Skip to Main Content

Audit + Rescue

Independent Inspection. Controlled Repair.

Audit is read-only wherever reasonably possible. It answers “what's actually going on here?” Rescue is separate, controlled work — and it never silently adds features.

Independent Audit — $495

Read-Only. No Repair Included.

A structured inspection with evidence. The report identifies what was tested, the evidence, findings, severity, limitations, and what could not be verified. Unless an SOW expressly says otherwise, this is not a penetration test, compliance certification, legal opinion, or repair engagement.

READY
READY WITH CONDITIONS
NOT READY
NOT VERIFIED

Severity scale: Critical · High · Medium · Low · Info

Audit Categories

  • Functionality
  • Authentication
  • Authorization / data isolation
  • Data integrity
  • Security architecture
  • Payments
  • Integrations
  • Responsive / UI
  • Error handling
  • Performance
  • Regression risk
  • Deployment / configuration
  • Source / repository condition
  • Backup / recoverability

Rescue — From $1,495

Controlled Repair, Defined Scope

Rescue does not silently include new features. Repair scope is established separately, with the exact fixed scope and price confirmed before authorization. We protect what works with regression testing.

Authorized scope→
Baseline / recoverability→
Controlled repair→
Test→
Regression test→
Post-Repair Verification→
Controlled deployment→
Version provenance→
Known limitations

Software occasionally responds to being fixed by developing a new personality. That's why we retest the parts that already worked after a repair. Fixing payments, for example, shouldn't mysteriously break login. We also verify the agreed repair before it is put into normal use.

Source & Access

We Ask for What the Work Actually Needs — After Authorization

Submitting an Audit or Rescue intake does not authorize source transfer. After the proposal, required agreements, any supplemental data terms, and the applicable payment gate are cleared, SBG decides whether the engagement actually needs a source ZIP, repository/platform access, test or staging access, or no additional client material at all.

If a source ZIP is genuinely required, SBG opens a project-specific Secure Source Upload inside the authenticated Client Portal. Source archives are accepted only through that SBG workflow — not by ordinary email, Google Drive, Dropbox, WeTransfer, or another file-sharing link. Repository and platform access are coordinated separately through official collaborator/team or other least-privilege mechanisms when available. SBG does not currently operate a raw shared-credential vault; if a platform requires a shared secret and offers no safe delegated mechanism, SBG may be unable to perform the access-dependent work rather than asking you to send the secret through an unsafe channel.

Source is uploaded only when the portal opens an authorized request. That keeps unnecessary copies of proprietary code out of ordinary channels.

Honest Boundary

Pre-Existing Conditions Stay Outside the Repair Scope Unless We Agree Otherwise

Taking on an existing application does not silently expand the repair scope to every condition already present. We'll tell you what we find, what we recommend, and what belongs inside or outside the agreed work.