notra·
Use case · pre-launch

The days-before-launch audit

The launch is on the calendar, the checklist is mostly done, and security is the item nobody has an answer for. Here is the week that fixes it: a free scorecard on Monday, a verified $149 audit on Tuesday, fixes on Wednesday, a clean re-run by Friday.

The launch-week timeline

T-minus 7 · Scorecard

Run the free scorecard: about 16 passive checks in roughly a minute — TLS, headers, exposed-file signals, mail posture. It tells you whether a real audit is worth buying, costs nothing, and touches nothing.

T-minus 5 · Deep Audit

One $149 credit buys the deep run: roughly 360 requests over about 60 minutes against your live app, targeting up to 20 verified findings — each with the request and response that proved it.

T-minus 2 · Fix & re-run

Fix from the plain-English list, then buy another credit — same flat $149 — and re-attack the same surface. The fix gets verified the same way the flaw did.

What lands in your lap on Tuesday

Verified findings, with exhibits

Auth and session flaws, injection-class sinks (harmless PoCs), exposed files and secrets, vulnerable component versions, missing hardening — every one carrying its own proof, nothing padded with low-confidence maybes.

A fix list in plain English

Each finding says what's broken, why it matters, and the concrete fix — written for the engineer who has to ship it, not for a security vocabulary quiz.

An honest empty set

If nothing could be verified, the report says exactly that, with the scope it covered. That is a real launch-day answer — better than the silence a consultancy quote leaves you in.

After launch day

Keep watching

Monitor re-scans daily from $49/domain/month and emails you on every change — the post-launch hotfix that introduces a regression doesn't get to hide.

Gate the next release

Wire the CI/CD gate into your pipeline so the next deploy is checked before it ships, not after.

Share with customers

The manifest-pinned report is evidence you can attach when the first enterprise prospect sends their questionnaire.

Compare the one-time audit against a manual pentest before budgeting, and check pricing if you want the audit plus monitoring from day one.

Launch-week questions

How fast is all of this, really?

The scorecard is about a minute. After the agent starts, the Deep Audit report lands in roughly 35–60 minutes — the run is about 360 requests over about 60 minutes, and you can watch it live while it happens. No scoping call, no queue.

Our launch is tomorrow. Is it too late?

Not for the scorecard, and probably not for the audit. A verified report in an hour beats a consultancy's three-week timeline in every scenario where tomorrow is real — and if it flags something you can't fix in time, you at least know the exposure and can decide with open eyes.

Will the audit slow down or break the site?

The probes are read-first and rate-limited, and injection proofs are harmless PoCs — designed to prove a flaw fires without mutating your data. The run is manifest-pinned, so every request it made is auditable afterward.

Monday's task, today.

The free scorecard costs nothing and takes a minute. Everything else in launch week follows from what it finds.

Get your free scorecard

Related: pricing for the credit model, the sample verified report to preview Tuesday's deliverable, and early access if your launch is big enough to want the founder onboarding it.