Frequently asked questions
Direct answers, including to the questions that are awkward for us.
- What types of application do you review?
- Web applications built primarily in JavaScript, TypeScript or Python, in one repository, with one deployment target. Mixed AI-generated and hand-written code is entirely normal and expected. If your project spans several repositories or a different stack, ask before purchasing and we will tell you honestly whether we are the right fit.
- Can you review a private repository?
- Yes, and that is the usual case. The preferred route is a read-only invitation to our dedicated audit identity, which you revoke when the audit is finished. Alternatives are a time-limited encrypted archive upload or a temporary read-only credential you control. We never ask for your normal account password.
- Will you run my code?
- Only if you explicitly permit it, and never on our own machines. Execution happens inside a disposable container with no network access by default, dropped privileges, resource and time limits, and a read-only copy of your source. The container is destroyed afterwards. Declining execution is a supported choice — the audit stays static, and the report says so rather than implying checks ran that did not.
- Does my code go to an AI provider?
- That is entirely your choice, made explicitly at intake. Mode 1 means no external AI provider processes your source at all. Mode 2 permits redacted snippets only. Mode 3 permits repository-level assistance. Under modes 2 and 3, your code genuinely is transmitted to the provider we name — we will not claim otherwise. See confidentiality for the detail.
- Is this a penetration test?
- No. This is a release-readiness review: static analysis, safe automated checks, and human judgement about what blocks launch. It is not a penetration test, not a compliance or accessibility certification, and not a legal opinion. If you need a formal penetration test, you need a specialist testing firm, and we will say so rather than sell you this instead.
- What happens if my project is out of scope?
- We tell you before starting. Either we propose a re-scope with an adjusted price, or we decline and refund. We would rather return your money than deliver a thin report on a project we cannot assess properly.
- When does the delivery clock start?
- At acceptance, never at payment. Five things must be true first: payment is confirmed, we have accepted the project, your access works, your consents are complete, and the project is within scope. A clock that starts before we can read your code would be measuring nothing.
- What do you retain?
- Your repository copy, extracted workspace and temporary evidence are deleted at the end of the retention period — 30 days after delivery by default, or sooner if you ask — and a deletion record is produced. We keep the job record, your consent records, the findings register and the report itself as the service and commercial record.
- Can you fix the problems?
- Yes — through a separately scoped MVP Rescue Sprint, from £1,250, quoted after the audit because the price depends on what we find. Plenty of customers simply fix things themselves using the prioritised plan, and that is a perfectly good outcome. The report is written to be actionable by your own developer, not to make you dependent on us.
- Can you guarantee that the application is secure?
- No. No audit can, and any service that says otherwise is selling you a feeling rather than a finding. What we provide is a point-in-time review of the materials you supplied, with the evidence behind every conclusion and an explicit record of what was not checked. That is a genuinely useful thing. A guarantee would not be.
- What if my application handles health, financial, government or children's data?
- Tell us at intake — there is a specific question for it. Regulated and high-risk domains carry obligations that a release-readiness audit does not discharge, and some sit outside our competence boundary entirely. In those cases we decline and refund rather than give you assurance you should not rely on.