What gets reviewed
Six things, in order: the repository, the architecture, security, technical debt, UX and product structure, and the AI implementation itself. Not a workshop series. Not a discovery phase. Your codebase in, a written verdict out.
Security gets disproportionate attention, because that is where AI-assisted builds fail hardest and most quietly. Row Level Security policies that exist but permit everything. Service keys that reached the client bundle. Authorisation enforced in the interface and nowhere else. Storage buckets left open. These are not hypothetical — they are the recurring findings across this class of application, and none of them are visible from the outside.
What you get
- A candid assessment of what should be retained, improved or rebuilt — stated plainly, not hedged into uselessness.
- A prioritised 60–90 day plan, ordered by risk and by what unblocks the next thing.
- A realistic development estimate for the work that plan implies.
- Risk-ranked findings with the evidence attached — each one demonstrated, never asserted.
- Delivery within 5 working days of the audit starting.
- One factual-correction round if something in the report is wrong.
What it costs
One fixed fee, agreed before anything starts. Not billed by the hour, and no meter running. The number is set at the fit check once the scope of your codebase is clear, and it does not move afterwards. 50% to book the slot, 50% on delivery of the report. VAT is charged at the prevailing UK rate; a business outside the UK is invoiced without it under the reverse charge.
Critical security findings are disclosed to you as soon as they are found, never held back until the report or the invoice is settled.
Who it is for
- Founders deciding whether to commit budget to a build, before the build starts.
- Boards and investors who need an independent technical read before backing a decision.
- Teams who suspect their architecture, AI adoption approach, or roadmap is wrong, and have no senior technical voice in the room to confirm it.
- Anyone who wants the specific risks named in writing, not talked around in a meeting.
Who it is NOT for
- Not implementation work — the audit produces a verdict, not a pull request.
- Not a substitute for legal, regulatory, or financial advice.
- Not an ongoing retainer or ongoing support — it's one decision, one report.
- Not for a system nobody can give access to, or a decision with no real material to review.
- Not a rubber stamp — if the honest verdict is "don't do this", that's what the report says.
How it works
- Send the decision. Email what you're deciding, and whatever you can share — architecture docs, a roadmap, repository access, a pitch deck.
- Review. The decision is assessed against what's actually there — code, documents, or a working session, depending on what the question needs.
- Verdict. A written report lands within 5 working days: the answer, the reasoning, and the risks — plus one round to fix anything factually wrong.