Go / No-Go
Seventeen categories, a one-word verdict on page one, and the first fixes arrive as pull requests — not as a list for somebody else to implement.
The problem it solves
You have a launch date somebody senior has already said out loud, and no independent read on whether the thing is actually ready.
Who buys it: CTO, VP Engineering or Head of Platform at a 20–2,000 person company.
What lands
- Findings across seventeen categories plus a synthesis pass — the taxonomy is published in full, so you can see the method before you buy.
- The verdict is one word, on the first page. Not a score out of a hundred, because percentages invite negotiation.
- Every finding carries a severity, a named failure mode, a file path, and what happens if you ignore it.
- Every finding is challenged by a second adversarial pass and either survives with evidence or is struck before it reaches you.
- A supply-chain module: lifecycle scripts, dependency provenance, token hygiene, and a written blast radius.
- A remediation plan sequenced against your launch date.
- Up to five P0 fixes opened as pull requests against your repository.
The scope ceiling
Up to 3 repositories, 400,000 lines combined, up to 12 deployed services. Above that, +£2,500 per additional 200k lines or 6 services — agreed before anything starts, never after.
What this is not
- Not a penetration test and not sold as one. No CREST, no OSCP, and pretending otherwise would be the first dishonest thing on this page.
- Not independent assurance. Independence is an accredited property under conformity-assessment standards and this is first-party tooling.
- No certification of any kind.
- No infrastructure rebuild, and no remediation beyond the five capped pull requests.
Who shouldn't buy it: Anyone who needs a certificate for a regulator. You need an accredited body, and I will tell you which one.
The guarantee
Every finding carries a file path and a named failure mode. Any finding you can disprove is struck from the report and refunded pro rata. If the verdict misses day ten, the second half of the fee is not payable. No promise about the number of findings — the count is whatever is true.
Why me
The auditor is mine, it runs against my own portfolio before anything ships, and the taxonomy is published so you can argue with the method rather than take it on faith.
Questions people actually ask
Why does the clock start at access granted rather than signature?
Because I have never met a change-advisory board that moves at the speed of a contract. Starting the clock at signature would be promising something your organisation controls, not something I do.
Why pull requests rather than a remediation report?
A report transfers the work to the team that was already too busy to find the problem. A pull request is reviewable, revertable, and either merges or does not.
Will you merge the fixes?
No — your reviewer, your CI and your branch protection decide that. I promise the pull request is opened. Anyone promising a merge has never sold into a company with a change-approval process.