Find out what you actually shipped.
Two weeks. Three senior engineers. Every finding written down with evidence, a severity, and what it costs to fix. You get a prioritized roadmap you can act on with us, with someone else, or on your own.
A human, not an agent, is the reviewer.
What a fix list actually looks like
Sample rows from a real report, anonymized. Every one has a severity, a location, and an estimate. Nothing says "consider reviewing."
Session tokens signed with a hardcoded secret in git history
~3 hrsAdmin endpoints authorize on a client-supplied role claim
~4 hrsNo rate limiting on login or password reset
~4 hrsFour dependencies unmaintained for 2+ years, one carrying a known CVE
~9 hrsTest suite covers 11% of a critical user path
~10 hrsIs this you?
The audit exists for one situation: software that works, that nobody can vouch for. Most of the codebases we see got there honestly: fast, under pressure, with tools that write plausible code very quickly.
This is designed for you if…
- You shipped fast — with AI assistance, a contractor, or an agency — and nobody on your team can vouch for everything that's in there.
- It works in a demo, and you're about to put real customers, real money, or real personal data through it.
- You inherited a codebase and need to know what you actually own before you invest another dollar in it.
- You're doing technical diligence on an acquisition or a portfolio company.
- Something already broke, and you need to know whether it was one-off bug or a pattern.
Skip it if…
- There's nothing built yet. (We can help you with a fixed-price build instead!)
- You already know exactly what's wrong and just need it fixed. Tell us and we'll quote the fix directly. No point paying us to confirm it.
- You need someone to attack a live system and prove exploitability. That's a penetration test, and we'll refer you to a trusted partner.
What we need from you
- Read-only repository accessWe never write to anything.
- Read-only infrastructure accessHosting, and whatever it depends on.
- 90 minutes of one subject-matter expertOnce. Nothing to prepare in advance.
The methodology, in full
Published because the judgment is the product. If you'd rather run this yourself using the outline below, do that. Genuinely. We'd rather be hired by someone who understands what they're buying.
We read before we judge. Repository history, architecture, deployment path, and a 90-minute walkthrough with whoever knows the system best.
Then we establish what "production-ready" means for you specifically: expected traffic, how sensitive the data is, what uptime actually costs you when it's gone, and any compliance obligations you're carrying. A prototype for ten internal users and a system holding patient records fail in completely different ways, and a generic checklist catches neither.
Delivered Readiness bar, agreed in writing
Automated analysis across the whole codebase. This is where breadth comes from, and it's the part most audits skip, because it takes tooling rather than reading.
Static analysis (SAST) and dependency composition (SCA), secret scanning across full git history rather than just the current tree, infrastructure-as-code scanning, and license scanning. Dependencies get verified against registry age, ownership, and download history. AI-suggested packages routinely name registries that don't exist, and the hallucinated names repeat consistently enough that people squat them.
We also run comprehension analysis to find where knowledge has evaporated, map the blast radius of every credential and integration, and execute your test suite repeatedly to measure real coverage and real flakiness rather than reported numbers.
Delivered Comprehension map
Three senior engineers read the code. Scanners find known patterns; they don't find business-logic flaws, broken authorization, or an architecture that will fall over at ten times the load. That still takes people.
Authentication and authorization paths traced by hand, end to end. Data handling: what's collected, where it rests, how it's encrypted, and whether the backup restores. Tested, not assumed. Infrastructure configuration against CIS Benchmarks. Architecture review for coupling and single points of failure. Then targeted deep reads wherever phase two raised a flag.
Delivered Security analysis
Every finding gets evidence, a location, a severity, and reproduction steps. Nothing appears in the report as an assertion you have to take on faith.
Then the part that makes it useful: each one is costed in hours and dollars and sorted into fix before launch, fix before you scale, and accept and monitor. That last category is deliberate. A finding you consciously accept is a decision, and it goes in the report as one.
We close with a 60-minute readout with your team, recorded, where you can argue with our severities. Sometimes you'll be right; you know your business and we've known your codebase for two weeks.
Delivered Prioritized fix list
Assessed against OWASP ASVS Level 1 and 2, CIS Benchmarks for infrastructure configuration, and a NIST SSDF-aligned review of your development lifecycle. Public standards, so you can check our work, and so a second opinion has something to disagree with.
What you get
Artifacts, not impressions. Everything below is yours to keep, share with your board, or hand to another firm.
Production-Readiness Report
The full written assessment, cryptographically signed and independently verifiable. Anyone you forward it to can confirm it hasn't been altered.
Prioritized fix list, costed
Every finding with severity, evidence, and a real remediation estimate in hours and dollars. This doubles as the scope document for whoever does the work.
Comprehension map
Which parts of your codebase no one on your team meaningfully understands, per file. Usually the most uncomfortable page in the report.
Security analysis
What each credential, integration, and automated agent can actually reach if it's compromised. Not what it was intended to reach.
Dependency & license inventory
Everything you depend on, its known vulnerabilities, its provenance, and whether its license is compatible with how you're shipping.
Test coverage baseline
Real coverage and real flakiness, measured over repeated runs. A number you can hold future work against.
We built the instruments
Most audits are a senior engineer's reading comprehension in a PDF. Ours is generated from tooling we wrote ourselves, because the measurements we needed didn't exist.
Fathohm
Scores comprehension debt: how much of a codebase no human has meaningfully reviewed. It turns "we're not sure what's in there" into a number with a map attached.
Caveat
Agent access control and security analysis. It answers what your automated tooling is permitted to touch, and what it could reach if someone took it over.
Self-healing test suite
Runs your tests the way reality does — repeatedly, under churn — to separate genuine coverage from tests that pass because nothing is really being asserted.
What this is not
- Not a penetration test. We assess; we don't exploit. If you need proven exploitability, that's specialist work and we'll refer you to a trusted partner rather than pretend otherwise.
- Not a certification. We assess against OWASP ASVS and CIS Benchmarks. OWASP certifies no vendors, and anyone claiming an ASVS certification is misrepresenting it.
- Not a guarantee. This is a point-in-time assessment. Nobody can warrant software as secure, and residual risk stays with you. We'll say so in writing, not in a disclaimer you never read.
- Not a repair. We don't change your code during the audit. Assessment and remediation stay separate so we're never grading our own work.
- Not continuous. It reflects your system as of the readout. Code written afterward is unexamined by definition.
$5,000 flat. You get it back if you hire us.
Fixed price, quoted before we start, invoiced once. No hourly billing, no change orders, no discovery phase that quietly becomes the engagement.
The entire fee is credited against any work you start with us within 60 days. If the audit turns up $18,000 of hardening and you want us to do it, the hardening costs $13,000.
Which means: if you hire us, the audit was free. If you don't, you keep a costed roadmap any competent firm can execute. We're fine with that outcome.
Two weeks from now, you could actually know.
Tell us what you've got. We'll tell you honestly whether an audit is the right call.