mAIb TechmAIb MVP Release Audit

Frequently asked questions

Direct answers, including to the questions that are awkward for us.

What types of application do you review?
Web applications built primarily in JavaScript, TypeScript or Python, in one repository, with one deployment target. Mixed AI-generated and hand-written code is entirely normal and expected. If your project spans several repositories or a different stack, ask before purchasing and we will tell you honestly whether we are the right fit.
Can you review a private repository?
Yes, and that is the usual case. The preferred route is a read-only invitation to our dedicated audit identity, which you revoke when the audit is finished. Alternatives are a time-limited encrypted archive upload or a temporary read-only credential you control. We never ask for your normal account password.
Will you run my code?
Only if you explicitly permit it, and never on our own machines. Execution happens inside a disposable container with no network access by default, dropped privileges, resource and time limits, and a read-only copy of your source. The container is destroyed afterwards. Declining execution is a supported choice — the audit stays static, and the report says so rather than implying checks ran that did not.
Does my code go to an AI provider?
That is entirely your choice, made explicitly at intake. Mode 1 means no external AI provider processes your source at all. Mode 2 permits redacted snippets only. Mode 3 permits repository-level assistance. Under modes 2 and 3, your code genuinely is transmitted to the provider we name — we will not claim otherwise. See confidentiality for the detail.
Is this a penetration test?
No. This is a release-readiness review: static analysis, safe automated checks, and human judgement about what blocks launch. It is not a penetration test, not a compliance or accessibility certification, and not a legal opinion. If you need a formal penetration test, you need a specialist testing firm, and we will say so rather than sell you this instead.
What happens if my project is out of scope?
We tell you before starting. Either we propose a re-scope with an adjusted price, or we decline and refund. We would rather return your money than deliver a thin report on a project we cannot assess properly.
When does the delivery clock start?
At acceptance, never at payment. Five things must be true first: payment is confirmed, we have accepted the project, your access works, your consents are complete, and the project is within scope. A clock that starts before we can read your code would be measuring nothing.
What do you retain?
Your repository copy, extracted workspace and temporary evidence are deleted at the end of the retention period — 30 days after delivery by default, or sooner if you ask — and a deletion record is produced. We keep the job record, your consent records, the findings register and the report itself as the service and commercial record.
Can you fix the problems?
Yes — through a separately scoped MVP Rescue Sprint, from £1,250, quoted after the audit because the price depends on what we find. Plenty of customers simply fix things themselves using the prioritised plan, and that is a perfectly good outcome. The report is written to be actionable by your own developer, not to make you dependent on us.
Can you guarantee that the application is secure?
No. No audit can, and any service that says otherwise is selling you a feeling rather than a finding. What we provide is a point-in-time review of the materials you supplied, with the evidence behind every conclusion and an explicit record of what was not checked. That is a genuinely useful thing. A guarantee would not be.
What if my application handles health, financial, government or children's data?
Tell us at intake — there is a specific question for it. Regulated and high-risk domains carry obligations that a release-readiness audit does not discharge, and some sit outside our competence boundary entirely. In those cases we decline and refund rather than give you assurance you should not rely on.