Code and product audit

A fixed-price review of your code and the business it carries.

Aaron reviews your app's code, data and infrastructure alongside your product and business goals. You get a written report that ranks every finding by what it means for the business, a plan to fix it, and a fixed price for the fix.

US$3,300A$4,900¥490,000 fixed, in 5–10 business days

Prices exclude GST / consumption tax where applicable.

Who it is for

Apps built quickly, often with AI tools, that now have to hold up for real customers. It is usually one of these moments:

  • You are about to launch, or about to take your first payments.
  • Something has gone wrong, such as a leak or an outage, and you want to know what else is waiting.
  • You are raising, and an investor will ask how the app is built.
  • An enterprise customer has sent you a security questionnaire.
  • A tool someone built quickly has become one the business depends on.

What is reviewed

The whole app, not only what is visible from outside: the free check looks only at the public surface and never reads private code, and the audit reads the code.

Code and architecture
How the app is put together, and whether it can carry the next year of the product.
Data model and access control
Who can read and change which records, checked against who should.
Authentication
Sign-up, sign-in, sessions, password reset and roles.
Secrets
Keys and credentials: where they live, who can reach them, and what ships to the browser.
Infrastructure and deploys
Hosting, environments, and how a change reaches production and comes back out.
Dependencies
What the app relies on, how current it is, and what is known to be vulnerable.
Performance
What users wait for now, and what will slow down as the data grows.
Product and business goals
An interview about what the app has to do for the business next, so every finding can be ranked by what it means for it.

What you get

  • A written report, with every finding ranked by business impact: revenue, security exposure, fundraising or enterprise-sale readiness, and the cost to change it later. Not only by severity.
  • A remediation plan: what to fix, in what order, and roughly how much work each fix is.
  • A fixed-price quote for a production-readiness sprint, scoped from the findings, if the findings call for one.
  • A 60-minute readout: a call to walk through the findings and answer your questions.

Every finding is written the way the free check's report writes it: a severity, its business impact in one line, and the fix. Read the sample audit of a fictional app, from the summary to the sprint quote, beside the sample report of its free check.

See a sample audit

How long it takes, and what access it needs

5 to 10 business days from the day access is granted to the day the report arrives. The readout follows at a time that suits you.

Read-only access. You invite a dedicated Anyfront account to the repositories in scope, with read access only. Nothing is changed during an audit.

No production secrets. They are never requested. If a check needs a credential, it is a staging or scoped one, shared through your secret manager or a one-time share.

How access is given

Price and payment

Prices in

Audit

US$3,300A$4,900¥490,000

One fixed price, the same for every client.

  • 100% at booking. Work starts once the payment is received.
  • Refundable in full until access is granted. Once access is granted and work starts, the fee is non-refundable.
  • Credited against a sprint. If you book a production-readiness sprint within 30 days of the readout, the audit fee is credited against it.

Prices exclude GST / consumption tax where applicable. Every price and payment term is on the pricing page.

If you want someone to take the app over

The audit is also the first step of a takeover: a fixed-price sprint scoped from its findings, with the audit fee credited if you book it within 30 days of the readout, then an engineering retainer for ongoing ownership. The code and the accounts stay in your name throughout.

Taking over an app

Not a security guarantee

An audit is a professional review against a defined scope: the one in your proposal. It is not a penetration test, a certification or a guarantee that the app is free of vulnerabilities. The report says what was found and what it means for the business. Not finding a problem does not prove it is not there.

Not sure yet? Start with the free check.

The free check scans your app's public surface and is reviewed by Aaron within two business days. Or book a 30-minute call, and if an audit will not help, Aaron will say so.