Every price on this page is the price.
Most shops make you book a call to find out what anything costs. We would rather you knew before you got in touch. Pick the one that matches where your app is today, whoever built it.
From "is this thing safe?" to production you own
Start wherever it makes sense and stop whenever you want. Nothing here requires the next thing.
Free Scan
We scan your live app's public surface for the failure modes that show up in almost every handed-off codebase: exposed keys, open data policies, missing auth boundaries. You get a findings count and severity breakdown.
Scan your site
Deep Audit
A senior engineer does a full code audit and security audit of your app by hand, on top of the automated pass: source code review, data layer, authentication, API access, and infrastructure. If you are on Supabase or Firebase, that includes your row level security policies, security rules, and exposed keys. You get a written report that sorts every finding into Must Fix, Should Fix, and Nice to Have, in language you can act on without a translator. Includes a findings call.
Rescue Sprint
We fix every Must Fix item from your audit report, then re-scan and hand you a verification report showing what changed. The audit list is the contract boundary, so the price does not move while we work. Anything we discover along the way goes on a change order, with your say-so.
Full Remediation
The same work at a larger scope: Must Fix and Should Fix items together, structural refactoring where the previous team painted you into a corner, and test coverage on the paths that matter. Priced from the audit report, so you see the number before we start.
Outgrow
Your app has outgrown the platform it was built on, or it is sitting on accounts and infrastructure someone else set up and still controls. We move it onto infrastructure you own, with nothing lost on the way across. You end up with the repository, infrastructure as configuration, a CI/CD pipeline, monitoring, and a runbook your next engineer can actually read.
After the fix
Two ways to keep a senior engineer in reach without hiring one, plus a side door for professional buyers.
Incidents and advice, not feature work. Hours are included by tier and expire monthly.
- 4, 8, or 12 hours per month
- Next business day response
- Quarterly re-scan included
- Cancel any time
The technical adult in the room. We review what your team or your tools are shipping, steer architecture, and sit in investor conversations with you.
- Architecture direction
- Build versus buy calls
- Code review on what ships
- Investor and diligence support
For angels, micro-PE, and acquirers buying a product they did not watch get built. An unsentimental read on what is actually under the hood.
- Code and infrastructure review
- Risk and remediation cost estimate
- Platform and vendor dependency assessment
- Written report inside one week
Or start with nothing at all
Everything above is for apps that already exist. If yours does not yet, this is the same two engineers on a longer engagement.
Custom Product Development
Full-cycle builds from architecture through launch. React, Next.js, React Native, Node, Python, Supabase, AWS. Two architect-level engineers, no juniors, no handoffs, fixed price with milestone payments.
Architecture reviews and standalone technical advisory start at $300.
$5,000 project floor
Four rules we do not bend
01 No fix without an audit
We will not quote a rescue on a codebase we have not read. The audit is what makes a fixed price honest instead of a guess, and it is what keeps the scope from moving under you.
02 The report is yours either way
The audit is a standalone deliverable, not a sales call in disguise. If you take the report and fix everything yourself, that is a fine outcome and we will answer questions about it.
03 A clean audit gets a certificate
If we find nothing serious, you get a scoped and dated readiness report you can hand to an investor or a customer's security review. We state what we checked and what we did not.
04 Every finding in your report is triaged by a person
Automated scanners over-report. Your free scan returns a machine count, so you get an answer in seconds. Before any report reaches you, a senior engineer reviews and rates every single finding, so a forty item list does not arrive with fifteen items of noise in it.
Tell us where you are
Three questions. They decide whether you need us at all, and where to start. If the answers point to a free scan and a checklist instead of a paid engagement, we will tell you that.