FAQ
Questions worth
asking first.
If yours is not here, email me. Answers arrive within two business days, including the answer that this is not the right purchase for you.
- What exactly do I get?
A written report and a recorded sixty-minute call. The report contains an architecture map, a threat model, a ranked risk register, a prioritised fix list and a cost model. The call is where you argue with me about it.
The report is written to be handed to an engineer and acted on. It is not a slide deck and it is not a summary of what a static analyser said.
There is a complete one published at /sample-report — eleven findings on an AI-generated codebase, ranked by consequence. Read it before you decide.
- How long does it take?
Five to seven business days from the point I have repository access. You get a reply to your first email within two business days, either way.
- Why is it a fixed price?
Because hourly billing gives me a reason to take longer, and you a reason to hesitate before asking a question. Neither helps.
The fee does not change with what I find. An audit that surfaces three findings costs what one surfacing forty costs. You are paying for the reading, not the volume of bad news.
- What access do you need?
Read-only access to the repository. That is the whole list.
Not production credentials, not admin accounts, not your customer database. If I ever ask for more than read-only, push back — you would be right to.
- Will you sign an NDA?
Yes, and I will sign yours rather than insisting on mine. There is no negotiation stage.
The confidentiality obligation applies whether or not one is signed. Your code is never used to train a model and is never shown to another client.
- Why not just point an AI code reviewer at it?
Use one. They are good at what they do, and I use them too.
What they do not do is decide what matters. An AI reviewer will report a missing null check and a missing auth boundary with roughly equal urgency, because it has no idea that one is a style note and the other is your entire customer table. Ranking findings by real-world consequence at your particular stage is the judgment you are buying.
- What if you do not find anything?
You get a short report saying so, and I will tell you plainly that you did not need this. That has not happened yet on an AI-generated codebase, but it is a real possible outcome and the fee does not change.
If I can tell from the first conversation that an audit is the wrong purchase for you, I will say that on the call rather than after the invoice.
- My codebase is large. Does that change things?
Possibly. The listed price assumes something in the shape of an MVP built over weeks or months. A substantially larger or more complex system gets quoted before you commit, never after.
- Which stacks do you cover?
TypeScript, React, Next.js, Node, Python, Postgres, Prisma, Supabase, Firebase, AWS, Vercel — the stack most AI codegen tools reach for by default.
If you are on something outside that, say so in your first email. I would rather decline than review a system I cannot read properly.
- What if I disagree with a finding?
Good. That is what the call is for, and it is why the call is live rather than a recording sent over.
You know things about your business that do not appear in the code. A risk I rank high may be one you have consciously accepted. Tell me and I will note it as accepted rather than open — that is a legitimate engineering decision, not a failure to comply.
- Can I show this to an investor or an enterprise customer?
You can show them the report, and founders do. What you cannot do is present it as a certification, because it is not one.
It is not SOC 2, ISO 27001 or a penetration test. It is a senior engineer’s written assessment. That is worth something in a diligence conversation, but it is not a badge.
- What happens after the audit?
Usually nothing, and that is a fine outcome. The report stands on its own and most founders take it to their own engineers.
If you want the top findings closed by the person who found them, the Fix Sprint covers that. The ongoing CTO seat exists but is not sold here — it comes up after we have shipped work together, or it does not come up.
- Who is actually doing the work?
Me. There is no team, no junior, no offshore reviewer. That is the constraint that keeps the seat count low and it is deliberate.
The full method is written up on the methodology page, and the handling of your source code is spelled out in the privacy policy.