packages

Fixed prices. No surprises.

Start with a free scan to see what's exposed. When you're ready for a human to dig in and close the holes, the price is fixed and known up front.

Launch pricing while Harbova is new. We're pricing low to earn our first public reviews on Upwork, where your payment sits in escrow. Book before Sep 1 and you lock the lower rate. No countdown that resets. Prices rise on September 1, 2026, and stay there.

Vibe Check

Free

See what your app leaks to the outside world in about 60 seconds. No card, no call.

Instant · Anyone who just shipped and wants a fast, honest read before deciding anything.

  • Instant scan of your public surface: security headers, HTTPS, and exposed front-end keys
  • Flags a database that looks open to the world
  • A plain-English report emailed to you, no jargon
  • An honest result, including "nothing obvious on the surface" when that's true
  • No account, no credit card
Run a free scan
Start here

Verified Scan

$199

A human checks every finding on your live app, throws out the noise, and walks you through what is left.

This is the outside view, confirmed by a person. It does not read your code, so it cannot see inside your database. Your fee comes off a Deep Audit if you upgrade within 30 days.

48 hours · Anyone holding a scan result who wants to know which parts are actually real before spending more.

  • We run the scan on your live app, so you are never reading a report about the wrong URL
  • Every finding checked by hand against your app, with the false positives removed and named
  • The real ones ranked by what could actually bite you, in plain English
  • A ready-to-paste fix prompt for each one, written for Claude Code, Cursor, or whatever you build with
  • A 20-minute walkthrough so you know what matters and what does not
  • An honest all-clear when that is the answer, and we will say so rather than invent work
  • Your fee credited toward a Deep Audit if you upgrade within 30 days
Get a Verified Scan
Reads your code

Deep Audit

$850$650Launch price · goes to $850 on Sep 1

The full picture: every hole found, ranked, and explained, with exactly what to change.

The first tier that sees inside: your database rules, your auth, your logic. A scan only ever sees the outside. You (or your developer) apply the fixes and re-test on your own time, and whatever you pay here comes off Audit + Fix if you upgrade within 30 days.

3-5 days · Founders and devs who want to know exactly what's wrong and would rather patch it themselves.

  • A human reads your actual code: auth, access control, database rules, business logic, and APIs
  • A prioritized report in plain English, ranked by what to fix first
  • Clear fix instructions for each finding, ready for you or your developer to apply
  • False-positive filtering, so you only read real problems, not scanner noise
  • A 30-minute walkthrough call so you're not guessing
  • Your fee credited toward Audit + Fix if you upgrade within 30 days
Book a Deep Audit

Booked through Upwork: payment protected, released only when you're happy.

Recommended

Audit + Fix

$2500from$1900Launch price · goes to from $2500 on Sep 1

We find it, we fix it in your code, and we prove it's closed. You touch nothing.

A formal security engagement starts around $5,000, and you still chase them to confirm the fixes landed. This gets your app hardened and proven closed for less. We'll never call it a certified penetration test, because it isn't one.

1-2 weeks · Revenue-stage founders and agencies with real users who want it handled, proven, and off their plate.

  • Everything in Deep Audit, the full human-verified code review
  • We implement every fix directly in your codebase, so nothing gets pasted wrong or breaks a feature
  • A re-test pass that proves each issue is actually closed, not just described
  • Locked-down database rules, secrets, and auth
  • A before/after report you can hand a client or an investor
  • A 30-day in-scope fix warranty: if something we closed reopens, we fix it free
  • Your first 30 days of Continuous Shield included
Get Audit + Fix

Booked through Upwork: payment protected, released only when you're happy.

Keeps it closed

Continuous Shield

$399$299/moLaunch price · goes to $399/mo on Sep 1

Every time AI writes new code, we check it before a hole can sneak back in.

About $10 a day to keep an app with real users from silently regressing. Your founding rate is locked for as long as you stay.

Ongoing · Anyone who keeps shipping AI-generated features and wants to stay closed, not just closed once.

  • Monthly automated scan plus human review
  • A security check on every AI-generated change before it ships
  • Priority fixes when something turns up
  • A living security scorecard for your app
  • A direct line to us, no ticket queue
  • Founding rate locked for as long as you stay
Talk about Shield

What you actually get

Every line, itemized, so you can see you're getting more than you're paying for. The worth figures track real agency line-item pricing, kept conservative on purpose.

Vibe Check

  • Instant public-surface scan: headers, HTTPS, exposed front-end keys$99
  • A flag if your database looks open to the world$99
  • A plain-English report emailed to you$50
  • An honest result, even when it's "nothing obvious here"the reason you can trust the rest
Adds up to about $250Free

Verified Scan

Start here
  • The scan run for you on the right app, not a link you have to aim yourself$99
  • Every finding verified by hand, with the false positives named and dropped$400
  • The real findings ranked by what could actually bite you$150
  • A ready-to-paste fix prompt for each finding$200
  • A 20-minute walkthrough call$150
  • Your fee credited toward a Deep Audit within 30 daysthe full fee back
Adds up to about $1,000
$199

Deep Audit

Reads your code
  • The Vibe Check surface scan, so we start from the outside view$99
  • A human reads your actual code: auth, access control, database rules, business logic, APIs$900
  • False-positive filtering, so you only read real problems$300
  • A prioritized, plain-English report ranked by what to fix first$300
  • Clear fix instructions for each finding, ready to apply$500
  • A 30-minute walkthrough call so you're not guessing$150
  • Your fee credited toward Audit + Fix if you upgrade within 30 daysthe full fee back
Adds up to about $2,250
$850$650

Audit + Fix

Recommended
  • Everything in Deep Audit, the full human-verified code review$1,500
  • A prioritized findings report ranked by how badly each one could bite$300
  • We implement every fix directly in your codebase, you touch nothing$1,800
  • A re-test pass that proves each issue is actually closed$600
  • Locked-down database rules, secrets, and auth$700
  • A before/after report you can hand a client or an investor$400
  • A 30-minute walkthrough call so you understand what changed and why$250
  • A 30-day in-scope fix warranty on everything we closed$500
  • Your first 30 days of Continuous Shield included$299
Adds up to more than $6,300
$2500from$1900

Continuous Shield

Keeps it closed
  • Monthly automated scan plus human review$200/mo
  • A security check on every AI-generated change before it ships$250/mo
  • Priority fixes when something turns up$150/mo
  • A living security scorecard for your app$100/mo
  • A direct line to us, no ticket queue$100/mo
Adds up to about $800/mo
$399$299/mo

Deep Audit tells you exactly what's wrong. Audit + Fix does the work and proves it's closed. Start with a Deep Audit and the fee comes off Audit + Fix if you upgrade within 30 days. Deep Audit and Audit + Fix are booked through Upwork, so your payment stays in escrow until the work is done and you can read every review we've earned. The Verified Scan and Continuous Shield start with a message, because neither needs escrow to get going.

Questions people actually ask

Why are the prices lower right now?

We're new, and we're pricing low to earn our first public reviews on Upwork, where your payment sits in escrow. These are real founding prices: they go up on September 1, 2026, and stay there. Book before then and you lock the lower rate.

Deep Audit already gives me the fixes. Why pay for Audit + Fix?

Because they're two different jobs. Deep Audit hands you the full diagnosis and clear instructions, then you apply and re-test it yourself and hope you got it right. Audit + Fix is us doing the work in your codebase, proving each hole is actually closed with a re-test, and handing you a before/after report, backed by a 30-day fix warranty. And if you start with a Deep Audit, that fee comes off Audit + Fix if you upgrade within 30 days.

Do you need access to my code?

For the free scan, no, just your live URL. For a Deep Audit or a fix, yes: we look at the actual source, always under a signed agreement, and only after you authorize it in writing.

Is this a certified penetration test?

No, and we won't pretend otherwise. This is a security audit and hardening service tuned for AI-built apps. It catches the issues that actually sink these apps, without the enterprise price tag of a formal pentest.

My app is on Lovable or Bolt, don't they already scan it?

Partly. Their built-in scanners only check their own platform and only whether a rule exists, not whether it works. We verify it for real, cover the parts they ignore, and fix what we find.

I'm pre-revenue. Should I bother?

The free scan is always worth it. Paid audits make the most sense once you have real users or a client depending on the app, because that's when a leak actually costs you something.

Still not sure? Start free.

The scan costs nothing and tells you exactly where you stand. Everything else is your call.