Service 1: Audit what you have
Before we build anything, we find out what you actually trust today. Most teams are surprised: a typical SaaS-plus-AI stack gives dozens of parties the ability to read customer data or change production. Our audit names every one of them, finds what's exploitable now, and gives you a fixed-price plan to fix it.
The audit fee is credited 100% toward any build you sign within 60 days.
Launch Audit: $2,900 fixed, 5 business days
For startups and small teams, especially apps built quickly with AI coding tools (see Vibecoded startups).
Scope: one product. That means one web or mobile app, its backend and database, its cloud account, its CI/CD and its AI/LLM features.
What we check:
- Secrets exposed in the client bundle, the repo, git history, logs or CI
- Authentication and authorization: broken object-level access (IDOR), unprotected admin routes, and weak session handling
- Database access rules, such as Supabase row-level security and Firebase rules, plus public storage buckets
- Payment and webhook flows: unsigned webhooks, price tampering, replay
- LLM features: prompt injection, data exfiltration through tools, and over-privileged agent actions
- Abuse and cost controls: rate limits, and bill-shock exposure on paid APIs
- Dependencies: known CVEs, typosquatted or hallucinated packages, abandoned libraries
- Where your data goes: every third-party service that receives user data (your first TCB map)
You get:
- A findings report ranked by real exploitability, with proof-of-concept steps for each critical finding
- Fixes for up to three critical findings, delivered as pull requests to your repo
- A one-page TCB map: who can read your data today
- A security overview you can send to enterprise prospects, plus draft answers to a standard security questionnaire
- A free retest within 30 days
Sovereignty Audit: from $14,500, 2–3 weeks
For biotech, regulated businesses and scaling companies that need evidence for regulators, auditors, partners or acquirers.
Everything in the Launch Audit, plus:
- Full data-flow and residency map. Which data lives where, and in which jurisdiction. Who processes it, and under which contracts and subprocessors.
- TCB map with a reduction plan. Every party that can read or alter your data or systems (cloud operators, SaaS vendors, AI providers, admins, CI pipelines) and the concrete step that removes or contains each one.
- Threat model. Your realistic adversaries, including insiders, vendors and supply-chain attacks, and the attack paths that matter.
- AI exposure review. Which models and AI vendors see which data, their retention and training terms, and your prompt-injection surface.
- Compliance mapping. Your controls mapped to the frameworks you answer to, with gaps flagged: HIPAA, GDPR, CCPA/CPRA, 21 CFR Part 11 and GxP, SOC 2, ISO 27001, PCI DSS, DORA, NIS2, the EU AI Act and LATAM data-protection and AI rules.
- Hardware and deployment plan. The right GPUs, the right deployment (on-prem, colocation, confidential cloud or hybrid) and the option that fits your budget. See GPUs, hardware and colocation.
- Logging and evidence review. Can you prove what happened, and when? Where do your audit trails fail?
- Roadmap with fixed prices. Every fix is scoped and quoted, so you can approve the plan line by line.
- An executive readout for your leadership or board
Scope and price depend on the number of systems and environments. We quote a fixed price after the first call.
Continuous Assurance: $1,200 / month
For teams that ship every day. After any audit, we keep watching:
- A monthly rescan of repos, cloud configuration and dependencies
- Alerts for new exposed secrets and critical CVEs
- A quarterly TCB review: new vendors, new data flows, new AI features
- Help with security questionnaires and customer due diligence (up to 4 per month)
How it runs
- Kickoff (day 1). Mutual NDA, read-only access, and a 60-minute walkthrough with your lead engineer.
- Assessment. Automated scanning plus manual review by a senior engineer. We never run destructive tests without your written authorization.
- Readout. A live session going through findings and fixes, plus the written report.
- Fix or hand off. Fix it yourself using our report, or have us do it as a fixed-price build.
What an audit is not
- It isn't a SOC 2 or ISO 27001 certification. Only licensed CPA firms and accredited certification bodies can issue those. We get you ready, and our evidence feeds their work.
- It isn't legal advice. We map technical controls to regulations. Your counsel confirms your obligations.
- It isn't a guarantee that you can't be breached. Nobody can honestly promise that. We make the remaining risk small, known and written down.
Book a free call to scope your audit.