Offer 02
The AI project stalled. First find out what is actually there.
Five working days, fixed price, on the code that exists. You get a dependency and security scan, an architecture read, tests that capture what the system currently does, and a written salvage-or-rebuild verdict with the reasoning behind it. We will tell you if it should be thrown away.
- Price
- €2,000–4,000 discovery
- Duration
- 5 working days
- repository + manifests
- secrets + dependency scan
- architecture read
- characterisation tests
- salvage-or-rebuild verdict
- rescue, quoted from the verdict
- monthly ownership
◆ marks a point where a person decides. Nothing passes it on its own.
What you get
What the five days produce
All four land as documents you own, whether or not you hire us for the rescue.
- Dependency and security scan
- Hardcoded secrets, credentials in commit history, abandoned packages, and packages that were hallucinated rather than chosen. This is the fastest part and it is usually the loudest.
- Architecture read
- What the system does, what it was supposed to do, where those two diverge, and which parts a language model wrote without anyone reviewing.
- Characterisation tests
- Tests that pin down current behaviour — including the wrong behaviour. Without them nobody can change the code safely, which is usually why it stopped being changed.
- Salvage or rebuild, with reasoning
- A verdict, the cost of each path, and what we would do first. An audit that always recommends more work is not worth paying for.
The terms
The commercial terms
- Discovery
- €2,000–4,000 fixed. 5 working days on the code that exists.
- Credited against the rescue
- In full. Commission the rescue and the discovery fee comes off its price. If the verdict is to throw the code away, you keep the report and owe nothing further.
- Rescue
- Scoped and quoted from the discovery. Stabilise, add evaluations and observability, document. Never quoted before we have seen the code.
- Maintain
- €800–2,000 per month. Ongoing ownership, monitoring and a cost cap.
- What we need
- Read access to the repository and a description of what it was supposed to do. Production access only if the audit needs it, and only read-only.
- Excludes
- Fixing anything during the discovery week. This is a read, not a repair — mixing the two is how the estimate stops being trustworthy.
- Cross-border
- One clean price. 0% Thai VAT on export of services; nothing for you to withhold.
The sequence
How the week goes
The order is deliberate. Cheap and alarming findings come first, so you can stop the audit early if what we find is already decisive.
- 01
Access and inventory
Repository, dependency manifests, deployment configuration, and whatever documentation survives. Half a day.
- 02
Dependency and security scan
Secrets, credentials in history, abandoned and hallucinated packages, unpinned versions, known vulnerabilities.
- 03
Architecture read
How data moves, where the language model is doing work that should be deterministic, and which failure modes have no handling at all.
- 04
Characterisation tests
We capture what the system does today in executable form, so that whoever changes it next can tell whether they broke it.
- 05
Salvage-or-rebuild verdict
The written recommendation, the reasoning, and a cost for each path. Delivered as a document, walked through on a call.
- 06
Your decision ◆ your call
Rescue, rebuild, or stop. If the honest answer is that it should be thrown away, that is what the report says and the audit has still paid for itself.
Fit
Who this is for
- A pilot that was funded, half-built and then went quiet.
- An AI or automation workflow that works most of the time and nobody can say why it fails the rest of the time.
- A codebase whose author has left, or whose agency shut down.
- A system written largely by an AI assistant, now maintained by someone who did not write it.
Who it is not for
- A project nobody admits is in trouble. The trigger has to be an acknowledged failure — a stalled build, a departed developer, a vendor that disappeared. Otherwise the audit lands on a defensive team and changes nothing.
- A rescue quote without discovery. We will not fixed-price a codebase we have not read, and you should not accept one from anybody who will.
Objections
The questions we get asked
Why pay for discovery instead of just getting a fix quote?
Because a fix quote on an unread codebase is a guess, and the guess is always wrong in the same direction. Five fixed days on the actual code turns the rescue into a scoped piece of work, for you and for us — and the fee comes off the rescue, so it is the first week of the job rather than a fee on top of it. It is also the cheapest way to discover that the answer is "rebuild".
What if you tell us to throw it away?
Then that is the report, with the reasoning and the cost of each path, and you owe nothing beyond the five days. That outcome is the reason this is worth buying: a review that can only ever recommend more work is a sales call with an invoice attached.
Our developer says it is fine, it just needs a bit more time.
Then this is not for you yet, and we would rather say so. This offer works when the failure is already acknowledged. If it is contested, an outside audit lands as an accusation and nothing changes.
Do you need access to production and to our data?
Read access to the repository is the requirement. Production access only if the audit genuinely needs it, read-only, and scoped to what we ask for in writing. We work against zero-data-retention APIs and we do not train on anything you give us.
We do not want to end up with another system nobody maintains.
That is what stage three is for, and it is the part of this offer we most want you to buy: monthly ownership, monitoring and a cost cap at €800–2,000. A rescue without an owner reproduces the problem you are calling us about.
How do we know you can maintain an AI system properly?
We run our own company on agents, with evaluation runs, approval gates and a full action log. Ask on the call and we will open it.
Tell us what stopped.
Thirty minutes, no charge. What was it supposed to do, who built it, and when did it go quiet. If an audit is the wrong next step we will say so.