A person reads it. Software watches it.
The review is the product, and a human does all of it. The monitoring is software, it is honest about being software, and it cannot issue a seal.
Done by a person
Reviewsmall to medium project
$250one-off
- A senior developer reads your code
- Account takeover and auth logic
- The pull request that fixes it
- Findings you can act on
- Security Reviewed seal
Done by a person
Reviewlarge project
$1000one-off
- A senior developer reads your code
- Account takeover and auth logic
- The pull request that fixes it
- Findings you can act on
- Security Reviewed seal
- More routes, more roles, payments or regulated data
Done by software
Watchautomated monitoring
$29/mo
- Drift and staleness alerts
- Continuous checks on every push
- AI-readiness report
- Supply chain verification
Which review do I need?
$250 covers a small to medium project. All of these have to be true:
- One repository and one deployed app
- 25 routes or API endpoints, or fewer
- 2 user roles at most, for example a user and an admin
- No payment processing, no health records, no financial account data
Anything past that is the $1000 tier. More services, more roles, money or regulated records: more surface, and a higher cost of getting it wrong.
We check this against your repository before starting. If you picked the wrong one we tell you which it is and what it costs before any work begins. We do not start work and invoice you the difference afterwards.
A seal names the commit it covers and expires after 90 days. Only another human review renews it. No subscription and no automated check can issue or extend one.
