Skip to content

Connect your repository — then indicators turn into statements

Security changes less than you would expect — the decisive rules live in your database, not in your code. We only see those in the scoping.

What we do and what we don't

  • GitHub App, read-only, only the repositories you select during installation.
  • Revocable at any time — in your GitHub settings, without asking us.
  • We clone nothing. We fetch individual files through the GitHub API and hold them in memory only.
  • We store the findings and the reference state: repository name, branch, commit.
  • The access token is not stored. It is fetched from GitHub per run and expires by itself.
  • No personal access token, no broad OAuth scope.

Limits

One repository, one branch. We read at most 120 files, each up to 256 KB and 4 MB in total — that covers configuration, migrations, routes and auth paths, not your whole project. Larger or multi-part projects we agree individually.

Does this repository hold personal data (test data, seed data, real addresses in code)?

We record your answer with the request and agree retention with you before the run. “Not sure” is treated like “Yes”.

Read-only via GitHub. We then actively check Row Level Security, interfaces and dependencies — revocable at any time.

Your Rescue offer

Don't just learn what is wrong. Get a concrete offer to fix it.

Based on your scan — and optionally a read-only access to your repository — we prepare a fixed-price offer tailored to rescuing your build. Non-binding and without an hourly rate.

Three ways forward — pick the one that fits

Not every app needs a project right away. Sometimes a solid document is enough, sometimes the full analysis. All three start from the result you just saw.

Rescue scoping

€950

net · fully credited

Phase 0 of your rescue. The scan shows something is wrong. The scoping shows what exactly, how bad, and in which order it gets touched.

  • Read-only access to your repository — we see what the scan cannot see from outside
  • Every finding assessed, weighted and put into a defensible order
  • An action list to work from, not a non-binding recommendation
  • Human technical review — a person checks and owns the result
  • Delivered in 5 working days from confirmed access; access ends on delivery

Immediate mitigation

calculated from the findings

net, one-off · delivered in days

Only when there is a critical finding. Your system is live and has an open hole — we close that first, whether you later repair or rebuild.

  • Rotate access keys and remove them from shipped code
  • Close row-level security rules
  • Secure exposed endpoints
  • If needed: temporarily disable the affected feature, with a documented way back
  • The price follows the same calculation as our public cost calculator — checkable, not guessed

Another project

free

no commitment

No scan result but a project in mind? Skip the intermediate steps and write to us directly.

  • Reply within one working day
  • Fixed price instead of an hourly rate
  • Optional read-only access to your code on request
  • Reply within one working day
  • Optional read-only repo access for more depth
  • Fixed price instead of an hourly rate
  • Paid tiers by invoice — no automatic payment

Send request

We get back to you within 24 hours, arrange read-only access to your repository and start the scoping. Billed by invoice at €950 net — fully credited if you commission the work within 30 days, towards rescue loops or a rebuild alike. You are not paying for an opinion, you are paying for the first work step.

What would you like?

Submitting does not pay anything. Paid tiers are billed by invoice after we have got back to you.