We find what breaks before your customers or auditors do.
A fixed-scope, fixed-fee review of one system. We run the same checklist we run on our own platform, and each finding includes the evidence, a reproducible failure scenario, and a remediation estimate.
This review is for a system already serving real users, or about to be enabled in production. It is not an AI strategy assessment, a discovery workshop, a code-quality review, or automated pull-request scanning. If your system has not yet reached production, this is not the right engagement.
What happens
Two calendar weeks. 12–16 hours of our time against a fixed checklist covering automated checks, failure behaviour, AI-specific obligations, data protection, security, and operability. An automated scan takes minutes, and we run scanners too, but failure behaviour, data handling, and operational readiness need a person reading the code and the deployment path — that is what the two weeks buys.
One written report at the end. It is self-contained, and a walkthrough call plus asynchronous follow-up questions are included — no slide deck, no ongoing engagement implied.
What we mean by “one system”
The application code, its CI/CD configuration, one production deployment path, and its direct model and third-party integrations. Repositories, services, and environments in scope are agreed in writing before work starts.
What we need from you before starting
We do not begin without these. Confirming inputs before start keeps the review within the agreed scope and fixed fee.
Read access to the repository, including CI configuration.
A running instance, or the ability to run it locally, plus how it is deployed.
A named owner who can answer questions asynchronously within one working day.
One sentence on what the system does and what would hurt most if it broke.
Whether any decision it makes affects a person — hiring, credit, pricing, access, employment, or similar.
What you get
Findings ranked Critical, High, Medium, or Low.
Each finding cites evidence — a file and line, a command and its output, a request and its response.
Each finding carries a concrete failure scenario: what input, in what state, produces what wrong result.
A fix estimate against every finding, so remediation can be quoted separately.
An executive summary a non-engineer can act on: the three things to fix first, and why.
Price
£2.5k–£4k
£2.5k — one repository or service, on a standard deployment path.
£4k — multiple services or repositories, several direct integrations, or where the system makes or materially influences decisions about people.
The band is confirmed from the written scope before work begins. Published here so there is no qualifying call before you can decide — you already have the number you need.
What is out of scope
This is not a load test, a penetration test, or an infrastructure audit. This review does not include:
Load testing.
Penetration testing.
Infrastructure review.
Issues in these areas are reported when we happen to see them, but we do not claim exhaustive coverage of them.
How we handle access
We work under NDA — yours, or ours if you prefer.
Read-only repository and environment access is preferred; production write access is not required.
Evidence collected is kept to the minimum needed to support the report.
Access is revoked and working copies of your code are deleted at the agreed end of the engagement. We keep the report itself, and the notes behind its findings, for the period tax and accounting law requires — see the privacy policy.
This is not a certification
This review is not a SOC 2, PCI DSS, or legal compliance certification. It produces technical evidence and remediation priorities that your compliance process can use — it does not replace it.
Commercial terms, stated up front
Procurement asks these before granting repository access, so here they are without a call.
Who you contract with. A UK sole trader. If your procurement requires a limited company, we will incorporate before contracting — tell us early and it costs you nothing.
VAT. We are not VAT registered, so the fee is the fee. There is no VAT to add.
Insurance. We do not carry professional indemnity or public liability cover as standard. Where an engagement requires either, we arrange it before work starts and the engagement is covered under it. Raise it on the first call so it is in place before we need access.
Paperwork. A short master services agreement signed once, and a statement of work per engagement setting out scope, deliverable, price, and acceptance. We are happy to work under your paperwork instead.
After the review: remediation
If you want us to fix what we found, that is quoted separately — three to four calendar weeks, fixed price, £4k–£12k depending on scope. We only fix findings from our own review. No open-ended rebuilds, no scope creep.
Ready to see what a review would find in your system?