Audit + Rescue
Independent Inspection. Controlled Repair.
Audit is read-only wherever reasonably possible. It answers “what's actually going on here?” Rescue is separate, controlled work — and it never silently adds features.
Independent Audit — $495
Read-Only. No Repair Included.
A structured inspection with evidence. The report identifies what was tested, the evidence, findings, severity, limitations, and what could not be verified. Unless an SOW expressly says otherwise, this is not a penetration test, compliance certification, legal opinion, or repair engagement.
Severity scale: Critical · High · Medium · Low · Info
Audit Categories
- Functionality
- Authentication
- Authorization / data isolation
- Data integrity
- Security architecture
- Payments
- Integrations
- Responsive / UI
- Error handling
- Performance
- Regression risk
- Deployment / configuration
- Source / repository condition
- Backup / recoverability
Rescue — From $1,495
Controlled Repair, Defined Scope
Rescue does not silently include new features. Repair scope is established separately, with the exact fixed scope and price confirmed before authorization. We protect what works with regression testing.
Software occasionally responds to being fixed by developing a new personality. That's why we retest the parts that already worked after a repair. Fixing payments, for example, shouldn't mysteriously break login. We also verify the agreed repair before it is put into normal use.
Source & Access
We Ask for What the Work Actually Needs — After Authorization
Submitting an Audit or Rescue intake does not authorize source transfer. After the proposal, required agreements, any supplemental data terms, and the applicable payment gate are cleared, SBG decides whether the engagement actually needs a source ZIP, repository/platform access, test or staging access, or no additional client material at all.
If a source ZIP is genuinely required, SBG opens a project-specific Secure Source Upload inside the authenticated Client Portal. Source archives are accepted only through that SBG workflow — not by ordinary email, Google Drive, Dropbox, WeTransfer, or another file-sharing link. Repository and platform access are coordinated separately through official collaborator/team or other least-privilege mechanisms when available. SBG does not currently operate a raw shared-credential vault; if a platform requires a shared secret and offers no safe delegated mechanism, SBG may be unable to perform the access-dependent work rather than asking you to send the secret through an unsafe channel.
Source is uploaded only when the portal opens an authorized request. That keeps unnecessary copies of proprietary code out of ordinary channels.
Honest Boundary
Pre-Existing Conditions Stay Outside the Repair Scope Unless We Agree Otherwise
Taking on an existing application does not silently expand the repair scope to every condition already present. We'll tell you what we find, what we recommend, and what belongs inside or outside the agreed work.