Code and product audit
A fixed-price review of your code and the business it carries.
Aaron reviews your app's code, data and infrastructure alongside your product and business goals. You get a written report that ranks every finding by what it means for the business, a plan to fix it, and a fixed price for the fix.
US$3,300A$4,900¥490,000 fixed, in 5–10 business days
Prices exclude GST / consumption tax where applicable.
Who it is for
Apps built quickly, often with AI tools, that now have to hold up for real customers. It is usually one of these moments:
- You are about to launch, or about to take your first payments.
- Something has gone wrong, such as a leak or an outage, and you want to know what else is waiting.
- You are raising, and an investor will ask how the app is built.
- An enterprise customer has sent you a security questionnaire.
- A tool someone built quickly has become one the business depends on.
What is reviewed
The whole app, not only what is visible from outside: the free check looks only at the public surface and never reads private code, and the audit reads the code.
- Code and architecture
- How the app is put together, and whether it can carry the next year of the product.
- Data model and access control
- Who can read and change which records, checked against who should.
- Authentication
- Sign-up, sign-in, sessions, password reset and roles.
- Secrets
- Keys and credentials: where they live, who can reach them, and what ships to the browser.
- Infrastructure and deploys
- Hosting, environments, and how a change reaches production and comes back out.
- Dependencies
- What the app relies on, how current it is, and what is known to be vulnerable.
- Performance
- What users wait for now, and what will slow down as the data grows.
- Product and business goals
- An interview about what the app has to do for the business next, so every finding can be ranked by what it means for it.
What you get
- A written report, with every finding ranked by business impact: revenue, security exposure, fundraising or enterprise-sale readiness, and the cost to change it later. Not only by severity.
- A remediation plan: what to fix, in what order, and roughly how much work each fix is.
- A fixed-price quote for a production-readiness sprint, scoped from the findings, if the findings call for one.
- A 60-minute readout: a call to walk through the findings and answer your questions.
Every finding is written the way the free check's report writes it: a severity, its business impact in one line, and the fix. Read the sample audit of a fictional app, from the summary to the sprint quote, beside the sample report of its free check.
How long it takes, and what access it needs
5 to 10 business days from the day access is granted to the day the report arrives. The readout follows at a time that suits you.
Read-only access. You invite a dedicated Anyfront account to the repositories in scope, with read access only. Nothing is changed during an audit.
No production secrets. They are never requested. If a check needs a credential, it is a staging or scoped one, shared through your secret manager or a one-time share.
Price and payment
Audit
US$3,300A$4,900¥490,000
One fixed price, the same for every client.
- 100% at booking. Work starts once the payment is received.
- Refundable in full until access is granted. Once access is granted and work starts, the fee is non-refundable.
- Credited against a sprint. If you book a production-readiness sprint within 30 days of the readout, the audit fee is credited against it.
Prices exclude GST / consumption tax where applicable. Every price and payment term is on the pricing page.
If you want someone to take the app over
The audit is also the first step of a takeover: a fixed-price sprint scoped from its findings, with the audit fee credited if you book it within 30 days of the readout, then an engineering retainer for ongoing ownership. The code and the accounts stay in your name throughout.
Not a security guarantee
An audit is a professional review against a defined scope: the one in your proposal. It is not a penetration test, a certification or a guarantee that the app is free of vulnerabilities. The report says what was found and what it means for the business. Not finding a problem does not prove it is not there.
Not sure yet? Start with the free check.
The free check scans your app's public surface and is reviewed by Aaron within two business days. Or book a 30-minute call, and if an audit will not help, Aaron will say so.