A full 13-layer audit of your platform, delivered in 24 hours, using read-only access you can revoke the moment the report lands. We can see your code. We cannot change it, copy it, or take it anywhere. You get a scored report and prioritized findings. Every finding is matched to a fix skill built for your codebase, ready to load into Claude, Cursor, or whatever agent you build with.
Read-only GitHub App. Revoke anytime. NDA available on request. Nothing stored after delivery.
Will it survive production traffic? A security scan? A technical due diligence review? You built it with AI tools, it works, users like it. But "it works" and "it's ready" are two different sentences, and you can't grade your own homework.
Users are showing up and weird stuff is happening. Slow pages, odd errors, things that worked yesterday. You need to know if it's a patch or a foundation problem.
Technical due diligence is coming. "Who reviewed your security?" is a question you want to answer with a report, not a shrug.
AI got you to a working product fast. It did not tell you what it skipped. Sixty-five percent of vibe-coded apps ship with security issues. You'd rather find yours before someone else does.
Hundreds of builders have DM'd asking for a review of their app. Almost none of them had ever shared their repo with anyone. That hesitation is healthy. Your code is your work, your idea, and maybe your future company. So here is exactly what happens, in plain language.
You install Faction Audit Reader, a read-only GitHub App, on the one repo you choose. Read-only means exactly what it sounds like: it can look at the code. It cannot edit it, delete it, push to it, or change a single character. GitHub enforces this at the platform level.
We review the code, score it across the 13 layers, and generate your report. The moment your report lands, or any moment before, you remove the app from the repo and the access is dead. You hold the keys the entire time — no shared passwords, no personal access tokens, and an NDA is available if you want one.
You are never locked in. The moment your report lands, or any moment before, you remove the app from the repo and the access is dead. You hold the keys the entire time.
We run an engineering firm with a full client pipeline. Our business is finishing software, not launching competitors to yours. An NDA is available if you want it in writing before we see anything.
The repo is reviewed for the audit and purged after the report is generated. Nothing is stored, archived, or reused.
Your repo stays yours, untouched. No forks, no clones left behind, no copies floating around.
Zero write access. We couldn't change anything even if we wanted to. That's what read-only means, and GitHub enforces it, not us.
Every vibe-coded app has gaps. That's not a verdict on you, it's the nature of how AI builds. The report exists to close the gaps, not to grade you as a person.
These aren't audit customers being polite. These are builders who applied the same 13-layer lens to their own apps and reported back, unprompted.
I've been investigating my architecture and codebase after each video, and I have found hundreds of issues and violations. All of which are fixed right now following your best practices.
Came across your posts and realized my first app had literally no security checks or balances. The second app is now being hardened and built to scale.
This helped. Just saw 17 vulnerabilities. 7 moderate, 10 high. Thanks man.
I thought I had the most brilliant setup and locked it down. My friend found my API and in 10 minutes showed me the fail. Blew me away. Very humbling.
Your app has a list like this too. The audit finds it in 24 hours. Read 159+ more builder stories →
All 13 layers, each scored green, yellow, or red. One page. You know where you stand in thirty seconds.
Every finding: what it is, where it lives in your code, why it matters, and how severe it is.
Every finding maps to a fix skill generated from your code, not a template. Your stack, your gap, your fix. Buy the ones you need, skip the ones you don't.
P1, P2, P3. What to fix before you sleep tonight, what to fix this week, what to fix before you scale.
The report tells your agent what is broken. Each skill tells it exactly how to fix it, structured to load directly into Claude, Cursor, or whatever you build with. A fix written for one specific codebase cannot be written in advance. That is why it works.
The same 13-layer framework taught inside The Faction. Your report maps to the exact discipline thousands of builders are learning right now.
This is the same assessment we run at the start of every Faction Group commercial engagement. It's how we scope real builds for real clients. A senior engineer would charge $2,000+ for this review. An agency would quote $5,000 and up, after two discovery calls.
AI-directed automation collapsed weeks of senior-engineer review into an automated pipeline that scores all 13 layers in hours. We had a choice: keep the margin or pass it on. We passed it on. An audit is 200 tokens, and you add fix skills only where you actually need them. 200 tokens isn't the discount price. It's the honest price.
A full audit is about $20 USD (200 tokens). Fix skills run ~$10 each; re-runs ~$5.
Email only, magic link, no password. 100 welcome tokens land in your balance the moment you confirm.
The $25 Starter bundle plus your welcome tokens covers a full find-fix-verify cycle. Bigger bundles carry a bonus. Stripe checkout, done in a minute.
200 tokens. Repo URL required, live URL optional. Private repo? Install Faction Audit Reader first, then submit.
Most audits land in under two hours, 24 hours guaranteed. Scorecard, findings, and priorities in your dashboard and your inbox. Revoke access anytime.
Buy the skills you need, 100 tokens each, run them with your agent, then re-run the audit for 50 to prove the fixes landed. That loop is the product.
| Service | Tokens | ≈ USD (base rate) |
|---|---|---|
| Full 13-layer audit | 200 | ~$20 |
| Fix skill (per finding) | 100 | ~$10 |
| Re-run verification | 50 | ~$5 |
New accounts start with 100 free welcome tokens. Bigger bundles improve the rate — full pricing and a worked example on the tokens page.
Same intake form either way. We never ask for your GitHub password, 2FA, or a personal access token. An NDA is available on request. Questions about safety? See Code Safety & Trust.
1. Create your account and top up tokens if needed.
2. Paste https://github.com/owner/repo in the intake form.
3. Submit — 200 tokens, audit begins immediately.
1. Before you submit: install Faction Audit Reader on that repo only (choose "Only select repositories").
2. Sign in and submit your GitHub URL (200 tokens).
3. Your audit begins as soon as submission is confirmed.
Builders want to know their code is safe before they buy. Fair question. Faction Audit Reader is read-only — here is exactly what it can and cannot do, with links so you (or your AI) can verify independently.
Prefer it in writing? An NDA is available on request before we see anything. Either way, access is scoped through GitHub's standard Faction Audit Reader install on the single repo you choose — read-only, revocable anytime.
Faction Audit Reader requests Contents: Read-only only — the minimum GitHub allows for a code review. It cannot push commits, edit files, delete branches, open PRs, change repo settings, or access repos you didn't select.
The audit downloads a working copy to run scanners and analysis, then purges it after your PDF is generated. We don't retain, resell, or republish your source. Faction sells audits, not your IP.
GitHub shows you exactly what Faction Audit Reader can do before you approve it. You don't have to take our word for it — and you can have your own AI double-check:
≈ $20 USD · 100 welcome tokens at signup · top up from $25
Create a Free Account →100 welcome tokens at signup. Sign in, top up, and your audit starts from right here. Already have an account? Sign in.
Have questions first? DM me @mattmurphy.ai. Real answer, usually same day.
That's not a sales line, it's the pattern. Some findings are a prompt and an afternoon. Some are architecture. If your report surfaces work beyond your reach, Faction Group engineers are already familiar with your stack from the audit. No re-discovery, no starting over.
Book a Call