Fixed-fee audit

You built it with AI. Now find out what you actually have.

Claude Code, Lovable, Cursor — you shipped something real, faster than a team would have. What you don't have is an honest read on what's underneath it: what's sound, what's a security hole, and what has to be rebuilt before it carries real users. Appaya reviews it and tells you plainly.

Fixed fee

quoted at a fit check · written verdict · delivered in 5 working days

What gets reviewed

Six things, in order: the repository, the architecture, security, technical debt, UX and product structure, and the AI implementation itself. Not a workshop series. Not a discovery phase. Your codebase in, a written verdict out.

Security gets disproportionate attention, because that is where AI-assisted builds fail hardest and most quietly. Row Level Security policies that exist but permit everything. Service keys that reached the client bundle. Authorisation enforced in the interface and nowhere else. Storage buckets left open. These are not hypothetical — they are the recurring findings across this class of application, and none of them are visible from the outside.

What you get

What it costs

One fixed fee, agreed before anything starts. Not billed by the hour, and no meter running. The number is set at the fit check once the scope of your codebase is clear, and it does not move afterwards. 50% to book the slot, 50% on delivery of the report. VAT is charged at the prevailing UK rate; a business outside the UK is invoiced without it under the reverse charge.

Critical security findings are disclosed to you as soon as they are found, never held back until the report or the invoice is settled.

Who it is for

Who it is NOT for

How it works

  1. Send the decision. Email what you're deciding, and whatever you can share — architecture docs, a roadmap, repository access, a pitch deck.
  2. Review. The decision is assessed against what's actually there — code, documents, or a working session, depending on what the question needs.
  3. Verdict. A written report lands within 5 working days: the answer, the reasoning, and the risks — plus one round to fix anything factually wrong.

FAQ

Common questions

What counts as a decision you can audit?

Anything specific enough to state in a sentence: whether to build in-house or buy, whether an architecture will hold up, whether an AI adoption plan is sound, whether a roadmap is realistic. If it can't be stated as a decision, it isn't ready for this yet.

Do you need production access?

Only if the question requires it. Most audits work from documents, a repository, and a working session; any access granted is scoped to what's needed and revoked when the audit ends.

Can I get a call instead of a written report?

The deliverable is the written verdict — a document holds up in a board pack or an investor update in a way a call doesn't. A short call to walk through the findings is included.

What if the verdict is "not enough information to be sure"?

Then that's what the report says, along with exactly what's missing. The audit doesn't manufacture confidence it doesn't have.

What happens after I get the report?

Nothing automatic. If the findings point to a build, a fractional engagement, or nothing at all, that's a separate conversation you start when you're ready — not an upsell built into this report.

Have a decision that needs a straight answer

Email what you're deciding, and what you can share about it, to the address below. You'll hear back on fit before anything is invoiced.