Skip to content

Pricing

What this costs,
before you have to ask.

The fee does not change with what I find. An audit surfacing three findings costs what one surfacing forty costs, because you are paying for the reading.

Production Audit
01 · 5–7 business days

$1,500one-time

Read the code before real users do.

  • Architecture map of every route, service and trust boundary
  • Threat model covering auth, secrets, PII surface and abuse vectors
  • Risk register ranked by likelihood against blast radius
  • Prioritised fix list, each item scoped to a day, a week or a quarter
  • Cost model per user, with the caps to install before your first spike
  • A recorded 60-minute walkthrough with the person who wrote it

Not included

  • Implementation of the fixes
  • Penetration testing against running systems
  • Formal security certification
Audit + Fix Sprint
02 · Scoped per engagement

Quoted after the audit

The audit, then the fixes, by the person who found them.

Scoped against the findings and agreed in writing before any work starts. Implementation cost tracks the size of the problem, not a number picked in advance.

  • Everything in the Production Audit
  • Implementation of the agreed high-severity findings
  • Pull requests you review and merge, not a patch dumped on you
  • A short handover so your engineers can carry it forward

Not included

  • Open-ended feature work
  • Findings you choose not to prioritise

After the audit

Fractional CTO

from $4,000 per month

A continuing CTO seat for a founder who has already shipped through the audit. Architecture decisions go through a senior pair, and you stop being the only person who knows why the system is shaped the way it is.

Founders a quarter or two past the audit who are still shipping — adding payments, hiring a second engineer, opening an API, moving up-market.

By application, after an audit. The seat is small on purpose: two or three teams at a time.

Ask about the seat