FAQ

Questions people usually ask.

Short answers on access, ownership, money and time. Anything not here: ask a question, and Aaron answers.

Access, confidentiality and ownership

What access do you need, and how is it revoked?

Only what the work needs, given in one of two ways. By default it is at arm's length: you invite a dedicated Anyfront account, never a personal one, to the repositories in scope, with read access for an audit and write access for a sprint, a retainer or a quoted project. Every change arrives as a pull request that you merge, and production secrets are never requested: if a task needs a credential, it is a staging or scoped one, shared through your secret manager or a one-time share.

If you would rather have the work done than proposed, as in a takeover or a clean-up, you can choose delegated access in the proposal. Within the scope it sets, Aaron merges, deploys and changes infrastructure without asking you to approve each change, through a role on your own accounts that you can remove at any time. You stay the owner of every account, nobody shares root credentials, and every change goes through version control and into a change log.

GitLab and Bitbucket work the same way. For Lovable, Bolt and Replit projects, GitHub sync is preferred, and a project invite works otherwise. At the end of the engagement the access is removed and the removal is confirmed in writing, unless a retainer continues. You can also remove it yourself at any time.

The two access modes

Do you sign NDAs?

Yes. A mutual NDA is available, and it can be signed before a discovery call or before you share anything. The terms of service also carry mutual confidentiality, so an engagement is covered even without a separate NDA.

Terms of service

Who owns the code you write?

You do, once it is paid for. The intellectual property in the deliverables, including the code in every pull request, is assigned to you on payment. Pre-existing tools, such as scripts, templates and checklists, stay with Anystack G.K., and you get a licence to use them with the deliverables.

Terms of service

Does the free check look at my code?

No. The free check looks only at what your deployed app already serves to anyone on the internet: its pages, the JavaScript it sends to browsers, its headers and its error pages. It never reads or scans private code, and it does not need access to your repositories.

A read-only repository invite is accepted as one way to show that the app is yours, and that is all it is used for. Reviewing your code is the audit.

The free check

How the work is approached

Do you rewrite or fix what is there?

Fix what is there, by default. A production-readiness sprint takes its fixed scope from the audit findings and delivers it as pull requests against your existing code. A rewrite or a modernisation project is proposed only when the audit shows it is worth the cost, and it is quoted separately.

The production-readiness sprint

Can you just take over my app?

Yes. Taking over an app is the audit, the production-readiness sprint and an engineering retainer, in that order. The audit finds out what "ready" means for your app. The sprint closes the most important gaps it finds, at a fixed price, with the audit fee credited if you book it within 30 days of the readout. The retainer then looks after the app month to month. If the audit finds more than one sprint's work, it says so, and anything further is quoted before it starts.

You keep ownership throughout. The code stays in your GitHub organisation, hosting and accounts stay in your name, you get written handover notes, and access is revoked if the retainer ends. If you choose delegated access in the proposal, Aaron merges and deploys within the agreed scope, with every change in version control and a change log; otherwise every change is a pull request you merge.

Taking over an app

Will you move us off Lovable, Bolt or Replit?

Not by default. The platform got your app this far, and the default recommendation is to make it hold up in production where it is. Moving off a platform is recommended only when the audit shows the move is worth its cost, and then it is quoted as a modernisation project.

Modernisation

What if the audit finds nothing serious?

Then the report says so, and says what was reviewed and how. That is a result you can use, for example when an investor or an enterprise customer asks how the app was checked. The fee is for the review, not for the number of findings.

Nothing further is proposed unless the findings call for it: a sprint, a retainer or a project follows an audit only when there is work worth doing.

The audit

Is the audit a security guarantee?

No. It is a professional review against a defined scope: the one in your proposal. It is not a penetration test, a certification or a guarantee that the app is free of vulnerabilities.

The report says what was found and what it means for the business. Not finding a problem does not prove it is not there.

What the audit covers

Who, where and when

Who does the work?

Aaron Culbert. Every engagement is scoped, reviewed and signed off by him, and nobody else works on your code without your written agreement. Anyfront is a service of Anystack G.K., a company registered in Japan, which holds the contract and sends the invoices.

Delivery is AI-assisted: Aaron uses AI tools under his own direction, and reviews everything before it reaches you.

About Aaron and Anystack G.K.

What time zones do you work in, and how fast do you respond?

Aaron works in JST (UTC+9), which overlaps Australian business hours. Calls in UK mornings and US evenings are by arrangement.

Free-check reviews are done within 2 business days. Audits are delivered in 5 to 10 business days. Retainer response times are set in the proposal.

Book a call

Hours, money and invoices

How do retainer hours and overage work?

Each retainer has a monthly hour cap: up to 4 hours for the advisory retainer, 20 for the engineering retainer and 40 for the fractional retainer. Retainer terms: Monthly, 30 days' notice, unused hours do not roll over.

Overage is billed at the plan's effective hourly rate (the monthly fee divided by the hour cap), only with your prior approval. It is billed monthly in arrears.

The retainers

What payment methods and currencies do you take, and how is invoicing done?

All payments go through Stripe: Checkout for fixed-price offers, Invoicing for quoted work and Billing for retainers. Audits and retainers can be paid by card or a local method Stripe supports, and invoices above US$5,000 can be paid by bank transfer, through Stripe Invoicing or Wise.

Prices are published in US dollars, Australian dollars and Japanese yen, each set in its own currency rather than converted. Invoices come from Anystack G.K., Japan. Prices exclude GST / consumption tax where applicable.

Prices and payment terms

Start with the free check.

It costs nothing and commits you to nothing. If you would rather talk first, book a 30-minute call.