Rapid Platform Audit · Read-Only · 200 Tokens

FIND OUT IF YOUR APP IS PRODUCTION-READY. WITHOUT GIVING UP YOUR CODE.

A full 13-layer audit of your platform, delivered in 24 hours, using read-only access you can revoke the moment the report lands. We can see your code. We cannot change it, copy it, or take it anywhere. You get a scored report and prioritized findings. Every finding is matched to a fix skill built for your codebase, ready to load into Claude, Cursor, or whatever agent you build with.

200Tokens≈ $20 USD
13Layers
<2 HrsTypical · 24hr Guarantee
SkillsBuilt For Your Codebase
Get Your Audit Is My Code Safe? See a Sample Report

Read-only GitHub App. Revoke anytime. NDA available on request. Nothing stored after delivery.

YOU BUILT SOMETHING. YOU SHIPPED IT. NOW THE QUESTION YOU CAN'T ANSWER YOURSELF.

Will it survive production traffic? A security scan? A technical due diligence review? You built it with AI tools, it works, users like it. But "it works" and "it's ready" are two different sentences, and you can't grade your own homework.

You're scaling and things are breaking.

Users are showing up and weird stuff is happening. Slow pages, odd errors, things that worked yesterday. You need to know if it's a patch or a foundation problem.

You're fundraising and investors will ask.

Technical due diligence is coming. "Who reviewed your security?" is a question you want to answer with a report, not a shrug.

You vibe-coded it and the foundation might be shaky.

AI got you to a working product fast. It did not tell you what it skipped. Sixty-five percent of vibe-coded apps ship with security issues. You'd rather find yours before someone else does.

HANDING SOMEONE YOUR REPO FEELS RISKY. YOU'RE RIGHT TO THINK ABOUT IT.

Hundreds of builders have DM'd asking for a review of their app. Almost none of them had ever shared their repo with anyone. That hesitation is healthy. Your code is your work, your idea, and maybe your future company. So here is exactly what happens, in plain language.

You install Faction Audit Reader, a read-only GitHub App, on the one repo you choose. Read-only means exactly what it sounds like: it can look at the code. It cannot edit it, delete it, push to it, or change a single character. GitHub enforces this at the platform level.

We review the code, score it across the 13 layers, and generate your report. The moment your report lands, or any moment before, you remove the app from the repo and the access is dead. You hold the keys the entire time — no shared passwords, no personal access tokens, and an NDA is available if you want one.

REVOKE ACCESS ANYTIME

You are never locked in. The moment your report lands, or any moment before, you remove the app from the repo and the access is dead. You hold the keys the entire time.

THE FEARS, NAMED AND ANSWERED.

✕

We don't steal ideas.

We run an engineering firm with a full client pipeline. Our business is finishing software, not launching competitors to yours. An NDA is available if you want it in writing before we see anything.

✕

We don't copy code.

The repo is reviewed for the audit and purged after the report is generated. Nothing is stored, archived, or reused.

✕

We don't fork your repo.

Your repo stays yours, untouched. No forks, no clones left behind, no copies floating around.

✕

We don't touch your code.

Zero write access. We couldn't change anything even if we wanted to. That's what read-only means, and GitHub enforces it, not us.

✕

We don't judge.

Every vibe-coded app has gaps. That's not a verdict on you, it's the nature of how AI builds. The report exists to close the gaps, not to grade you as a person.

WHAT BUILDERS FOUND WHEN THEY FINALLY LOOKED.

These aren't audit customers being polite. These are builders who applied the same 13-layer lens to their own apps and reported back, unprompted.

I've been investigating my architecture and codebase after each video, and I have found hundreds of issues and violations. All of which are fixed right now following your best practices.

@yassine__bn__7 · Hundreds of issues found and fixed

Came across your posts and realized my first app had literally no security checks or balances. The second app is now being hardened and built to scale.

Andy Graham · Australia, solo entrepreneur

This helped. Just saw 17 vulnerabilities. 7 moderate, 10 high. Thanks man.

@_que.ster · 17 vulnerabilities surfaced in one pass

I thought I had the most brilliant setup and locked it down. My friend found my API and in 10 minutes showed me the fail. Blew me away. Very humbling.

@kaydub7897 · The 10-minute wake-up call

Your app has a list like this too. The audit finds it in 24 hours. Read 159+ more builder stories →

NOT A VIBE CHECK. A SCORED, PRIORITIZED, FIXABLE REPORT.

EXECUTIVE SCORECARD

All 13 layers, each scored green, yellow, or red. One page. You know where you stand in thirty seconds.

LAYER-BY-LAYER DEEP DIVE

Every finding: what it is, where it lives in your code, why it matters, and how severe it is.

A SKILL MATCHED TO EVERY FINDING

Every finding maps to a fix skill generated from your code, not a template. Your stack, your gap, your fix. Buy the ones you need, skip the ones you don't.

PRIORITIZED ACTION PLAN

P1, P2, P3. What to fix before you sleep tonight, what to fix this week, what to fix before you scale.

BUILT FOR YOUR AGENT

The report tells your agent what is broken. Each skill tells it exactly how to fix it, structured to load directly into Claude, Cursor, or whatever you build with. A fix written for one specific codebase cannot be written in advance. That is why it works.

WE DON'T CHECK YOUR FRONTEND AND CALL IT A DAY.

01Frontend 02APIs & Backend Logic 03Database & Storage 04Auth & Permissions 05Hosting & Deployment 06Cloud & Compute 07CI/CD & Version Control 08Security & RLS 09Rate Limiting 10Caching & CDN 11Load Balancing & Scaling 12Error Tracking & Logs 13Availability & Recovery

The same 13-layer framework taught inside The Faction. Your report maps to the exact discipline thousands of builders are learning right now.

THIS ASSESSMENT USED TO COST $10,000. NOW IT'S 200 TOKENS.

$10,000 → 200 TOKENS

This is the same assessment we run at the start of every Faction Group commercial engagement. It's how we scope real builds for real clients. A senior engineer would charge $2,000+ for this review. An agency would quote $5,000 and up, after two discovery calls.

AI-directed automation collapsed weeks of senior-engineer review into an automated pipeline that scores all 13 layers in hours. We had a choice: keep the margin or pass it on. We passed it on. An audit is 200 tokens, and you add fix skills only where you actually need them. 200 tokens isn't the discount price. It's the honest price.

A full audit is about $20 USD (200 tokens). Fix skills run ~$10 each; re-runs ~$5.

SIGN UP. AUDIT. FIX. VERIFY. REPEAT.

01

Create Your Account

Email only, magic link, no password. 100 welcome tokens land in your balance the moment you confirm.

02

Top Up Tokens

The $25 Starter bundle plus your welcome tokens covers a full find-fix-verify cycle. Bigger bundles carry a bonus. Stripe checkout, done in a minute.

03

Submit Your Repo

200 tokens. Repo URL required, live URL optional. Private repo? Install Faction Audit Reader first, then submit.

04

Receive Your Scorecard

Most audits land in under two hours, 24 hours guaranteed. Scorecard, findings, and priorities in your dashboard and your inbox. Revoke access anytime.

05

Fix & Verify

Buy the skills you need, 100 tokens each, run them with your agent, then re-run the audit for 50 to prove the fixes landed. That loop is the product.

FOR SOME BUILDERS, NOT ALL.

THIS IS FOR YOU IF

  • You built with AI tools and you're not sure what's actually production-ready
  • You're a technical founder about to fundraise and due diligence is coming
  • You inherited a codebase and need to know what you're standing on
  • You're a Faction Community builder about to go live with real users

THIS ISN'T FOR YOU IF

  • You don't have a codebase yet. Start with the free Vibecoding kit and come back when you've built.
  • You need an organization-level AI readiness assessment. That's a different Faction Group engagement.
  • You want someone to fix everything without you understanding what was wrong. The report teaches. That's the point.

ONE BALANCE. THREE SERVICES.

ServiceTokens≈ USD (base rate)
Full 13-layer audit200~$20
Fix skill (per finding)100~$10
Re-run verification50~$5

New accounts start with 100 free welcome tokens. Bigger bundles improve the rate — full pricing and a worked example on the tokens page.

PUBLIC OR PRIVATE — TWO PATHS.

Same intake form either way. We never ask for your GitHub password, 2FA, or a personal access token. An NDA is available on request. Questions about safety? See Code Safety & Trust.

Public repo

1. Create your account and top up tokens if needed.
2. Paste https://github.com/owner/repo in the intake form.
3. Submit — 200 tokens, audit begins immediately.

Private repo

1. Before you submit: install Faction Audit Reader on that repo only (choose "Only select repositories").
2. Sign in and submit your GitHub URL (200 tokens).
3. Your audit begins as soon as submission is confirmed.

Faction Audit Reader

Faction Audit Reader is a read-only GitHub App. It can view repository contents to run your audit. It cannot push commits, edit files, delete branches, change settings, or access repos you did not select. Verify permissions yourself →

Install Faction Audit Reader →

YOUR REPO STAYS YOURS.

Builders want to know their code is safe before they buy. Fair question. Faction Audit Reader is read-only — here is exactly what it can and cannot do, with links so you (or your AI) can verify independently.

NDA available on request

Prefer it in writing? An NDA is available on request before we see anything. Either way, access is scoped through GitHub's standard Faction Audit Reader install on the single repo you choose — read-only, revocable anytime.

Faction Audit Reader is read-only

Faction Audit Reader requests Contents: Read-only only — the minimum GitHub allows for a code review. It cannot push commits, edit files, delete branches, open PRs, change repo settings, or access repos you didn't select.

We don't keep your code

The audit downloads a working copy to run scanners and analysis, then purges it after your PDF is generated. We don't retain, resell, or republish your source. Faction sells audits, not your IP.

Verify Faction Audit Reader yourself (before you install)

GitHub shows you exactly what Faction Audit Reader can do before you approve it. You don't have to take our word for it — and you can have your own AI double-check:

  1. Open the public app page: github.com/apps/faction-audit-reader — published by faction-team.
  2. Optional: paste that URL (and GitHub's app permissions docs) into ChatGPT, Claude, or your preferred AI and ask it to confirm the app is read-only and limited to repository contents.
  3. Click Install (or use our install link). GitHub's permission screen lists every requested permission before you confirm.
  4. Choose Only select repositories and pick the single repo you'll submit — not your whole account.
  5. After install, review or revoke anytime: GitHub → Settings → Applications → Installed GitHub Apps → Faction Audit Reader → Configure.

TWO FIELDS. THAT'S EVERYTHING.

Private repo? Install Faction Audit Reader (read-only) on your repo before you submit — see GitHub Access and why it's safe. Then sign in, top up if needed, and submit (200 tokens).
Rapid Platform Audit · 200 Tokens
200 Tokens

≈ $20 USD · 100 welcome tokens at signup · top up from $25

Create a Free Account →

100 welcome tokens at signup. Sign in, top up, and your audit starts from right here. Already have an account? Sign in.

Have questions first? DM me @mattmurphy.ai. Real answer, usually same day.

7 OUT OF 10 AUDIT CUSTOMERS FIND WORK THEY CAN'T FINISH ALONE.

That's not a sales line, it's the pattern. Some findings are a prompt and an afternoon. Some are architecture. If your report surfaces work beyond your reach, Faction Group engineers are already familiar with your stack from the audit. No re-discovery, no starting over.

Book a Call

EVERYTHING BUILDERS ASK BEFORE THEY BUY.

How much is 200 tokens in dollars?
At the base rate, $100 buys 1,000 tokens — so one token is $0.10. A full audit (200 tokens) is about $20. A fix skill is 100 tokens (~$10); a re-run is 50 tokens (~$5). Bundle pricing can lower the effective rate; see the tokens page for Starter ($25), Builder, Pro, and Engineering packs.
What do I need to provide?
An account, 200 tokens, and your repo URL. A live URL helps if the app is deployed. For private repos you install Faction Audit Reader (a read-only GitHub App) on the one repo you select before submitting. We never ask for passwords, 2FA, or personal access tokens. That's everything.
Is my code safe?
Yes. Faction Audit Reader requests Contents: Read-only only, so we cannot modify, push, or delete anything — GitHub enforces that, not us. Your code is never stored after the audit, and an NDA is available on request before we see anything.
Is an NDA available?
Yes — an NDA is available on request before we see anything. It's optional: access is already scoped through Faction Audit Reader, a read-only GitHub App installed on the single repo you choose, and revocable anytime.
Can you steal my idea?
We run an engineering firm with a full pipeline of client work. Reviewing your code and building your competitor are not the same business, and we're only in one of them. The NDA is there if you want it in ink.
What does read-only actually mean?
Faction Audit Reader can open and read your files. It cannot change them, delete them, fork the repo, open PRs, or push anything. It's a permission level you approve on GitHub and can revoke under Settings → Applications → Installed GitHub Apps.
What if my code isn't on GitHub?
GitLab and Bitbucket work the same way with read-only access. If it's somewhere else, DM me and we'll figure it out.
Can I get a re-audit after I fix things?
Yes. A re-run is 50 tokens, a quarter of a full audit, because we already know your codebase. Same 13 layers against your updated code so you can watch the score move.
What if I can't fix things myself?
Every finding is matched to a fix skill built for your codebase, and your agent runs it. That handles most findings. For the work beyond that, Faction Group can take it from there, and we already know your stack.
How is this different from an AI Readiness Assessment?
The audit reviews your codebase. A readiness assessment reviews your organization. If you have an app, you want the audit. If you have a company figuring out AI, that's a Faction Group conversation.