01 The 48-hour audit
Pay. Send the repo. Know where you stand in 48 hours.
No call, no scoping meeting, no "let's chat". Just a written, severity-ranked report on the five things that break vibe-coded apps, with a fixed quote to fix what's dangerous. Takes us longer than 5 days? You pay nothing.
You get a personal confirmation the same working day; the 48-hour clock starts once payment and repo access are both confirmed, not while you sleep. No report within 5 calendar days: every cent back.
Card works inside the PayPal checkout, no PayPal account needed. Bigger than one app and one repo, want an invoice, or need a guaranteed-48h rush? Write to us before you pay.
This is an expert code review against the five failure modes, not a penetration test. Details in the FAQ and the full audit terms.
Key exposed right now? Revoke or rotate it first; that alone stops most damage. Then say so here: we reply within 4 hours on working days (IST) and start with containment, not the checklist.
Not ready to pay? Free exposure check first.
Send your deployed URL. We run the external checks only (exposed endpoints, headers, obvious leaks visible from outside) and reply within 24 hours with what a stranger can already see. No repo access needed.
Got it. Check your inbox within 24 hours (working days). No follow-up sequence, no sales calls. One useful email.
Free · external checks only · answered by the founder who runs the audits
02 How it works
Three steps, one clock.
Pay the fixed €299
Checkout via PayPal. Card works too, no account needed. Credited in full if you hire us for the fix.
€299Send us access
Reply to the receipt or use the contact form: repo URL, the deployed URL, and one line on what worries you. Send a read-only invite to our GitHub org account (github.com/EtherLabZ; the confirmation email names the exact account to invite). We confirm receipt, and that confirmation starts the 48-hour clock. Everything you share stays private.
~10 minReport in 48 hours
A written, severity-ranked report on the five failure modes (auth & access control, payments, secrets, error handling, monitoring) with a fixed quote to fix, plus a fine-as-is list of what you can leave alone. Yours to keep either way. Usual turnaround is 48 hours; a busy week can stretch delivery to day 5, and if no report lands by then you get a full refund.
48 h- H+0: Payment + access confirmed. The clock starts
- You pay, get a personal confirmation, and send read-only repo access plus one line on what worries you. Once we confirm access works, the clock starts. Everything you share stays private.
- H+8: Secrets & git-history scan logged
- Exposed keys, service roles in client code, credentials in git history: found, logged, and (if leaking right now) flagged to you immediately.
- H+16: Auth & access-control pass complete
- Row-level security, server-side checks, session handling. Can a stranger read another user’s data by changing a parameter? We find out.
- H+24: Payments & error handling checked
- Does the Stripe flow actually charge, is the webhook verified, and what happens on the unhappy path? Logged with severity.
- H+36: Monitoring reviewed, findings ranked
- Environments, logging, alerting. Every finding is ranked by severity so you know what’s dangerous versus cosmetic.
- H+48: Report + fixed quote delivered
- A written, severity-ranked report with a fixed quote to fix. If a busy week pushes delivery past day 5, you get a full refund. Yours to keep either way.
§ Chain of custody
Your code is handled like evidence
Confidential by default. Read-only repository access is enough. Any secret we touch gets rotated before handback. Stacks we live in: Next.js, Supabase (including row-level security), Stripe, Vercel, Firebase, Node. Yours not on the list (Convex, Clerk, Railway, whatever Bolt picked)? Ask first; the five checks map to most stacks, and if we can't audit yours properly we say so before you pay. See exactly what the report looks like before you pay.
03 Who you're paying
Named humans, checkable work.
Mradul Tripathi (engineering) and Sanya Madre (design). The founders do the audits themselves, no outsourcing: Mradul runs the security and engineering side, Sanya runs the UI/UX audits. We run our own production auth and billing every day: Rekey is our MIT-licensed auth & billing product, and you can read the code before you trust us. Etherlabz IT Solutions Pvt. Ltd., registered in India, working with founders across the EU and US.
“Communication was clear, consistent, and highly responsive, making collaboration smooth and efficient.”
Kristjan Idrizi · Founder & CEO · ★ Verified 5.0 review on Clutch
Not ready to pay? Read the sample report or the rescue overview. Prefer a human first? Book a 30-minute call.
04 FAQ
The fine print, answered.
When exactly does the 48-hour clock start?
At our written confirmation that both your payment and working repo access have arrived. Pay at 11pm and send access in the morning, and the clock starts when we confirm access works, not while you sleep.
What happens if you're late?
In a busy week delivery can stretch to day 5, and we say so at confirmation. If no report lands within 5 calendar days of confirmation, you get every cent back. Need it guaranteed in 48 hours regardless of the queue? Rush delivery costs extra, priced case by case: ask before you pay.
What counts as one audit?
One app: one repo, one auth provider, one payment integration. A monorepo, several services, or more than one project needs a written quote first, so write to us before paying and we quote it properly instead of short-changing you.
Is this a penetration test?
No. It's an expert code review against the five failure modes that break vibe-coded apps, not a penetration test and not a compliance certification (SOC 2, ISO 27001, PCI DSS). A clean result is still a deliverable: every report ends with a fine-as-is checklist of what we verified and you can leave alone.
Can I get a refund if I change my mind?
Paid but haven't sent access yet? Full refund on request; nothing has started. Once we confirm access and the clock starts, the fee is committed, and the 5-day late-delivery refund still applies. Full details in the audit terms.
The contractual version of all of this lives in the audit terms.