Founding cohort ยท three paid slots

A manual launch-risk review for one AI-built SaaS journey

I am testing a smaller CodeVetta review for founders and agencies shipping now. You get up to five code-backed launch blockers, a SHIP or HOLD verdict, and a fix plan for one primary journey.

No public checkout. I screen the project by email before sharing the private payment link. No calls.

Good fit

The app and launch must be narrow enough

  • You are a business founder or agency with an AI-built SaaS launch or client handoff in the last 14 days or next 14 days.
  • The review covers one repo, one deployed or staging app, and one primary journey.
  • The app has authentication plus payments, teams or tenancy, private data, webhooks, or Supabase.
  • You can provide stable source and test access without sending secrets in the fit screen.

Manual review, not scanner output

What I deliver

  • Up to five launch blockers tied to code, configuration, or observed app behavior.
  • A SHIP or HOLD verdict for the named journey and stable commit/deploy.
  • A prioritized fix plan, with the highest-risk work first.
  • One asynchronous recheck, submitted in one batch within seven days.

The free scanner is automated triage from public HTTP responses. This paid service is a manual review of the agreed source, app, and journey. Neither proves that an app is secure.

Async fit screen

Send only these five answers

This form opens a draft in your email app. It does not send or store anything on the website. I reply by email if the project fits, then share the terms and private payment link.

Do not include repo access, credentials, secrets, authorization documents, private data, or production access. Those do not belong in this form or an email.

Must be within 14 days before or after today.

Framework, backend, database, and hosting. No URLs or access details.

Describe the user actions and expected outcome, not private data.

No calls. Opening the draft does not reserve a slot or accept payment.

Offer terms

What starts the clock

The 72-hour delivery clock starts only after settled payment, written acceptance of these terms, a complete intake, a named stable commit and deploy, and working access. The last completed condition starts the clock.

Scope and time cap

The review covers one repo, one deployed or staging app, and one primary journey. The total provider-time cap is four hours, including the recheck. I stop when that cap is reached even if fewer than five blockers are reported.

Recheck

One asynchronous recheck is included. Submit all fixes for recheck in one batch within seven calendar days after delivery. Unused recheck time expires after that period and is not transferable.

Customer-caused pause

Broken access, a changed commit or deploy, missing intake information, or a requested scope change can pause delivery. I document the reason and resume the clock after the issue is corrected.

No security guarantee

The review is a limited professional opinion on the named code and journey at that point in time. It is not a penetration test, compliance audit, certification, or guarantee that the app is secure or free of defects.

Excluded work

The offer excludes penetration testing; compliance or certification work; destructive or production exploitation; load or denial-of-service testing; social engineering; production customer-data extraction; remediation implementation; native mobile apps; broad infrastructure or cloud review; multi-repo or broad architecture work; unrelated journeys; and any promise that all security issues will be found.

Access and handling

Use temporary read-only repo access, staging or test accounts, test-mode payments or fixtures, sample data, and least privilege where practical. Never send secrets by email or through this public form. Do not provide production customer data for this review.

I use non-public material only to deliver the review. Before sending customer content to an AI provider, I will name the provider, account type, and relevant retention and data handling in writing and obtain the customer's written acceptance. Without that acceptance, I will not send customer content to that provider.

I delete local source, credentials, and working notes within seven days after the recheck is completed or expires. I remove the delivered memo from active storage 30 days later and from backups within 90 days. I retain only payment, accepted-terms, and cohort records required by law, without source, secrets, or customer app data.

Refunds

A customer who cancels before the delivery clock starts receives a full refund. A full refund also applies if CodeVetta screens the project out after payment, accepts a fourth payment, or misses the delivery clock other than during a documented customer-caused pause. After the clock starts, the fee is otherwise non-refundable.

Liability

These terms are subject to applicable law. Where legally permitted, total liability arising from this service is limited to the US$750 paid, and MotionObj is not liable for indirect, incidental, special, or consequential loss. Nothing excludes or limits liability that cannot lawfully be excluded or limited.

The contracting seller and service provider is MotionObj, a Singapore sole proprietorship owned by Yar Hwee Boon. CodeVetta is the service brand. The fee is US$750 and no GST is added because MotionObj is not GST-registered.

The explanations on this page are not legal advice. Written acceptance and payment apply to this founding-cohort engagement only.