SERVICES
Read it. Fix it. Or have us build it.
The audit is self-serve: one repository, one price, no call required. Everything past that is an engagement, and we scope it from what the audit found rather than from a conversation about what might be wrong.
01 · THE AUDIT
A graded read of the whole repository.
Thirteen code dimensions and fifteen visual ones, graded A–F, worst finding first. Every finding cites a file and a line and ships with a prompt that fixes it. Usually under 90 minutes, and you watch it happen.
- Self-serve. No call, no scoping, no contract.
- A report you can hand to a client, an auditor or a buyer.
- Re-run it after fixes and watch the findings go green.
02 · REMEDIATION
We clear the findings for you.
Some people paste the prompts themselves. Others would rather hand the dossier back and have it done: credentials rotated and purged from history, dependencies upgraded, missing access checks added, tests written for the modules where a bug costs money.
- Scope comes from the audit, so the quote is a list of findings and not an estimate.
- Delivered as reviewable pull requests against your branch, on your terms.
- Closed out with a re-audit that shows the findings resolved.
03 · BUILD WITH YOU
Engineers alongside your team.
Your team knows the domain. They're short on time, or short one specific skill. We work in your repository and your standups on the part nobody internally has the bandwidth or the background to take: security, payments, data handling, infrastructure.
- Your process, your review standards, your release cadence.
- Knowledge stays behind: documented decisions, tests, and a graded codebase.
- Monthly re-audits give you and your board a trend line rather than an assurance.
04 · BUILD FOR YOU
We build it and hand it over.
A new product, or a rebuild of what a previous vendor left behind. The difference from the agency you may already have tried is that what we hand over has been audited by the same system we sell to everyone else, and you get the report with it.
- Delivered graded, tested and documented, with the audit trail attached.
- Written to be read by whoever comes next, not just to demo well.
- Handover includes the remediation list, if any, and the prompts to clear it.
HOW IT WORKS
Every engagement starts with an audit.
Not as an upsell. It's the only honest way to price the work, because a consultancy that quotes before reading your code is quoting a guess and you are the one carrying it.
01
Audit
$149 and usually under 90 minutes. You own the report either way, whether or not anything follows.
02
Scope from findings
We turn the dossier into a list: what we'd fix, in what order, and what we'd leave alone.
03
Fixed quote
Priced against that list. If the scope changes, the quote changes before the work does.
04
Re-audit
The same audit, run again, showing the findings resolved. That is the deliverable behind the invoice.
TALK TO US
Start with the audit.
Buy one, read it, then decide whether you want us anywhere near the codebase. If the report is short, that is the cheapest engagement you will never book. If it isn't, you will know exactly what you are asking us to quote.
Enterprise procurement, security review or a signed statement of work: start with the security page, then send us what your team needs answered.