ElCampeon Systems

In development A Claude-powered tutor for Learn Web Application Security

We build apps. We break them.

ElCampeon Systems is a two-sided studio from India. We ship free Android learning apps written with Claude Code, and we test web apps and APIs for the flaws attackers look for, with written permission, every time.

What we're doing now

  • Building Claude tutor in Learn Web Application Security In development
  • Breaking Web application and API security testing Taking enquiries
  • Learning AI and LLM application testing Coming 2027

One studio, two sides

Building makes us better breakers.

Security testers rarely ship products, and app studios rarely attack them. We do both. Shipping apps teaches us where real code cuts corners; attacking apps teaches us what not to ship.

ElCampeon Apps

Free Android apps for people learning security and computer science. Written with Claude Code, with Claude API features in development.

  • Three apps live on Google Play
  • Free, and no account needed
  • AI features designed so no API key ever ships in an app
Explore the apps

ElCampeon Security

Hands-on security testing for web applications and APIs, by a researcher who reports vulnerabilities through bug bounty programs.

  • Web app and API testing: taking enquiries
  • AI and LLM application testing: coming 2027
  • CVSS 3.1 severity, a specific fix, a free retest
See security services
3Android apps live on Google Play, all free
0API keys inside our apps. Claude calls go through our own server.
30Days of free retesting after every security report
1Rule: written authorization before anything touches a target

Same endpoint, two views

Logged in? Checked. Yours? Never.

Serious bugs are rarely exotic. Usually it's one missing check: obvious from the attacker's side, invisible from the developer's. Drag the seam to see both.

Buildroutes/invoices.js
// Return one invoice to a logged-in user
router.get("/api/v2/invoices/:id", requireLogin,
  async (req, res) => {
    const inv = await Invoice.findById(req.params.id);
    // logged in? checked. yours? never checked.
    res.json(inv);
  });
request against stagingBreak
GET /api/v2/invoices/48213
Authorization: Bearer <user A's token>

HTTP/1.1 200 OK
{
  "invoice_id": 48213,
  "owner": "user B",
  "amount": "₹1,84,000"
}

One request with user A's login reads user B's invoice. The route checks that you're signed in, but never checks that the invoice belongs to you. That's broken object-level authorization, the most common serious API flaw we look for.Illustrative example, not taken from a client engagement.

Claude on both sides

AI speeds us up. A person signs off.

We use Claude where it makes the work faster or better, and keep a named person accountable for everything that ships or gets reported.

→ When we build

  • Our apps are written with Claude Code, then reviewed and tested by hand.
  • In-app tutors will call the Claude API through our own Cloudflare Worker, so no key ships inside an app.
  • We attack our own AI features for prompt injection and data leaks before they reach users.

← When we break

  • Claude helps map and prioritise an authorised target's attack surface during recon.
  • A person does the testing, and reproduces every finding before it goes in a report.
  • What we learn attacking AI products feeds back into how we build ours.

How we use Claude, in detail

Our rule

Nothing touches a target without written authorization and a person driving it.

No scanner left running overnight. No AI agent let loose on someone else's systems. Every test is scoped, signed and run by someone who answers for it. It's the same rule whether the tool is Burp Suite or Claude.

Roadmap

Where we're going

Only what's ahead. Nothing on this list is live yet, and we keep it up to date.

  1. NextIn development

    Claude tutor in Learn Web Application Security

    Plain-language explanations of any vulnerability, plus practice questions generated for your level.

    Web and API testing opens to clients

    First engagements, scoped and signed, with a full report and free retest.

  2. H1 2027Planned

    Claude features in our other two apps

    An algorithm tutor that walks through your own input, and general diet and activity suggestions in BMI Calculator.

    AI and LLM application testing

    Prompt injection, data leaking through tools and retrieval, and agents taking actions they shouldn't.

  3. 2027Planned

    AI and LLM security

    Security reviews of AI products end to end: models, prompts, tools, retrieval and the apps around them.

    Authorized red team engagements

    Adversary-style testing for organisations, under written rules of engagement agreed before day one.

Contact

Got something that needs building or breaking?

For a security test

Tell us the app or API, roughly how many endpoints or user roles it has, and when you need the report. We reply within two working days.

Found a flaw in our apps?

Report it to the same address. Our disclosure policy and security.txt have the details.