For software you are about to ship, buy, fund or inherit. We read the code rather than run a scanner over it, and deliver a ranked report with file-level references, concrete failure scenarios and an effort estimate for every fix. Three to seven days, fixed price, no obligation to hire us for the fixes.
Read-only access is enough · NDA on request · Reply within one business day
Technical due diligence for an acquisition, a funding round or a joint venture. You get an independent view of what the asset actually is, what it will cost to maintain, and which claims in the deck the code does not support.
An MVP is about to meet paying customers. Find the authorisation gap, the exposed key and the query that times out at 10,000 rows before a customer does.
The agency delivered and left. Before your team commits to maintaining it, know what you have been handed and what the first three months of ownership will cost.
Codebases produced with Cursor, Lovable, Bolt, v0 or Replit have a recognisable set of problems. The audit is the first step of every rescue engagement.
An enterprise customer's security questionnaire, a SOC 2 or ISO 27001 effort, a GDPR question. Know your gaps before the auditor finds them for you.
Traffic is about to grow ten times. Find the parts of the system that were designed for one region, one tenant or one server while there is still time to change them.
Eight areas, every time. We read handlers, middleware, data access and infrastructure configuration line by line. Automated scanners run too, but their output is the starting point, not the report.
If a prior audit exists, we check each of its findings against the current code and report which are still open. That alone is often the most useful page.
One document per service or module, plus a summary you can hand to a board or an investor. Every finding is written so that an engineer who has never seen the codebase can go straight to the line and fix it.
X-Team-ID from the request and uses it to scope the query. Nothing verifies the authenticated user belongs to that team.The price is set after the scoping call and does not change. It does not depend on whether you hire us for the fixes afterwards.
Ask for a number. You get it within a business day.
A senior engineer reads the code, the infrastructure configuration and the data model, then delivers a written report covering architecture, security, data layer, reliability and operations, code quality, test coverage, dependencies and delivery process. Every finding has a severity, a file and line reference, a concrete failure scenario and an effort estimate for the fix.
Three to seven working days depending on codebase size. Under 25,000 lines is typically three days; up to 100,000 lines four to five days; larger codebases are scoped individually and may be split into modules.
Read-only access to the repository and, ideally, read-only access to the hosting or cloud console and a staging environment. We sign an NDA first if you want one. We do not need production credentials or customer data.
No. A penetration test probes a running system from the outside. A code audit reads the source and finds the class of bugs a pen test misses: authorisation logic errors, secrets in the repository, unsafe shell or SQL construction, data-layer problems that only appear at scale, and maintainability issues. The two are complementary; we can arrange both.
If you want. The audit stands on its own and you can take the report to any team. Many clients ask us to continue into a rescue engagement or a retainer, but there is no obligation and the audit price does not depend on it.
Yes, and it is a large share of what we audit. Apps generated with Cursor, Lovable, Bolt, v0 or Replit have a recognisable set of problems around authorisation, secrets handling, input validation and deployment. See our dedicated page on rescuing vibe-coded apps.
Tell us what the system does, roughly how big it is, and what decision the audit needs to inform. An engineer replies within one business day with a scoping call slot and a price.
NDA on request · Read-only access is enough