Terms

What you get, what you are responsible for, and what this assessment is not. Written to be read rather than to be survived.

The service

A scan, and a person's opinion of it

We scan a repository you connect against 28 production-readiness checks, and a senior engineer writes an assessment of the results. The free tier covers one repository and returns your three highest-priority findings and a readiness score. The full read is $750 and covers one application, which may be several repositories: all 28 checks, the engineer's priority list, a stack risk analysis, a skills assessment, an enterprise readiness track, delivery within 48 hours, and a 30-minute call. The read covers that application for 90 days.

Remediation — us fixing what the read found — is quoted separately after the read.

Scope of assessment

An opinion, not a certificate

This is an assessment, not a certification, not a penetration test, and not a guarantee. It reports what the checks found and what an engineer thinks about it on the day they looked. Passing every check does not mean your application is secure, and we do not represent that it does.

The catalogue assesses JavaScript and TypeScript applications — web, React Native and Expo — Python services, native iOS apps written in Swift, and .NET and ASP.NET Core. Coverage is not the same for each. A web application is what the catalogue was written for; a mobile app, whether Expo or native, answers most of those plus two that only it can fail, and four that ask about API endpoints and response headers cannot apply to it at all; a Python service answers the checks our rules can read and leaves the rest to the engineer.

A report says which checks did not apply to your application and why, so the difference is on the page rather than in this paragraph. A repository outside all of that — Go, Kotlin, Ruby, PHP, Rust, C — will answer very few checks, and we warn before anyone is billed for a report that would mostly say "awaiting review".

Your side

You must be allowed to show us the code

By connecting a repository you confirm you are entitled to grant read access to it. We cannot tell from a GitHub installation whether the person installing owns the code, and we rely on you.

You are responsible for acting on the findings, or not. We tell you what we would fix first; we do not fix it unless you buy a remediation sprint.

Payment

One-time, before the read

The full read is $750 USD, charged once through Stripe. It entitles you to a read of one application, and it expires 90 days after purchase. Ninety days covers a remediation sprint and the re-scan that proves it worked; after that a new read is a new purchase.

If we cannot deliver a read — a scan that will not complete, a repository outside scope, our own failure — you are refunded in full. If you have had the read and disagree with it, tell us and we will talk; a refund at that point is a conversation rather than a rule.

Liability

What we are responsible for

We are responsible for doing the assessment carefully and for handling your code the way the security page says we do.

We are not responsible for what happens to your application. A finding we missed, a risk outside the catalogue, or a breach that follows a clean report is not something this assessment insures against — it is an opinion about production readiness, and it says so on every report.

Ending it

One click, no conversation

Uninstall the GitHub App and we stop reading anything, immediately, without talking to us. Reports already delivered remain yours. Ask and we delete what we hold.

Law

Ontario, Canada

Deop Inc. is incorporated in Ontario and these terms are governed by the laws of Ontario and Canada.

Contact

Who to write to

Deop Inc., Vaughan, Ontario, Canada — our contact form. A person reads that address; it is the same one that answers questions about a report.