ElCampeon Systems

How we use Claude

Built with Claude. Signed off by people.

Claude is part of how we build apps and how we test them. Here's exactly where it's used, where it isn't, and the rules we keep on both sides.

Illustrative example of a Claude Code session

Where Claude is in our work

Claude does the heavy lifting. We answer for it.

Every use has a named person on the other end who reviews, decides and takes responsibility.

Writing our Android apps

Claude Code

Writes and refactors app code from our specs and lessons.

A person

Reviews every change, tests it on devices and decides what ships to Google Play.

In use

Tutors inside the apps

Claude API

Explains concepts, generates practice questions and walks through examples.

A person

Designs the prompts and limits, attacks the feature for prompt injection, and approves release.

In development

Recon in security tests

Claude

Helps sort and prioritise the attack-surface map of an authorised target.

A person

Chooses what to test, does the testing by hand, and reproduces every finding before it's reported.

In use

Architecture

No key in the app. No logs on the server.

How our apps will reach the Claude API. We test security for a living, so it's designed the way we'd want a client's to be. In development

Android app

Sends only the text the learner chooses to send. No account, no identifiers, no API key.

Cloudflare Worker

Holds the key as a secret, rate-limits requests, and keeps no logs of questions.

Claude API

Generates the answer under Anthropic's commercial terms and privacy policy.

Key never ships

A key inside an APK can be pulled out in minutes. Ours lives only in the Worker's secret store.

Abuse limited

Rate limits at the Worker stop one client from draining the key or using the tutor as a free general chatbot.

Attacked first

Before release we test each feature for prompt injection, system-prompt leaks and off-topic misuse.

Responsible use

The rules we keep

Security work and AI tools are both powerful. These apply to every engagement and every tool, Claude included.

  1. Written authorization, every time

    We test only systems the client owns or controls, named in a signed authorization, within the agreed window. No exceptions for "quick checks".

  2. A person drives every action

    Claude helps us think, sort and write. It is never left to scan or exploit anyone's systems unattended.

  3. We follow the rules of the tools and the programs

    Anthropic's Usage Policy, and the scope and rules of every bug bounty and disclosure program we take part in.

  4. Every finding is reproduced by hand

    Nothing goes in a report because a tool said so. If we can't reproduce it, we don't report it.

  5. Client data is handled carefully, then deleted

    Test accounts, notes and evidence are kept confidential and deleted when the engagement ends.

  6. We test our own AI first

    Before we test anyone else's AI product, we attack our own Claude features and fix what we find.

Toward AI security

From web bugs to AI red teaming

The same skills that find a missing authorization check find an agent that can be talked into one. We're building toward it deliberately.

  1. NowTraining

    HTB Academy AI Red Teamer path

    Building on EC-Council CPENT AI, and working toward Hack The Box's COAE certification.

  2. H1 2027Planned

    AI and LLM application testing

    Prompt injection, data leaking through tools and retrieval, and agents acting beyond their remit.

  3. 2027Planned

    Authorized red team engagements

    Adversary-style testing of AI systems and the organisations around them, under written rules of engagement.

Questions

Ask us how we use AI.

[email protected]
Clients

We'll tell you up front where Claude is used in your engagement, and answer any question about it.

Not affiliated

Claude is a trademark of Anthropic, PBC. ElCampeon Systems is an independent company, not a partner of Anthropic.