No "book a call to hear the price."
Publishing prices is deliberate — most boutique auditors hide them behind a call. Pricing scales with your codebase size, so a weekend project and an enterprise monorepo never pay the same.
- Source-only, no credentials
- Static findings + a ten-module coverage ledger
- Same-day, yours to keep
- All ten modules, reviewed with real verdicts
- Live database: RLS, Supabase advisors
- PII protection verified in production
- Read-only access — nothing stood up
- Everything in the Connected audit
- We stand up your stack and attack it live
- Cross-tenant access & auth flaws proven
- Mutation-tested tests + investor-ready summary
| Codebase size · measured automatically | Free scan | Connected | Full audit |
|---|---|---|---|
| Small · under 10k lines | $0 | $500 | $1,000 |
| Medium · 10k–50k lines | $0 | $1,500 | $3,000 |
| Large · 50k–150k lines | $0 | $3,500 | $7,000 |
| Enterprise · 150k+ / monorepo / regulated | $0 | Custom | Custom |
We measure your codebase size during the free scan and quote from it — generated and vendored code doesn't count. Launch pricing; for context, source-only "vibe-code" audits run $1,500–$5,000 and a traditional pentest $4,000–$12,000 regardless of app size.
Findings to tickets. We file every finding as an issue in your tracker — GitHub, Jira, Linear, GitLab, or Azure DevOps — deduped against your last audit, so your team fixes from their own board.
Investor-ready summary. A buyer-facing document for fundraise or acquisition diligence — non-technical to read, defensible under technical scrutiny. Available on the Full tier.
Re-audit credit. When you ship the fixes, we re-verify the critical findings once at no extra charge, if requested within 30 days of the original audit. Additional re-audits within that window are a paid add-on at 50% of the original audit price. The repeat-customer diff automates it, so it's cheap for us and high-trust for you.
Machine-readable exports. Ask and your findings also ship as SARIF — the format GitHub code scanning and security tooling ingest — plus a CycloneDX software bill of materials of your dependencies, the artifact enterprise buyers ask for. The coverage ledger travels inside the SARIF, so a module that didn't run can't disappear into "no results."
What each tier can and can't tell you.
The escalation is by access: Free reads your source, Connected adds your live database, Full stands up and attacks a running copy. Each rung is a clean superset of the one before.
| What you actually get | Free scan$0 | Connectedfrom $500 | Full auditfrom $1,000 |
|---|---|---|---|
| Reads your source | |||
| Findings from every module source alone can run | ● | ● | ● |
| Coverage ledger: all ten modules, status and reason | ● | ● | ● |
| False positives triaged out | — | ● | ● |
| Fixes named, not just flagged | — | ● | ● |
| Reads your production database | |||
| Live database + Supabase advisors | — | ● | ● |
| PII protection verified in production | — | ● | ● |
| Stands up & attacks your app | |||
| Cross-tenant access proven on a live stack | — | — | ● |
| Points out tests that pass even when the code is broken | — | — | ● |
| Auth, endpoint & service-seam attacks | — | — | ● |
Straight answers.
How is my codebase size measured?
Automatically, during the free scan — lines of application code, with generated and vendored code excluded (our dead-code and duplication modules already detect it). The free scan doubles as an instant, transparent quote for the paid tiers.
What if I decline database access on a paid tier?
The database-dependent checks record "not run — no access" in the coverage ledger, on-brand, and the rest of the audit still runs. You're never charged for a check we couldn't perform.
Is the small-tier Full audit a real pentest?
It's a genuine audit of a small app, and the Full tier does run a live pen-test on a copy of your stack. We keep the language honest: a small MVP is scoped-small, so it sits alongside the $1,500–$5,000 source-review audits rather than a formal enterprise pentest — the difference being that those are source-only, and this one actually runs. If you need a compliance letter, we'll point you to a pentest firm for that specifically.
Are these prices final?
These are launch anchors. Exact price points are being validated against real engagements; the grid is the honest starting point, not a placeholder for a bigger number revealed on a call.
The free scan is also your quote.
Source-only, no credentials — and it measures your size to quote the paid tiers.