CASE STUDY · AI FINANCIAL MODELLING · EXCEL ADD-IN · CLIENT ASSURANCE
How Cellori reassured an institutional client with a penetration test set up in days.
Cellori builds AI financial modelling software for institutional investors. An institutional client asked for independent security assurance, and wanted it fast. EJN Labs set out a route to proceed within two days and tested the product. The client reviewed the report and EJN Labs’ credentials, and accepted them.

- Industry
- AI financial modelling software
- Market
- Institutional investors · infrastructure and real assets
- Service
- Application + API penetration test
- Engagement
- Client-driven assurance
- Scope
- Excel add-in · API · supporting components
- Complexity
- Multi-component product
- Dates
- June 2026
The challenge.
Cellori builds software that helps infrastructure investors value and acquire assets, particularly renewable energy assets. Its core clients are institutional financial services firms. In its founder’s words, that makes for a difficult conversation around governance.
One institutional client asked for independent security assurance and wanted it as quickly as possible. The requirement was entirely client-driven.
Why Cellori chose EJN Labs.
On that call EJN Labs described similar projects, particularly in the Excel add-in environment. Cellori found that quite rare among the providers it spoke to.
No long forms before a decision. Cellori explained what it needed and did not have to go back and forth on scope. Its founder recalls starting the next business day or the day after.
Cellori wanted to matter to its testing provider, rather than be one account among many.
Cellori needed its client to accept the testing provider. EJN Labs supplied more evidence of its credentials, and the founder says they got there.
The scope we set out.
This is the scope EJN Labs set out before testing Cellori’s Excel add-in and the components that work with it. EJN Labs was given access to a dedicated test environment, not live production. We publish scope, not exploit detail.
- Authentication and authorisationSign-in, sessions and permission checks.
- Access and data segregationSeparation of each customer’s data and access.
- API securityThe interfaces between the product’s components.
- File handling and workflowsFile processing and workflow controls.
- Audit functionalityRecording of user and system actions.
- Infrastructure exposureInternet-facing services that support the product.
How the engagement worked.
- FIRST CALLScope
Cellori explained the product and the client’s demand for speed. No generic forms. A route to proceed followed within two days.
- AGREEMENTAgree
NDA and statement of work signed.
- AFTER SIGNINGTest
Testing began, with a shared Slack channel for questions, findings and fixes.
- DURING TESTINGFix
Cellori fixed issues as they were raised. The loop between a finding and its fix worked quickly.
- AFTER TESTINGReport
Cellori shared the report and EJN Labs’ credentials with its client.
Results and business impact.
- Cellori’s client reviewed the report and EJN Labs’ credentials, and accepted them.
- In the founder’s words, the client loved it and Cellori was proceeding with them.
- Cellori valued having an independent team scrutinise a product its own team had built.
- Cellori says it would be happy to use EJN Labs again or recommend it to another organisation.
It did work, the client loved it and we’re proceeding with them. So we got instant ROI out of the engagement.
Check our accreditations yourself.
Do not take our badges on trust. These are the public registers where you can check them.
// READY?
Book a 30-minute scoping call.
Tell us your procurement or audit deadline. We’ll size the engagement the same day.



