SERVICES.
Fixed-scope backend, security, and AI engagements — for teams who need a specific problem solved, not a headcount.
API & Backend Security Audit
Find the auth holes before someone else does.
Includes
- Auth & session review — token handling, JWT validation, RBAC/permission checks
- Endpoint review — injection risks, IDOR, mass assignment, input validation
- Data exposure check — sensitive data in responses/logs, secrets in config, CORS
- Dependency scan — packages with known CVEs, exposed debug endpoints
- Rate-limiting check on sensitive endpoints
- Prioritized report (critical → low) with reproduction steps and concrete fixes
- 30-minute walkthrough call
Not included
- Infrastructure / network penetration testing
- Compliance certification (ISO 27001, SOC 2)
- Mobile or client-side app review
- Ongoing monitoring — one-time engagement
Backend Development
Ship the feature, integration, or API your team doesn't have time for.
Includes
- Custom API/backend features built to a defined spec
- Third-party integrations (payments, carriers, auth providers, internal systems)
- Performance and scaling fixes on an existing service
- Code review, tests, and handover documentation
Not included
- Open-ended hourly retainer without a defined deliverable
- Frontend/UI work (backend and API surface only)
AI / RAG Integration
Add search or chat over your own documents — grounded, not hallucinated.
Includes
- Document ingestion pipeline for your existing files (PDFs, records, internal docs)
- Retrieval setup wired into a chat or search interface
- Evaluation pass on real queries before handover
- Handover with minimal ops documentation
Not included
- Fine-tuning custom models
- Ongoing hosting — quoted separately as an optional monthly maintenance fee