorization.

Most vulnerability scanning stops at a list of things that might be wrong. A human-led penetration test goes much deeper, usually once a year. Our agents sit between the two and add something neither one offers.

What is revolutionary is what happens after the scan. Each finding is confirmed, a fix is written for you, and the fix is watched until it proves safe. It is one of eleven agent services in our AI for business lineup, and it is built for owners who want answers, not a spreadsheet of maybes.

Vulnerability scanning attack surface map showing a company's public web addresses, subdomains and exposed services

Why does every engagement start with written authorization?

Because testing a computer system without permission is a crime in Canada. The Criminal Code makes unauthorized use of a computer, done fraudulently and without colour of right, an indictable offence with up to 10 years in prison. The owner's signed authorization is what makes a test lawful, so we never test a single system without one.

You can read section 342.1 of the Criminal Code on the federal justice laws website. Our scope letter turns that legal line into a practical checklist:

  • Every web address and system in scope, and everything excluded
  • The testing window, and who to call if something looks wrong
  • Confirmation that the signer owns or controls each system
  • Hosted platforms and software services you do not control stay out of scope

Agencies, take note. You cannot authorize testing of a client's website on the client's behalf, so each client signs for their own systems and each client's results stay in a private workspace.

What does our website security scan look for?

Our agents look at your business the way an outsider would. They find every public web address, subdomain and open door connected to you, check whether a firewall protects your site, and compare your website software and add-ons against published vulnerabilities. They also look for files left public and weak security settings, all without damaging data or disrupting service.

Everything you expose

  • Forgotten subdomains, old test sites and addresses nobody remembers launching
  • Open doors on your servers that should be closed
  • Whether a firewall sits in front of your website

Your website and apps

  • Outdated software and add-ons with published vulnerabilities
  • Ways an outsider could discover user account names
  • Files, settings and data that should never be public

Settings that protect visitors and your brand

  • Encryption, browser security settings and cookies
  • Email settings that stop someone sending fake email from your domain

Nothing on this list involves taking a service down, guessing passwords at scale or changing your data. Those limits are written into every engagement.

How does the red-to-purple loop confirm findings and fix them?

In security, red means attack and purple means attackers and defenders working together. Our red side confirms each weakness is real, which removes false positives. Our purple side then writes a fix you can deploy, such as a security setting change or a software update. You get an executive summary for leadership and technical detail for whoever maintains your systems.

We call the full cycle the Authorized Red-to-Purple Loop:

  1. Scope. Signed written authorization naming every system, the window and the exclusions. No scope, no testing.
  2. Map. Find everything you expose online, including forgotten subdomains and open doors.
  3. Probe. Check software, add-ons, public files and security settings, non-destructively.
  4. Prove. Confirm each finding is real; unconfirmed items are dropped or clearly labelled.
  5. Patch. Deliver a fix you can deploy, with an executive summary and technical notes.
  6. Watch. Monitor every patch for three days and roll it back if errors return.
AI penetration testing findings report listing confirmed high, medium and low severity issues with fixes ready to deploy

What happens between assessments?

Security does not stop on report day. After an engagement, our agents run a daily security self-test and open a ticket for each new finding. Every patch is watched for three days and rolled back if errors return. Suspicious files your team receives can be checked safely without anyone opening them, which keeps a fake invoice from becoming an incident.

A yearly report tells you where you stood last spring. Daily self-tests with automatic patch rollback are a revolutionary change for a small business that cannot afford a security team.

This approach lines up with the Canadian Centre for Cyber Security's baseline controls for small and medium organizations, which include automatically patching software and securing websites. Findings flow into the same ticket desk our AI agents use, so every issue has an owner.

Vulnerability scanning vs AI assessment vs a human-led penetration test

A vulnerability scan matches software versions to known issues and produces a long list with many false alarms. A human-led penetration test proves the worst case, usually once a year. Our AI-driven assessment sits between them: it confirms what is real, hands you fixes and keeps checking daily. Audits that require a human-led test still need one.

Three ways to run a cybersecurity audit
QuestionAutomated vulnerability scanEluxAI AI-driven assessmentHuman-led penetration test
What it doesMatches versions to known issuesMaps what you expose, tests safely, confirms findingsExperts chain attacks and test business logic
Destructive techniquesNoNoSometimes, by agreement
False positivesCommonReduced by the confirmation stepLow
FixesGeneric adviceFixes ready to deploy, plus executive summaryWritten recommendations
FrequencyContinuous or weeklyDaily self-test plus periodic full assessmentsUsually yearly
After a patchNothingWatched for three days, rolled back if neededNothing until the next test
Evidence for compliance auditsNoSupporting evidence onlyYes

Verdict: scans tell you what might be wrong, a human pen test proves the worst case once a year, and our agents confirm what is wrong, help fix it and keep checking.

Why do Canadian businesses need continuous security testing?

Because attackers scan continuously and the cost of a breach keeps climbing. Statistics Canada found about 1 in 6 Canadian businesses were impacted by cyber security incidents in 2023. IBM's 2026 report puts the average Canadian data breach at a record CA$7.11 million, and 48,185 new software vulnerabilities were published in 2025 alone.

The Canadian Centre for Cyber Security's National Cyber Threat Assessment warns that threat actors are constantly scanning for publicly known vulnerabilities and exploiting unpatched systems. It also says AI is lowering the barrier to entry for attackers.

Recovery spending by Canadian businesses doubled from about $600 million in 2021 to $1.2 billion in 2023, according to Statistics Canada. Organizations that used security AI extensively paid CA$5.5 million per breach on average, versus CA$8.91 million without it, in IBM's Canadian results.

What do PIPEDA and Quebec Law 25 mean if testing uncovers a problem?

A vulnerability on its own is not a breach. If testing shows personal information was actually accessed without authorization, PIPEDA requires a report to the Privacy Commissioner when there is a real risk of significant harm, and breach records must be kept for two years. Quebec's Law 25 adds its own reporting duties and much larger penalties.

Knowingly breaking PIPEDA's breach rules can bring fines of up to $100,000, as the Privacy Commissioner's guidance and the Act explain. Under Law 25, penal fines can reach $25 million or 4% of worldwide turnover, whichever is greater.

If our agents see signs of past unauthorized access, we flag it to you immediately. Your privacy lead or lawyer decides whether it must be reported.

How much does penetration testing cost in Canada?

Typical Canadian market ranges put most penetration tests between about $5,000 and $30,000, with mid-market engagements mostly between $8,000 and $20,000. Automated vulnerability scanning for a small business costs roughly $2,000 to $8,000 a year. These are market ranges, not our prices. EluxAI quotes after a free scoping assessment of your systems.

Typical market ranges for penetration testing in Canada (CAD), not EluxAI prices
EngagementTypical market rangeSource
Most Canadian penetration tests$5,000 to $30,000Canadian cost guide, July 2026
External network test$5,000 to $12,000Same guide
Web application test, standard scope$12,000 to $25,000Canadian cost guide, June 2026
Cloud environment test, standard scope$25,000 to $40,000Same guide
Small business network test$8,000 to $25,000Canadian SMB guide, 2026
Vulnerability scanning, small business$2,000 to $8,000 per yearSame guide

What moves a quote: the number of web addresses and applications, whether logged-in areas are tested, how many environments you run, retesting and reporting depth. Be careful with very cheap offers, since quotes under $5,000 are usually automated scans sold as penetration tests. EluxAI quotes after a free assessment, and you can book a scoping call without sharing any access.

Who needs AI penetration testing?

Businesses that hold customer data but have no security team, and the agencies and developers who build for them. SEO and web agencies add security to maintenance retainers. App studios test before launch. Clinics, property managers, online stores and franchises use daily checks to keep booking pages, tenant portals and checkouts from becoming the weak link.

  • SEO and web agencies. Outdated add-ons and public files often surface in technical audits too. Each client signs a scope, and daily self-test tickets land in that client's private workspace.
  • App developers and software studios. Pre-launch assessments of live and test environments, with an executive summary for investors or enterprise buyers.
  • Clinics and professional practices. Booking pages and patient data, tested in clearly scoped, quiet windows.
  • Property management and e-commerce. Tenant portals, payment pages and store domains, plus safe checks on suspicious invoice attachments.
  • Franchises. One scope template across locations, with head office reading every executive summary.

Example scenario, illustrative only: two weeks before launch, an app studio in Montreal orders an assessment. The agents discover a forgotten test address, still online, serving a settings file that should never be public. The studio takes it down before launch, then asks our web app development agents to add the check to every release.

Planning a new site? Security reviews can be built into a website redesign from the first day.

Cybersecurity audit executive summary page with risk rating, confirmed findings and plain-language next steps for leadership
Runs on NVIDIA GPUs

Built on NVIDIA: faster analysis, private by design

We chose NVIDIA accelerated computing as the innovative foundation for our agentic platform, and security analysis shows why. Confirming a finding means reasoning over many published vulnerabilities and test results at once, which is exactly the parallel work GPUs excel at.

NVIDIA's own research makes the point. Its vulnerability analysis agent checked a software package with 20 published vulnerabilities 9.3 times faster in parallel than one at a time, then handed the results to a human analyst to decide. We follow the same principle.

Running on NVIDIA GPUs also means details about your weak points stay on our own NVIDIA-powered hardware, not on a public AI service.

EluxAI Labs, research and development in Ontario, Canada

How does EluxAI Labs keep AI security findings free of false alarms?

Language models are good at suggesting weaknesses and poor at proving them. The EluxAI Labs team in Ontario developed a confirmation algorithm that reports a finding only after safe evidence reproduces it, and it grades confidence for everything else. You receive fewer false positives, clearer severity ratings and fixes aimed at real problems rather than guesses.

What it could look like in your industry

Clinical research
Participant portals and study data systems are tested within an authorized scope.
Banking
Customer-facing apps and third-party exposure receive evidence-backed findings.
Manufacturing
Internet-facing systems at plants and warehouses are mapped and checked.
Marketing
Agencies confirm the security of the client websites they manage.

Questions about AI penetration testing

What is AI penetration testing?

The phrase has two meanings. One is using AI agents to test your websites, servers and apps for weaknesses. The other is testing AI systems, such as chatbots, to see whether they can be tricked into leaking data. EluxAI delivers the first: AI-assisted testing of your systems, done only with your written authorization, with each finding confirmed and a fix ready to deploy.

Is penetration testing legal in Canada?

It is legal when the owner of the system authorizes it. Section 342.1 of the Criminal Code makes unauthorized use of a computer, done fraudulently and without colour of right, an indictable offence with up to 10 years in prison. Written authorization is what gives a tester that right. We do not test a single system without a signed scope from its owner.

How much does a penetration test cost in Canada?

Canadian market guides put most engagements between about $5,000 and $30,000 CAD. Web application tests commonly run $7,000 to $25,000, and cloud or complex network work can pass $40,000. Automated vulnerability scanning for a small business costs roughly $2,000 to $8,000 a year. These are market ranges, not our prices. We quote after a free scoping assessment.

Will AI replace penetration testers?

Not for complex work. AI agents are fast at mapping what you expose online, checking for published vulnerabilities and retesting fixes, and they can run every day. Human testers still lead on business logic flaws, chained attacks and compliance-grade engagements. Even NVIDIA's vulnerability analysis agent hands its findings to a human analyst who decides what to do. We treat AI as the always-on layer.

How often should we test our website and systems?

Continuous checks and periodic deep assessments work best together. Our agents run a daily security self-test and open a ticket for each new finding. We recommend a full assessment before a launch, after major changes such as a redesign, and at least once a year. With 48,185 new software vulnerabilities published in 2025, a yearly test alone leaves long gaps.

What does a non-destructive assessment check?

We find every public web address, subdomain and open door connected to your business, and whether a firewall protects your site. Then we check your website software and add-ons against published vulnerabilities, look for files and data that should not be public, and review encryption, browser security settings, cookies and email spoofing protection. Nothing is attacked in a way that could damage data.

What happens after you find a vulnerability?

Each finding goes through a red-to-purple loop. The red side confirms the issue is real, which removes false positives. The purple side writes a fix you can deploy, such as a security setting change or a software update. You get an executive summary for leadership and technical detail for developers. After a patch, we watch for errors for three days and roll back if needed.

Do we have to report a vulnerability you find?

A vulnerability on its own is not a breach. If testing shows personal information was actually accessed without authorization, PIPEDA requires a report to the Privacy Commissioner when there is a real risk of significant harm, and breach records must be kept for two years. Quebec's Law 25 has its own reporting duties. Your privacy lead or lawyer should make that call.

Book your free scoping call

Every day a known weakness stays open is a day someone else can find it first. Tell us what you run, and we will confirm the scope, the limits and exactly what you receive.

  • A person on our team reviews every AI Penetration Testing request and replies within one business day.
  • Your AI Penetration Testing plan spells out the agent's tools, what it handles alone and what waits for approval.
  • The AI Penetration Testing assessment is free, with no obligation. Prefer to discuss it by phone? Call (289) 800‑1722.

Canadian team in Markham, Ontario