• AI-performed (Claude)
  • Next.js + Supabase
  • Report + fix patches

Find and fix what could break your launch before your users do. No critical or high issue? Full refund.

One open database table or leaked key can turn a launch into a cleanup. Nordik Audit reads your Next.js and Supabase code at one exact commit and sends a ranked report plus patches for the critical and high issues it finds. Each serious finding is checked by a second independent AI reviewer. $249 for the first 5 clients, then $399, and a full refund if nothing critical or high turns up. Performed by AI (Claude), by email.

Illustration, not a customer's app
What you get

One report. The fixes that matter most.

Everything is delivered by email, on one exact commit of your repository.

A ranked, plain-language report

On one exact commit, most urgent first.

Patches for critical and high findings

Up to 10, where a code change can fix them. You review and apply them; we never get write access.

A "what was not checked" section

Listing skipped files and the limits of this audit.

A full refund

If the released report has no critical or high finding.

  1. 01
    Severity and stateCritical, high, medium or low, and whether it is confirmed, needs follow-up or was rejected after review.
  2. 02
    WhereThe file and line at your pinned commit, with the quoted code.
  3. 03
    Why it mattersThe possible impact in plain language, and what was and was not established.
  4. 04
    How it was checkedWhich pass found it and which reviewers agreed.
  5. 05
    How to fix itA suggested correction and, for critical and high findings where code can fix them, a patch. Each patch is one change with a plain explanation. Findings that a code change cannot fix are reported without a patch.
What a finding looks like

Every finding in the report follows the same layout. Every code finding cites the file and line, and the quote is checked against your code.

Example layout
CriticalConfirmed

Notes table readable by any signed-in user

Where
supabase/migrations/0004_notes.sql:12
create table notes ( ... );
How to fix it

One patch: enable row-level security and add an owner-only policy.

Want to see a full one? Read the sample report, built from an invented demo app.

What it checks

Built for Next.js and Supabase apps.

Nordik Audit is built for apps made with Next.js and Supabase: a JavaScript or TypeScript repository you send as one Git bundle.

Supabase row-level security problems.

Database rules left open or too broad.

Missing or weak authorization on Next.js routes.

Routes that do not check who is asking.

Every report ends with a "what was not checked" section, so you know exactly what the audit covered.

It works in four passes

01

Fixed rules

Look for common launch mistakes in the code: secrets committed to the repository (including its history) or exposed to the browser, database rules left open, unsafe input handling, unsafe configuration and cookies, and risky CI workflows.

02

A dependency check

Matches your locked package versions against a public vulnerability advisory snapshot, dated in the report. This needs a committed lockfile.

03

An AI reading

Of the most security-relevant files proposes design-level findings. Any finding whose quoted code is not at the cited file and line is dropped.

04

AI review

Each code finding is checked by an AI reviewer. Serious code findings (critical or high) are checked by two independent AI reviewers, and unclear cases are investigated further. Dependency findings rest on the advisory data. A person releases the finished report.

How it works

From first email to fixes, in five steps.

Everything happens by email. There are no calls and no booking links.

  1. 1

    Email us your repo details.

    We confirm in writing that it fits, before you pay.

  2. 2

    Agree to the consent, pay, send one Git bundle.

    No GitHub access, no token.

  3. 3

    The audit runs.

    Fixed rules, a dependency check and AI review. A person releases the report.

  4. 4

    You get the report, then the patches.

    Targets: 3 business days, then 3 more.

  5. 5

    Nothing critical or high?

    Reply within 14 days for a full refund.

More detail on each step
  1. Tell us the stack, where it is hosted, roughly how big it is and your launch or investor date. Launching soon, or waiting on an investor or customer? Put the date in your first message.
  2. The full AI-processing consent comes first: your code goes to Anthropic (Claude), and only with your consent. Then you pay, and send one Git bundle with the full commit ID. The code is never run.
  3. Fixed rules, an offline check of your locked package versions, and an AI reading of the most security-relevant files. Each code finding is quote-checked and reviewed by AI, and serious ones by two independent AI reviewers, with unclear cases investigated further. A person releases the report.
  4. These are targets, not promises: the report within 3 business days of a verified snapshot, the patches within 3 more business days, and a 14-day follow-up by message for questions and one revision round per fix.
  5. The fee is refunded in full within 5 business days. You keep the report.
Price and refund

One price. Full refund if nothing critical or high.

The Launch Check covers one repository at one commit. The scope and refund are the same at both prices. The limits are in the Terms.

Launch CheckFirst 5 clients

$249USD

$249 USD founding price for the first 5 clients. Then $399 USD, standard price.

  • A ranked, plain-language report on one exact commit
  • Patches for critical and high findings, up to 10
  • A "what was not checked" section
  • A 14-day follow-up by message, one revision round per fix
  • If the audit finds no critical or high issue, you get a full refund
Start my audit

Nothing is charged until we have confirmed in writing that your repository fits.

5 of 5 slots left this week.

Nothing critical or high? Full refund.

  • Scan, $249: Launch Risk Score and ranked findings, no patches.
  • Audit, $399: report plus patches for critical and high findings, and a re-check of the fixes within 14 days.
  • Launch Shield, $899: Audit plus a second re-check, a pre-launch checklist and priority turnaround.

Why one flat price

The audit is AI-performed, so there is no hourly billing, no scheduling and no call. You see the total price before you pay anything.

The exact refund term

If your released report contains no finding rated critical or high, we refund what you paid for that audit in full. Ask by replying to the report within 14 days of its release, and we refund the original payment within 5 business days. A finding counts if the released report rates it critical or high, including a vulnerable-dependency finding. You keep the report. This is a refund of the fee when the audit finds nothing at that level; it is not a statement that your app has no risk. If we decline your repository at intake we refund you in full separately. Once a report with a critical or high finding is released, there is no refund.

FAQ

Questions, answered.

Is a person reviewing my code?

The audit is done by AI (Claude), and that is the point: every serious finding gets a second independent AI reviewer, unclear cases are investigated further, and a person releases the finished report. You get a ranked report and patches by email, with no hourly billing and no call. If the audit finds nothing critical or high, you get a full refund and keep the report.

Can the AI be wrong?

Yes. Each AI-found issue is checked against the code and reviewed, and serious ones by two independent AI reviewers, but a finding can still be wrong and the audit can miss problems. The report says what was and was not checked, and an empty section is not a clean bill of health.

Who sees my code?

Your repository at the agreed commit is sent, in whole or in part, to Anthropic (Claude), the only AI provider used for this service, and only after you agree to the written consent. If you do not agree, we cannot do the audit. We do not send your code to anyone else. The privacy note has the details.

Do you need access to my GitHub or my hosting?

No. You send one Git bundle and the full commit ID. There is no access to your accounts, no token, and no write access to your repository. We never need production, hosting or database access, and we never run your code. Please run your tests before merging any patch.

How long do you keep my code?

The bundle file is deleted as soon as it is unpacked. Our working copy and the report are deleted 30 days after the report is released. Copies you hold, your email provider's copies and the AI provider's own retention are not covered. See the privacy note.

What happens if the audit finds nothing critical or high?

You get a full refund, under the term in the price section, and you keep the report. A refund of the fee does not mean your app has no risk.

Terms

What the audit covers, and what it does not.

Scope and limits

Not a pentest. It is a code audit of one repository at one commit. It does not test your running app, and it is not a penetration test, a certification, a compliance statement or proof that your app is safe. It can give you a dated, written record of what was checked, which some investors and customers ask for, but it does not replace a formal assessment.

It never runs your code and does not touch your live database, hosting or third-party accounts. Live database settings are not in your repository, so they are not reviewed.

The audit is AI-performed and can miss problems, and an AI-found issue can still be wrong even after quote-checking and review. An empty section means nothing was found by these checks, not that there is no risk. The report lists what was not checked.

Which apps, and which fixes

One JavaScript or TypeScript repository, built with Next.js and Supabase, with a committed lockfile for the dependency check. Monorepos with several apps, other primary languages, native mobile code and regulated systems such as payment processors or health records are declined at intake, with a full refund if you had already paid.

One fix per patch: for example a configuration change, a missing authentication or ownership check, a migration that enables row-level security, or moving a secret server-side. Fixes outside those kinds are reported without a patch, and redesign-scale work is out of scope. Please run your tests before merging any patch.

Contact

Launching soon? Get the audit before your users find the bugs.

Email is the only way to reach us: outreach@getnordik.com. Nothing is charged until we have confirmed in writing that your repository fits.