A 13-layer production engineering scan of any AI-built, citizen-coded, or vibe-coded application. We review the full codebase, probe the live deployment, and deliver a modular scope with a Statement of Work ready for signature. The discovery becomes the build plan.
Read-only repo access. Revoked when the report lands. NDA available on request.
90% of vibe-coded apps never ship. Not because the code doesn't work, but because nobody scoped what production actually requires. The Production Discovery replaces guesswork with a 13-layer assessment that produces a modular build plan, a prioritized scope, and a Statement of Work your team can approve and execute against.
The discovery scores your platform across all 13 layers and produces a modular Statement of Work. How many modules, which layers, in what order. No discovery calls, no estimates, no guesswork. The findings are the scope.
Your team built fast with AI tools. The discovery tells you, with specificity, what's production-ready and what isn't, before your customers, your investors, or an incident report does. Third-party validation on letterhead.
Enterprise procurement teams require third-party assessments. Boards ask who reviewed the security. The discovery produces the documentation that satisfies both, with severity ratings and a remediation roadmap.
The discovery becomes the build plan. The 13-Layer Scorecard and prioritized findings translate directly into a modular Statement of Work. Criticals become P1 modules. Warnings become P2 modules. The scope writes itself.
Your teams and citizen coders are building software in-house, and some of it is headed for customers. The discovery tells you which builds are deployment-ready and which need a finishing engagement to carry your name.
The deal is real but the vendor security questionnaire is in your inbox. The discovery produces the documentation procurement expects, and the Statement of Work to close the gaps they'll flag.
Assessment results are a standing requirement for vendor lists at larger customers. $200 and 24 hours gets you the artifact and a clear plan to address anything that isn't passing.
You've built something real. Now you need to know what stands between here and production. The discovery maps the distance and scopes the work to close it.
The same 13-layer framework that runs every Faction engagement and backs the CADE certification for AI-directed engineers. Nothing gets a pass because it wasn't checked.
Scroll to run a sample scan
Every layer receives one of three scores. The scorecard reads in thirty seconds and holds up in a procurement review.
The layer meets production standard. Documented, verified, nothing to action.
The layer works but carries risk at scale. The Statement of Work includes a module to address it.
The layer has a flaw that threatens security, data, or availability. Becomes a P1 module in the Statement of Work. Fix before deployment.
Full scan across all 13 production layers. Codebase review via read-only GitHub access plus live deployment probe.
Security vulnerability analysis. Auth, RLS, injection surfaces, exposed keys, rate limits, dependency CVEs.
Severity-rated findings. Every issue graded Critical, Warning, or Pass with its location in the codebase.
The 13-Layer Scorecard. One page. The document you hand to procurement, the board, or your insurer.
Modular scope and build plan. Critical and Warning findings translated into a prioritized module sequence with estimated hours and timeline.
Statement of Work. The discovery output is a SOW ready for review. Module count, layer assignments, pricing, and timeline. Sign it and work begins.
Five-minute form: repo URL, stack, what the application does, where the report goes.
$200 flat via Stripe. No proposals, no discovery calls, no invoicing cycle.
Your stack is scanned against all 13 layers through read-only GitHub access plus a live deployment probe.
Branded PDF with scorecard, findings, modular scope, and Statement of Work in your inbox within 24 hours.
Faction Audit Reader is a read-only GitHub App. It can view repository contents to run your discovery. It cannot push commits, edit files, delete branches, change settings, or access repos you did not select.
The repo is reviewed for the discovery and purged after the report is generated. Nothing is stored, archived, or reused.
An NDA is available on request before we see anything. For teams with formal vendor requirements, that's standard practice.
Revoke anytime. The moment your report lands, or any moment before it, you remove the collaborator invitation. Two clicks. Access dead. You hold the keys for the entire engagement.
1. Paste your GitHub URL in the form.
2. Pay via Stripe.
3. Done. Discovery begins when payment confirms.
1. Install Faction Audit Reader on that repo only.
2. Complete the intake form with your GitHub URL.
3. Pay via Stripe. Discovery begins when payment confirms.
Secure payment via Stripe. Report delivered as a branded PDF with modular scope and SOW. Re-discoveries available after remediation at the same rate.
Name, email, stack, description, repo URL, live URL. Then Stripe checkout via Tally.
Private repo? Install Faction Audit Reader (read-only) on your repo before you submit. Why it's safe →
tallyFormId in /assets/js/rpa-checkout-config.js.
Loading intake form…
Production Discovery · One-Time · $200 · Secure payment via Stripe. Faction Audit Reader (read-only). Repo purged after report. Revoke access anytime. Code safety FAQ. By paying you agree to our Terms and Refund Policy.
Questions first? support@gofactiongroup.com or Help & Support
The discovery scoped the work. Now choose how Faction delivers it.
Faction engineers work the findings module by module. $8K per 40-hour module, a demo every 10 hours, and an exit re-discovery that verifies every layer passes. Your code stays yours the whole way.
For teams building continuously, the discovery becomes the entry gate to a managed finishing pipeline. Your builds enter the belt, pass entry and exit scans, and ship to production on a cadence. $8K/month minimum, 6-month term.
13 layers. 24 hours. The $200 that scopes everything that comes after.