Launch-readiness source review

Your app works. Is it ready to launch?

A polished interface can hide unsafe trust, exposed data, runaway-cost paths and brittle deployment code. This focused review traces what a small AI-assisted web app actually does, then prioritises the fixes that matter most.

Evidence, not a scanner dump.
Every material finding includes the exact code reference, realistic impact, a practical correction and a way to verify the correction.
Founding price£149 + VAT if applicable
ScopeOne repo, up to 5,000 non-generated lines
SourcePublic GitHub repository at an exact commit

Working software can still make unsafe assumptions.

AI coding tools are excellent at getting a product onto the screen. The expensive failures tend to sit between screens: who may call an endpoint, which tenant owns a row, what reaches a browser bundle, what happens twice, and what an attacker can make the application pay for.

01 / TRUST

Authentication without authorisation

A user is signed in, but server routes or database rows still trust IDs supplied by the browser.

02 / DATA

Secrets and private data in the client

Keys, service credentials, verbose API responses or other users' records cross a boundary they should not.

03 / COST

Public paths to paid services

AI calls, storage, email, search or payment operations lack rate limits, ownership checks or replay protection.

04 / RELEASE

The wrong thing gets shipped

Debug artefacts, source maps, stale builds, duplicated code or permissive environment defaults reach production.

A decision you can act on.

The report is deliberately prioritised. It does not reward itself for finding fifty cosmetic warnings while burying the one route that can expose customer data.

  1. A launch recommendation: block, launch with conditions, or no material blocker found within scope.
  2. The highest-value findings: up to ten, ordered by realistic impact and reachability rather than alarming labels.
  3. Source evidence: reviewed commit, file paths and line references for every material claim.
  4. Practical remediation: the smallest sensible fix and a concrete check that proves it worked.
  5. Residual risk: unknowns the source review could not establish, stated plainly rather than guessed away.
  6. One written follow-up: clarification on the delivered report after your team has read it.
How the work is done: the review uses structured AI-assisted source analysis and appropriate static checks. Findings are rechecked against the cited source before delivery. Joel Bondoux is the named service provider and accountable contact; AI output is not presented as independent fact without repository evidence.

Small and specific on purpose.

This founding offer is meant for an MVP or compact SaaS application, not a disguised enterprise assessment. Fit and an exact delivery date are confirmed before an invoice is sent.

Included

  • One public GitHub repository at an agreed commit, plus one public deployment configuration where present.
  • Up to 5,000 non-generated lines of source.
  • Secrets/data flow, auth and authorisation, input/rendering, API abuse and cost, dependencies, artefacts, failure paths and material privacy-claim mismatches.
  • A source-level report; no access to production accounts is required.

Not included

  • Private repositories in the founding round.
  • Live penetration testing or exploit development.
  • A compliance certificate, legal opinion or promise that no vulnerability exists.
  • Production passwords, API keys, customer records, full remediation or open-ended feature work.

Four clear steps.

No sales call is required just to learn whether the scope fits.

01

Send the outline

App purpose, stack, approximate size and the public GitHub URL. Do not send credentials or private source.

02

Lock the scope

You receive the exact commit, exclusions, delivery date, written terms and price before payment.

03

Review the source

Contextual data-flow and business-logic review, supported by appropriate static checks.

04

Receive the decision

A prioritised evidence-backed report and one written clarification round.

Founding round · three genuine review slots

Independent scrutiny before real users arrive.

The founding price validates and tightens the format. It is not a countdown or an invented discount. If the public repository does not fit the scope or the review cannot add useful evidence, that is stated before invoicing.

£149 + VAT if applicable
Request a scope check
B2B enquiries only. No payment is taken on this page. Scope, terms and delivery date are agreed before invoice.

Useful questions.

The boundaries matter as much as the deliverable.

Is this a penetration test or security certification?

No. It is a bounded source-level launch-readiness review. It can identify serious security and privacy risks in code, but it does not test a live target, certify compliance or guarantee that no vulnerability exists.

Which applications are the best fit?

Small JavaScript or TypeScript web applications, particularly serverless or SaaS products built with AI coding tools and common managed services. Unfamiliar or oversized stacks are declined or re-scoped rather than reviewed superficially.

Why only public repositories?

That is a deliberate founding-round boundary. It keeps the source-processing arrangement plain and avoids asking a customer to entrust private code before confidential-repository handling, AI/tooling use and retention terms have been fully defined. Do not email private source or secrets.

Does AI take part in the review?

Yes. Structured AI-assisted analysis and static checks are used to inspect public source. The report identifies an exact commit and evidence for each material claim; raw model or scanner output is not treated as a finding merely because a tool produced it.

Will the findings become a case study?

Not without separate, explicit written permission. A public repository does not make private correspondence or the commissioned report public, and permission to review is not permission to market the findings.

Why only three reviews at this price?

It is the first paid round. Three is the actual capacity reserved for validating the scope and report format. The offer is reassessed after those reviews rather than presenting artificial scarcity.

Joel Bondoux is an independent technical director and engineer working across web products, AI-assisted development and developer tooling. See the open-source work or ask a scope question by email.

Back to top