What you get
A fixed-scope evidence-backed audit: buyer-path tests, risk-ranked findings, remediation plan, and an executive-ready closure report. The optional fix sprint is separately scoped after the audit.
Deliverables
- ✅ Evidence register (JSON + Markdown) — every finding with file:line, reproduction steps, severity
- ✅ Risk-ranked remediation plan — owner, effort, rollback, verification per item
- ✅ Executive summary — 1-page for leadership, no jargon
- ✅ Optional: Fix sprint — separately approved, scoped from findings
Scope boundaries (what we do NOT do)
- ❌ Penetration testing or red-teaming
- ❌ Legal/compliance certification
- ❌ Unrestricted source-code review beyond agreed scope
- ❌ Production changes without explicit approval
Process
- Scope confirmation — Agree repository, deployed URL, auth model, payment provider, test boundaries.
- Inventory & reproduction — Non-destructive probes, isolated test data, buyer-path reproduction.
- Evidence register — Every finding with file:line, severity, customer impact, reproduction, verification, rollback.
- Remediation plan — Owner, effort, risk, rollback, verification per item. Prioritized by buyer-path risk.
- Executive summary — 1-page for leadership. No jargon.
- Optional fix sprint — Separately approved, scoped from findings. $1,500 after review.
Safety boundary
No deployment, billing change, production write, outreach, or destructive action without explicit approval. Secrets are not copied into the report. Test data is isolated and cleaned up.
FAQ
- What does the audit actually cover?
- The agreed repository and deployed buyer path: auth, tenant boundaries, billing/checkout, webhook verification, fulfillment, health checks, tests, and release controls relevant to your stack.
- What do I receive?
- A prioritized evidence register, reproducible findings, recommended fixes, rollback notes, and a concise leadership summary. No production change is made without approval.
- How long does it take?
- Two business days after access and scope confirmation. The fix sprint (if approved) is separately timed.
- What if you find something critical?
- We stop, document, and escalate immediately. You decide the response. No silent fixes.
- Can this run against our private repo?
- Yes. We operate on your infrastructure or a scoped clone. No code leaves your boundary without approval.
Price & next step
$499 fixed-scope audit / $1,500 fix sprint after findings review
Fixed-scope audit. No hidden fees. Fix sprint only after findings review.
Why this audit exists
Every SaaS we've audited had at least one buyer-path defect that looked fine in CI but failed in production: webhook signature bypass, tenant bleed, fulfillment dead-end, silent auth bypass. The cost of finding it after a customer complains is 10-100× the cost of finding it first.
This audit is the tool we built for ourselves, now available to you.