What you get
Finding out is free.
Fixing it is $39.
Three things, and it's worth being clear which is which — the scan, the score and every finding cost nothing and stay that way. The $39 is for closing them. The $149 is for having me read what you did.
Free
The Exposure Check
No signup, no card, no scanning.
- The Exposure Scan. Paste your URL and I read what your app already shows the public — headers, bundle, the well-known paths. You get a letter grade and every finding.
- 13 questions — 16 if you name two backends. Plain language, no jargon.
- An Exposure Score out of 100. Lower is better.
- Every finding, in full. The title and the whole explanation — not a teaser, not a locked preview, not three free and the rest behind an email.
- The 5 audit prompts, one per stack — the same files a buyer reads, on a page with a copy button. No email.
- Core 1 of the course, in full —read it here, checklist and prompts included.
- Which module fixes each one, named — so you can see what you'd be buying before you buy it.
- Answers are scored in your browser. The scan reads only what your app hands anybody who visits it.
- Optionally emailed to you — same content, costs an address rather than money.
Scan your app free$39 once
The Sunday Sprint
A course and a prompt kit — not a report.
- 8 core modules that apply to any stack. The first one is free above; the other 7 are here.
- Your stack's track. 5 exist: Supabase, Firebase, Next.js / Vercel, Lovable · Bolt · v0 · Base44 · Replit, Azure.
- Three prompts in every module — one to audit, one to fix, one to prove the fix worked. Across all 19 modules. The audit ones are the 5 free above; the fix and proof ones are here.
- One prompt built from your own findings, assembled from what your scan and your answers actually turned up.
- It works on the next project too. This is the part people miss: you're not buying one report about one app. The prompts and the modules apply to whatever you build after this.
- One payment, no subscription, access for at least 12 months,seven days to change your mind.
See everything inside — $39$149 once
The Sunday Review
A person reads it. Includes the Sprint.
- Everything in the Sprint, included — all 19 modules and every prompt.
- I read your re-scan, your three most critical screens, and your stack. By hand, not by tool.
- A written reply within five days of your material reaching me — something you can forward, not a call you take notes in.
- A dated, signed note if your re-scan comes back clean, with my name on it and what I looked at.
- Not a penetration test, not a compliance artifact, and not a promise you're safe. It's one person's written opinion, labelled as one.
What the Review covers — $149The line between them
The free scan and check tell you what is wrong and where it lives. The Sprint tells you how to fix it — in your stack's specific terms, with prompts you hand to the same AI that built the thing. The Review tells you whether I think you actually did.
What it isn't
- The scan only sees the outside. It reads what your app already shows any visitor. It never logs in, never queries your database, and never stores the value of anything secret — the type and the file name, nothing else.The full list of what it won't do →
- The score is still your own answers. Whether you have backups, whether your admin route checks who's calling — no outside scan can see those, so the questions remain honest self-report.
- It's a snapshot, not monitoring. Nothing watches your app after you close the tab.
- Step-by-step instructions exist for 5 stacks.On AWS, or a server you run yourself, the core modules and the prompts still apply — but you'd be adapting the vendor-specific parts yourself.
- Not a penetration test, and not a compliance artifact. That's true of all three tiers, including the Review. If you need something to hand an auditor, none of this is it.