What you get, what you are responsible for, and what this assessment is not. Written to be read rather than to be survived.
We scan a repository you connect against 28 production-readiness checks, and a senior engineer writes an assessment of the results. The free tier covers one repository and returns your three highest-priority findings and a readiness score. The full read is $750 and covers one application, which may be several repositories: all 28 checks, the engineer's priority list, a stack risk analysis, a skills assessment, an enterprise readiness track, delivery within 48 hours, and a 30-minute call. The read covers that application for 90 days.
Remediation — us fixing what the read found — is quoted separately after the read.
This is an assessment, not a certification, not a penetration test, and not a guarantee. It reports what the checks found and what an engineer thinks about it on the day they looked. Passing every check does not mean your application is secure, and we do not represent that it does.
The catalogue assesses JavaScript and TypeScript applications — web, React Native and Expo — Python services, native iOS apps written in Swift, and .NET and ASP.NET Core. Coverage is not the same for each. A web application is what the catalogue was written for; a mobile app, whether Expo or native, answers most of those plus two that only it can fail, and four that ask about API endpoints and response headers cannot apply to it at all; a Python service answers the checks our rules can read and leaves the rest to the engineer.
A report says which checks did not apply to your application and why, so the difference is on the page rather than in this paragraph. A repository outside all of that — Go, Kotlin, Ruby, PHP, Rust, C — will answer very few checks, and we warn before anyone is billed for a report that would mostly say "awaiting review".
By connecting a repository you confirm you are entitled to grant read access to it. We cannot tell from a GitHub installation whether the person installing owns the code, and we rely on you.
You are responsible for acting on the findings, or not. We tell you what we would fix first; we do not fix it unless you buy a remediation sprint.
The full read is $750 USD, charged once through Stripe. It entitles you to a read of one application, and it expires 90 days after purchase. Ninety days covers a remediation sprint and the re-scan that proves it worked; after that a new read is a new purchase.
If we cannot deliver a read — a scan that will not complete, a repository outside scope, our own failure — you are refunded in full. If you have had the read and disagree with it, tell us and we will talk; a refund at that point is a conversation rather than a rule.
We are responsible for doing the assessment carefully and for handling your code the way the security page says we do.
We are not responsible for what happens to your application. A finding we missed, a risk outside the catalogue, or a breach that follows a clean report is not something this assessment insures against — it is an opinion about production readiness, and it says so on every report.
Uninstall the GitHub App and we stop reading anything, immediately, without talking to us. Reports already delivered remain yours. Ask and we delete what we hold.
Deop Inc. is incorporated in Ontario and these terms are governed by the laws of Ontario and Canada.
Deop Inc., Vaughan, Ontario, Canada — our contact form. A person reads that address; it is the same one that answers questions about a report.