Services

Four engagements.
Scoped before they start.

Some teams need someone to examine what they already run. Some need help setting a new project up so it does not need examining later. Some need both, for a while. Pick the one that sounds like you, or just get in touch and we will work it out on a call.


One to three weeks, fixed scope

Architecture and security review

We read everything, then tell you what actually matters.

We go through your codebase, your infrastructure, and your access model against the six areas in the register. You get a findings register: every issue written in plain language, ranked by what would genuinely hurt you, with a specific fix attached to each one. No 90 page PDF you will never read.

What you get

  • Findings register covering all six review areas
  • Every finding ranked by real impact, not by scanner severity
  • A specific, costed fix for each finding
  • A walkthrough call to go through the register together
  • Answers you can paste into a customer security questionnaire

Best for: Teams who have been asked a hard question by a customer, an investor, or an auditor, and want a straight answer before they respond.

A few days, start to finish

Foundations

Set the project up so the review is boring later.

For teams starting something new. We make the decisions that are expensive to reverse: how auth works, how the data model is shaped, how environments and secrets are separated, how code reaches production. You end with a running application and a written record of why each decision went the way it did.

What you get

  • Working scaffold with auth, data model, and deployment wired up
  • Environment and secret separation done properly from day one
  • Access rules written as policy, not scattered through the code
  • A written record of every architecture decision and its reasoning
  • Your AI development tooling configured to follow those same rules

Best for: Founders and teams at the start of a build who would rather not rewrite the foundation in eighteen months.

Monthly, scaled to what you need

Build partnership

We build alongside you, with the review discipline built in.

We work as part of your team and ship real features. The difference is that access control, data handling, and change management are considered while the code is being written rather than discovered afterward. We use AI-assisted development heavily, which is how the work moves quickly, but every decision still gets a human review before it lands.

What you get

  • Feature work delivered against your roadmap
  • Review of every change before it reaches production
  • Architecture decisions made with you, not handed down
  • Your team learns the patterns as we go
  • Scale up, scale down, or pause between phases

Best for: Small teams who need senior engineering capacity without adding a full time hire.

Monthly retainer

Ongoing advisory

A standing technical partner who already knows your system.

A regular call, code review on request, and someone to think through the hard decisions with. When a customer sends a security questionnaire or a framework asks for evidence, you are not starting from a blank page. We already know how your system is put together.

What you get

  • A recurring call at whatever cadence suits you
  • Code and pull request review on request
  • Help answering security questionnaires and audit requests
  • Architecture and vendor decisions talked through before you commit
  • Async access between calls

Best for: Teams with an engineer or two who want senior backup on the decisions that are hard to undo.

Questions

How is this priced?
Every engagement gets a written scope with a fixed number in it before any work begins. Reviews and foundations are quoted as a whole. Build partnerships and advisory run monthly. You will never get a surprise invoice, and you will never be billed for the first call.
What stacks do you work with?
Most of our work is TypeScript on the web: Next.js, Node, Postgres, and the usual hosting and auth providers around them. We are comfortable reviewing almost anything, because the six areas in the register are not language specific. If your stack is genuinely outside what we know well, we will say so on the first call.
We are a very small team. Is that a problem?
No. Small teams are most of the work. A two person team that gets access control and change management right early is in far better shape than a twenty person team retrofitting it under audit pressure.
Do you actually write code, or just advise?
Both, depending on the engagement. Foundations and build partnerships are hands on and we ship real code. Reviews and advisory are analysis and guidance, and the code stays yours to write. We will be clear about which one you are buying.
What do I get at the end of a review?
A findings register: each issue in plain language, ranked by what would genuinely hurt you, with a specific fix attached. Plus a call to walk through it together. It is written so you can hand it to an engineer and they can act on it without translation.
Can you help with a security questionnaire or a SOC 2 push?
Yes, and it is a common reason people get in touch. We cannot issue an attestation, that is an auditor’s job. What we can do is get your systems and your evidence into a state where the audit is a formality rather than a scramble.
How does AI fit into the work?
We use AI-assisted development heavily and we are open about it, because it is how the work moves quickly now. It does not change who is responsible for what ships. Every change still gets a human review before it lands, and we will configure your own AI tooling to follow the same rules if you want that.

Not sure which one you need?

That is normal, and it is what the first call is for. Thirty minutes, no charge, no pitch. If you would rather poke at something first, the free starter kit is a decent place to start.