Services · Audit and engineering

We look at your systems the way no one has before.

Five offers, one principle: produce evidence, not impressions. Every engagement ends with a written report and a dated plan.

Evidence

Six numbers measured on systems in production.

0 days

a personal-data leak left open

0 days

with no backup at all, every indicator green

0%

the gap between reported and actual revenue

0 sites

one injection, six entry points

0 of 43

tests that passed without measuring anything

0 layers

of stacked causes behind a single outage

These figures are measured and verifiable. We claim no others.

The five offers

What we do, precisely.

No vague retainer: a scope, a duration, a written deliverable.

01

Security and exposure audit

Know what is open — before someone else finds it.

  • Mapping of entry points and exposed surfaces
  • Review of access, privileges and forgotten accounts
  • Testing of injection paths and data leakage
Field finding

6 sites — one injection, six entry points.

02

Continuity and backups

A proven restore, not a ticked box.

  • Inventory of the data that is genuinely critical
  • Real, timed restore test
  • Alerts that fire when a backup fails
Field finding

64 days — with no backup at all, every indicator green.

03

Data and revenue reliability

Numbers you can actually decide on.

  • Reconciliation between reported and collected revenue
  • End-to-end event traceability
  • Dashboards that can be verified, not just admired
Field finding

164% — the gap between reported and actual revenue.

04

Quality and testing

Tests that measure something real.

  • Audit of the existing test suite
  • Regression tests on the journeys that make money
  • Continuous integration that blocks what must be blocked
Field finding

25 of 43 — tests that passed without measuring anything.

05

Incident diagnosis and post-mortem

Trace the cause, not the symptom.

  • Chronological reconstruction of the incident
  • Layered analysis of stacked causes
  • Prioritised remediation plan, with owners
Field finding

3 layers — of stacked causes behind a single outage.

Every engagement ends with a written report, reproducible evidence and a prioritised, dated remediation plan.

How it works

Five steps, no grey areas.

Every engagement follows the same sequence. You always know what happens next.

  1. 01

    Scoping call

    You describe your system. We tell you what we would look at first, and what we would not.

    30 minutes
  2. 02

    Read-only access and NDA

    NDA signed before anything else. Read-only access by default; write access requested case by case.

    Within 24 hours
  3. 03

    Investigation

    We reproduce, measure and record. Every finding comes with the exact steps to reproduce it.

    45 minutes to 3 days
  4. 04

    Written report

    Findings, evidence, severity. No slideware, no impressions — a document you can hand to a third party.

    48 hours after the work
  5. 05

    Dated remediation plan

    Prioritised fixes with dates. We can carry them out ourselves if you ask.

    Included
Who it is for

Three situations where we are useful.

If none of them describes you, tell us anyway.

01

Startups that just raised

The product runs, and so does the technical debt. You need to know what will hold for the next twelve months.

02

SMEs and scale-ups in production

Live systems, small teams, and nobody whose job is to check what breaks silently.

03

Institutions handling sensitive data

Real compliance and continuity obligations — to be proven, not merely declared.

Guarantees

What we commit to, in writing.

Six commitments that apply to every engagement, whatever its size.

Our refund guarantee
« I have never audited an AI-built application without finding something. If that ever happened, I would refund you. »

Fixed scope and price

Agreed before we start. No overruns billed after the fact.

NDA before any access

Signed systematically, before touching your systems or your data.

Minimum access

Read-only by default. Write access is requested explicitly, case by case.

Reproducible evidence

Every finding ships with the exact steps to reproduce it yourself.

Deadlines held

48 hours for the express diagnostic, 3 days for the full audit. If we slip, you are told before the deadline, not after.

No manufactured problems

If we find nothing, the report says so plainly and it is shorter.

Frequently asked

What people ask before we start.

Express diagnostic: 45 minutes, delivered within 48 hours. Full audit: 3 days. Audit and fixes: 5 to 8 days. Full platform: 3 to 6 weeks, depending on the scope agreed upfront.

Read-only access is enough to start. Any write access is requested explicitly, case by case.

Yes, always, before any access to your systems or your data.

Yes. The team is based in Dubai and works remotely with clients across several continents.

The report says so plainly, and it is shorter. We do not manufacture problems to justify an engagement.

With a 30-minute call to frame the scope. You leave with a written estimate, no commitment.

Audit checklist

The 12 things we check first.

Leave your email and we will send you the checklist we use at the start of every engagement. You can run it yourself.

One address, one email. No resold lists, unsubscribe on request.

Next step

A 30-minute call, and you will know where you stand.

Describe your system in three sentences. We will tell you what we would look at first.