Find and fix what could break your launch. No critical or high issue? Full refund.
Nordik Audit reads your app's code at one exact commit and sends a ranked report plus patches for the critical and high issues it finds. Performed by AI (Claude), by email.
- Report + fix patches
- $399 · $249 for the first 5 clients
- Full refund if nothing critical or high
What you get
- A ranked, plain-language report on one exact commit, most urgent first.
- Patches for critical and high findings (up to 10, where a code change can fix them). You review and apply them; we never get write access.
- A "what was not checked" section listing skipped files and the limits of this audit.
- A full refund if the released report has no critical or high finding.
What a finding looks like
Every finding in the report follows the same layout. Every code finding cites the file and line, and the quote is checked against your code.
- Severity and state
- Critical, high, medium or low, and whether it is confirmed, needs follow-up or was rejected after review.
- Where
- The file and line at your pinned commit, with the quoted code.
- Why it matters
- The possible impact in plain language, and what was and was not established.
- How it was checked
- Which pass found it and which reviewers agreed.
- How to fix it
- A suggested correction and, for critical and high findings where code can fix them, a patch. Each patch is one change with a plain explanation. Findings that a code change cannot fix are reported without a patch.
Want to see a full one? Email us “sample” and we will send the sample report, built from an invented demo app.
What it checks
Nordik Audit is built for apps made with Next.js and Supabase: a JavaScript or TypeScript repository you send as one Git bundle.
- Supabase row-level security problems.
- Missing or weak authorization on Next.js routes.
- It is AI-performed and does not catch everything. The report lists what was not checked.
It works in four passes
- Fixed rules look for common launch mistakes in the code: secrets committed to the repository (including its history) or exposed to the browser, database rules left open, unsafe input handling, unsafe configuration and cookies, and risky CI workflows.
- A dependency check matches your locked package versions against a public vulnerability advisory snapshot, dated in the report. This needs a committed lockfile.
- An AI reading of the most security-relevant files proposes design-level findings. Any finding whose quoted code is not at the cited file and line is dropped.
- AI review. Each code finding is checked by an AI reviewer. Serious code findings (critical or high) are checked by two independent AI reviewers, and unclear cases are investigated further. Dependency findings rest on the advisory data. A person releases the finished report.
What it does not do
It does not run your code, test your running app or touch your live database, hosting or third-party accounts. Live database settings are not in your repository, so they are not reviewed.
It is not a penetration test, a certification, a compliance statement or proof that your app is safe.
AI-found issues are quote-checked against the code but may still be wrong. Findings were settled by AI reviewers, with a second reviewer for critical and high findings, and the report was released by a person. An empty section means nothing was found by these checks, not that there is no risk.
How it works
- Email us your repo details. We confirm in writing that it fits, before you pay.
- Agree to the consent, pay, send one Git bundle. No GitHub access, no token.
- The audit runs. Fixed rules, a dependency check and AI review. A person releases the report.
- You get the report, then the patches. Targets: 3 business days, then 3 more.
- Nothing critical or high? Reply within 14 days for a full refund.
More detail on each step
- Tell us the stack, where it is hosted, roughly how big it is and your launch or investor date. Launching soon, or waiting on an investor or customer? Put the date in your first message.
- The full AI-processing consent comes first: your code goes to Anthropic (Claude), and only with your consent. Then you pay, and send one Git bundle with the full commit ID. The code is never run.
- Fixed rules, an offline check of your locked package versions, and an AI reading of the most security-relevant files. Each code finding is quote-checked and reviewed by AI, and serious ones by two independent AI reviewers, with unclear cases investigated further. A person releases the report.
- These are targets, not promises: the report within 3 business days of a verified snapshot, the patches within 3 more business days, and a 14-day follow-up by message for questions and one revision round per fix.
- The fee is refunded in full within 5 business days. You keep the report.
Everything happens by email. There are no calls and no booking links.
Price and refund
$399 USD, standard price
$249 USD founding price for the first 5 clients.
The Launch Check covers one repository at one commit. The scope and refund are the same at both prices.
If the audit finds no critical or high issue, you get a full refund.
The exact refund term
If your released report contains no finding rated critical or high, we refund what you paid for that audit in full. Ask by replying to the report within 14 days of its release, and we refund the original payment within 5 business days. A finding counts if the released report rates it critical or high, including a vulnerable-dependency finding. You keep the report. This is a refund of the fee when the audit finds nothing at that level; it is not a statement that your app has no risk. If we decline your repository at intake we refund you in full separately. Once a report with a critical or high finding is released, there is no refund.
The audit is AI-performed, so there is no hourly billing, no scheduling and no call. Nordik Audit reads your code; it does not test your running app.
FAQ
Is a person reviewing my code?
No. The audit is AI-performed (Claude). A person releases the report, but there is no human security reviewer at the moment. If that is what you need, this is not the right product.
Can the AI be wrong?
Yes. Each AI-found issue is checked against the code and reviewed, and serious ones by two independent AI reviewers, but a finding can still be wrong and the audit can miss problems. The report says what was and was not checked, and an empty section is not a clean bill of health.
Who sees my code?
Your repository at the agreed commit is sent, in whole or in part, to Anthropic (Claude), the only AI provider used for this service, and only after you agree to the written consent. If you do not agree, we cannot do the audit. We do not send your code to anyone else. The privacy note has the details.
Do you need access to my GitHub or my hosting?
No. You send one Git bundle and the full commit ID. There is no access to your accounts, no token, and no write access to your repository. We never need production, hosting or database access, and we never run your code. Please run your tests before merging any patch.
How long do you keep my code?
The bundle file is deleted as soon as it is unpacked. Our working copy and the report are deleted 30 days after the report is released. Copies you hold, your email provider's copies and the AI provider's own retention are not covered. See the privacy note.
What happens if the audit finds nothing critical or high?
You get a full refund, under the term in the price section, and you keep the report. A refund of the fee does not mean your app has no risk.
Is this a penetration test or a compliance report?
No. It is a code audit of one repository at one commit. It does not test your running app, and it is not a certification or a compliance statement. It can give you a dated, written record of what was checked, which some investors and customers ask for, but it does not replace a formal assessment.
Which apps does it take?
One JavaScript or TypeScript repository, built with Next.js and Supabase, with a committed lockfile for the dependency check. Monorepos with several apps, other primary languages, native mobile code and regulated systems such as payment processors or health records are declined.
What does a patch change?
One fix per patch: for example a configuration change, a missing authentication or ownership check, a migration that enables row-level security, or moving a secret server-side. Fixes outside those kinds are reported without a patch, and redesign-scale work is out of scope.
Contact
Email is the only way to reach us: outreach@getnordik.com. Nothing is charged until we have confirmed in writing that your repository fits.