We audit whether your software does what you promised.
Security firms audit whether your software can be broken into. We audit whether it works: logic, regressions, fault tolerance, and the behavior your enterprise customers depend on. Every finding is validated by a named reviewer before it reaches you, ships with a reproducer you can run, and lands in your repository as evidence your own team can rerun after the engagement ends.
Engagement shape · external review
A fixed-fee baseline audit, scoped to one component before work starts, running about four weeks.
Continuous coverage as a monthly retainer, at a cadence set per client.
Approved requirements, one runnable reproducer per finding, the known-issue register, and an audit gate that runs in your CI.
Three steps, taken in order.
Every engagement starts with the baseline audit. It's fixed-fee, agreed before work starts, and scoped to one component you name. Continuous coverage comes after that, once there is a corpus worth defending. Fix work is a separate conversation and a separate scope.
Step 1 · Baseline audit · the mandatory on-ramp
Fixed fee, agreed before work starts. One component. About four weeks.
Approved requirements for the component, a findings report with severity and reachability, one runnable reproducer per finding, the known-issue register, and a re-runnable audit gate. Handed over as a live walkthrough, split into an exec summary and a developer appendix. When you have remediated, we re-verify every finding and re-issue the report with per-finding status at no extra fee.
Read access to the scoped path, about two hours of an architect's time to review and approve the requirements, and one engineer for finding review.
Fixes. Anything outside the agreed component. Pentest, SAST, SCA, fuzzing, and bug bounty, which this sits next to rather than replaces.
Step 2 · Continuous coverage · the flagship
Monthly retainer. Cadence set per client: every release, weekly, or faster.
Each cycle re-audits the component against the full requirement and known-issue corpus, so nothing already verified regresses without the gate saying so. Every fix you ship is verified by reproducer flip and becomes a permanent regression test in your CI. One new component is formalized and brought under audit each quarter. Monthly evidence report and walkthrough.
Continued read access, a triage owner on your side, and notice of release windows.
Fix work. The raw register as an outward-facing document: anything shared outside your company is a curated summary you control and route through your own counsel.
Step 3 · Fix work · separate scope
Scoped and quoted on its own. Never bundled into an audit fee, and never a condition of one.
We remediate findings from the register. Acceptance is mechanical and client-side: the reproducer flips from failing to passing, and your engineer signs it off.
The sign-off. Route any or every finding to your own team instead, at identical finding status and identical guarantees.
Any say in whether our own fix counts as accepted. Any defect one of our fixes introduces is covered at no charge.
How the fee is set
One component or code path. Not per finding, and not per seat.
Fixed for the agreed scope. Continuous coverage is a separate monthly retainer.
After a scoping conversation, in writing, before any access is granted.
An independent audit engagement, funded from the line that holds a QA vendor contract or an open engineering requisition rather than a tooling budget.
The baseline comes first in every case. Continuous coverage without an approved requirements corpus has nothing to check the next release against.
Quoted after scoping, never off a list.
We don't publish a rate card, and no engagement is priced off one. Each is a fixed fee, agreed once the component and the scope are written down.
That means the number arrives with what it buys attached: which path is in scope, which behaviors we're checking it against, what you get back, and what we've explicitly left out. A figure without those four things is a guess with a currency symbol on it.
How this gets funded.
No company has a budget line called correctness audit, so the first question finance asks is what this replaces. In practice it's one of three things: a QA vendor contract, an open SDET requisition, or incident cost nobody budgeted. Decide which one before the conversation, because the answer changes who signs.
An open SDET requisition takes months to fill and ramp, and then writes tests for the risks your team already knows about. An audit brings an outside method, a corpus that compounds every cycle, third-party standing your enterprise prospects can inspect, and a regression commitment no employee offers. Your engineers would find most of this themselves, given the time. This is what buying that time looks like.
Fill the worksheet in yourself
We won't pretend to know your numbers, and a CFO can tell when a vendor made them up.
# incident-cost.txt: your numbers, not ours Sev-1 incidents in the last 12 months ____ Engineer-days per incident (repro, fix, retest) ____ Loaded cost per engineer-day $____ Releases that slipped or bounced ____ Engineer-weeks lost to those slips ____ Customer credits or churn you can attribute $____ ------ Annual cost of the failure mode $____
If we find nothing: you still keep the floor deliverable. Approved requirements for the component, an executable gate running in your CI, and the known-issue register. A cycle that reports no new defects is the coverage doing its job, and the artifacts that show it are yours either way.
Five commitments we publish.
| Commitment | What we are on the hook for |
|---|---|
| Reproducer guarantee | Every finding ships with a runnable reproducer or it doesn't appear in the report. If a delivered finding fails its own reproducer on the scoped tree, we pull the finding. |
| Severity SLA | High-severity findings reach you within three business days of validation. They're never held back for the report cycle. |
| Regression guarantee | If a defect we verified as fixed recurs in production on an audited component, you get a fee credit on your next invoice and the incident deep-dive is on us. We state it as a fee credit rather than an indemnity because a credit is what we can honor today. |
| Bounded claims | Assurance within a declared scope, for declared behaviors, with evidence commensurate to the consequence of failure. We don't claim your system is free of defects, and that refusal goes in the contract. |
| Zero lock-in | The corpus is plain YAML plus tests in your repository, and the gate runs without us. Cancel and every artifact keeps working. What you lose is the ongoing review, not the asset. |
Severity is our own assessment, weighted by reachability and impact, and it is offered as a starting point for your triage. It is not a CVSS score and not a vendor determination.
Not an automated backlog. Not a claim of total correctness.
What this is not
Where it sits
A finding must be runnable or explicitly bounded.
What ships with every finding
Public methods, private tooling
The full method, and the limits we state for it, are on the methodology page. What we've published so far is in the findings ledger.
How access, disclosure, and your team's time actually work.
| Question | Answer |
|---|---|
| Do you need private repo access? | Not always. A review of public code can start from the public repository, its issues, docs, release notes, and tests. Private access matters for unreleased paths and for evidence specific to your customers. For private code we countersign your NDA first, and for sensitive code there is a mode where the gate runs inside your CI and nothing leaves your infrastructure. |
| How are findings delivered? | Private report first. Public issues, advisories, field notes, or pull requests happen only after your approval, and under coordinated disclosure where that applies. |
| Who owns reproducers? | You do. Reproducers, regression tests, and report artifacts are inspectable and handed over for your CI or your internal regression suite. |
| How much of your team's time? | Scoping, access approval, about two hours of an architect's time per component on the requirements review, finding review, and retest coordination. The point is to take triage load off your team, not to hand it another automated backlog. |
| Can a company sponsor a review of an open-source component? | Yes. The paying company funds the review while maintainer notification and publication stay coordinated and approval-based. |
The data flow, the named subprocessors, and the disclosure terms your security reviewer will ask for are on the trust page.
Read this before you fill in the form.
There's no price on this page, so the filter below and the three questions in the form do the qualifying. If the wrong column describes you, close the tab and keep your afternoon.
Write to us if this is you
Skip the call if this is you
Capacity: we take a limited number of engagements each quarter. We would rather tell you it isn't a fit than take work we cannot do properly.
Start with one component
Name the component, the trigger, and how access would work. With those three on the table, the first reply is scoping instead of qualification.
Don't send secrets or private source code through this form. What you submit is used for scoping and follow-up; see trust.
Every finding is validated by a named reviewer before it reaches you.
Tooling carries the breadth. Judgment carries the finding. Nothing reaches you that a person hasn't confirmed and can't defend on a call, and the report names who that was, the way any audit firm names the engineers who sign its reports.
Proof is the engine behind the breadth: the requirements model, the verification chain, MC/DC and formal property checks, and the gate that ends up in your repository. It's proprietary and it stays that way. Expert-signed, machine-verified.
Signature
Proof is built by ProbeLabs and led by Leonid Bugaev, author of GoReplay and jsonparser, who spent years running engineering at an enterprise API infrastructure company, which is where most of the failure modes on this page come from.
Related reading: the methodology, the instruments, the findings ledger, and the AI-native systems audit.