Fresh-clone build & test
We clone from nothing, build it, and run your tests, then report honestly whether it works and how many tests actually pass.
Forgehaven Labs · Overnight Audit
A fixed-price code audit that an agent fleet runs and a human engineer verifies. You get findings with evidence, a severity call by impact, and a 30-day plan you can actually book time against. Not a scanner dump. 24-hour turnaround.
Fixed price · 24 hours · every finding verified by a human before it ships
What you get
Every audit runs the same passes on a fresh clone of your code. Then a director-level engineer reads the whole thing, reproduces the findings, and cuts the noise before you ever see it.
We clone from nothing, build it, and run your tests, then report honestly whether it works and how many tests actually pass.
Known CVEs, unmaintained packages, and license conflicts, with the exact advisory IDs and the one-line fix for each.
Committed credentials, weak fallback secrets, and unignored env files. We report type and location only, never the value.
Injection, authorization, and input-validation review on the code that actually handles auth, money, and user data.
P0 to P3, ranked by what it costs you if ignored. False positives are killed in a human review gate, so the list is real.
Grouped by work session with time estimates, plus quick wins under 30 minutes each, and an honest list of what we did not check.
The 24-hour promise
The pipeline is roughly 85% automated, so the clock is never at the mercy of a busy week. An agent fleet handles the clone, the build, the scans, and the first draft; a human spends about twenty minutes verifying the top findings and hits send. If a repo turns out to be out of scope, we tell you within the first hour and refund. If we find nothing wrong, we tell you that too, with the receipts.
Pricing
$149
A full code audit of one repository, delivered in 24 hours.
$249
Rejected by App Review? We decode the real reason and hand you a resubmission plan.
Secure checkout via Stripe. You will receive an intake form right after payment; the 24-hour clock starts when we have repo access.
See it first
We ran the exact process against two popular open-source repos and published the reports unedited. Read them before you spend anything.
A boolean-vs-string bug that silently keeps directory listing on in the library API, dotfiles served by path, and four production CVEs. Grade: B.
Read the report →A weak fallback secret that makes password-reset tokens forgeable, an unignored .env, and 17 of 54 pinned dependencies with published CVEs. Grade: C+.
Read the report →Start an audit
Already paid, or want to ask before you buy? Send the details below and we will confirm scope and timing. Everything on this page is run by Steven Green, Forgehaven Labs LLC.
Email us the following and we will reply within one business day:
Prefer to just start? Pick a tier and the intake form follows checkout.
Honest answers
No. The fleet does the mechanical passes, but a human engineer reproduces and prunes every finding before delivery. The value is what gets cut, not what gets flagged. The microblog sample even has a section listing things that are not problems.
That is a finding. You get the green scorecard plus a clear account of what we checked and why the repo is solid. A clean bill from a real audit has value.
No. Your code is cloned into a throwaway working directory and deleted at close-out. Any read-only access key you issue should be revoked afterward; we remind you to. Secrets are reported by type and location only, never by value.
No one honestly can. What we give you is the real reason behind the rejection, the exact changes to make, and an honest read on the odds. We are engineers, not lawyers.
Node, Python, Swift/iOS, Go, and most mainstream web stacks. If your repo is out of scope, we say so within the first hour and refund, no charge.