Score your app. Out of 100.
The same framework we score paid audits against, published in full and made tickable — all 49 checks, weighted, with the criticality of failing each one. Do it yourself, right here, before you speak to anybody including us. Then treat it as what it is: a baseline we tailor to where you are, never a script we run.
Tick what is already true. Watch the number build.
Every check is here — nothing gated, nothing withheld to make the paid audit look better. Tick only what you have actually verified; a check you assume is fine is a check that fails. Nothing leaves your browser while you do this. How the weighting and the bands work sits behind How scoring works, next to your score.
0 of 49 ticked
Authentication & access control
0/20 ptsSecrets & configuration
0/10 ptsData protection & recovery
0/10 ptsAutomated testing
0/15 ptsDeployment & operations
0/15 ptsPerformance & scale
0/10 ptsPayments & billing
0/10 ptsCode quality & maintainability
0/10 ptsWorking demo, not a product. Putting real users or real data behind it carries risk you have not measured yet.
- Not production-ready0–29
- Major gaps30–49
- Significant work remaining50–69
- Near-ready70–84
- Production-ready85–100
Ticking sends nothing. Your score only reaches us if you fill in the form below. Findings come back in 72 hours, and we can sign an NDA before we see any code.
You scored it. Now let us try to break it.
Self-scoring is honest work, and it has one blind spot: you cannot adversarially test your own assumptions about who can reach what. Send us the score you just produced and an engineer will read it before anyone calls you.
How the score works
Two things make the number mean something: what the bands say about your total, and how the 100 points are spread across categories whose 49 checks carry very different consequences. Both are our published engineering judgement — argue with either and use the list anyway.
What the number means
A score compresses a lot of judgement into one figure, which makes it useful for deciding whether to worry and useless for deciding what to do. Both come out of the same assessment.
- 0–29Not production-ready
- Working demo, not a product. Putting real users or real data behind it carries risk you have not measured yet.
- 30–49Major gaps
- Core function works, but at least one category is missing outright — usually authorization, testing or deployment.
- 50–69Significant work remaining
- The shape of a production system is there. The work left is real, but it is scoped and finite.
- 70–84Near-ready
- Launchable with known, accepted risks and a plan to close them. Most rescues finish in this band.
- 85–100Production-ready
- Nothing critical outstanding. Remaining items are improvements rather than exposures.
Where the weight and the danger sit
Bar length is the category's share of the 100 points; the segments are how its checks split across the four criticality levels. Access control is longest because it is the only category where one failure exposes every user at once — and it is mostly red, because those failures are the kind that block a launch outright. Weight tells you where the points are; criticality tells you what one failure does to you.
- Severe11
- A single failure exposes data, money or credentials. Blocks launch outright.
- High19
- Fails loudly in production — an incident you will feel, on a day you do not choose.
- Medium11
- Degrades the product or slows recovery. Fix on a schedule, before it compounds.
- Important8
- Costs nothing today. Decides how expensive every future change will be.
A baseline we tailor to you. Never a script we run.
This list is where an assessment starts, not what it is. Before anything gets scored, the checklist itself is rebuilt around your situation — categories that do not apply come out, obligations you carry go in, and criticalities shift with what your product actually holds. What to check first depends on which tool built the app; what to check hardest depends on everything below.
Your stage
Pre-launch, a severe finding is a task on a list. With live users, the same finding is an incident and possibly a disclosure. The stage you are at changes which items block and which can wait.
Your stack & platform
A design-led generator leaves a different gap than a full-stack one. What gets checked first — and how deep — follows from what built the application, not from a fixed order.
Your data sensitivity
Health, financial or children's data pulls checks up a level and adds ones this list does not carry. An app holding public content is scored on a genuinely different bar.
Your obligations
A compliance regime, an enterprise customer's security questionnaire, an investor's diligence checklist — whatever you have already promised gets layered onto the baseline before scoring starts.
From read access to shipped fixes.
Score it yourself honestly first — a check only passes if you have verified it, and our guide to triaging a production failure is free if something is already on fire. When you want it done adversarially, delivered and closed, this is the path our audit runs — each stage ends with something you hold, and every stage is priced before it starts.
- 01
Get access
Read-only · day oneWhat happensYou grant read access to the repository and infrastructure — under NDA if you want one. Nothing is changed, nothing is deployed. This is also where the checklist gets tailored: categories that do not apply to you come out, obligations you carry go in.
What you walk away withA confirmed scope — exactly what will be assessed, what is excluded and why, before any clock starts.
- 02
Audit
Findings in 72 hoursWhat happensEngineers assess your application against the tailored checklist adversarially — attempting the access that should be denied, reading the deployment configuration, testing the restore. Evidence, not opinion.
What you walk away withA scored report where every finding carries its criticality, the evidence behind it, and the specific fix.
- 03
Prioritise
Ranked with youWhat happensFindings are ranked against your reality, with you in the room: severe items block launch, high items get dated, medium and important items get scheduled where they stop compounding. Your launch date and risk appetite set the order — not our template.
What you walk away withA remediation plan with milestones that any engineering team could execute — including one that is not us.
- 04
Ship the fixes
Typically 2–6 weeksWhat happensFixes land in criticality order, milestone by milestone — tests and the deployment pipeline go in early so every later fix ships safely. Each milestone is independently verifiable against the original finding.
What you walk away withClosed findings, a re-scored application, and full handover — code, infrastructure and documentation are yours.
Questions about the framework.
QWhat score is safe to launch on?
QIs this the same checklist you use in paid audits?
QWhy is authentication and access control weighted highest?
QHow are the criticality levels assigned?
QIs the checklist applied the same way to every application?
QDo you need access to my code to score it?
QWhat happens after I send my score?
QCan I run this myself?
QWhat if a category does not apply to us?
QHow long does a full assessment take?
Send us the repository. We'll tell you what's missing.
Fixed price, 72 hours to findings, and a report you can act on with or without us. Nothing is committed until you have read it.
- Give us a call+1 (424) 283 4679Straight to an engineer, not a switchboard.Reach out
- WhatsAppStart a chatFastest if you are in a different timezone to us.Reach out
- Emailhello@indianic.comSend the repo link and anything you already suspect.Reach out
- Get my scorecardFindings in 72 hoursThe audit, scored against every check on this page.Start the audit
NDA signed before you send anything · read-only access, revoked when the report lands · our copy deleted on delivery.