Scope one real boundary
Select one product and agree the code, artifact, live target, authorization, and business context that make the evaluation credible.
Operations is normally $500 per month. Cohort companies pay $2,000 upfront for the first year, or $166.67 per month effectively. That includes a founder-assisted initial assessment and report, the Operations platform for 12 months, and three founder-assisted rescans during the year.
Choose one authorized product boundary, investigate it, challenge the findings, and produce the first report.
Keep findings, remediation, reports, schedules, integrations, and evidence in one operating record.
Use three founder-assisted rescans plus additional self-service runs within the Operations limits.
The initial scan establishes the baseline. The Operations subscription lets the team remediate, rescan, refresh the report, and keep the evidence current through the year.
Select one product and agree the code, artifact, live target, authorization, and business context that make the evaluation credible.
Investigate the product with deterministic candidates and AI agents, then preserve the source, reasoning, evidence, and project history.
Use separate adversarial review, proof, and human disposition so weak results do not quietly become engineering work.
Have your designated technical reviewer distinguish newly discovered, valid results from known issues, rejected claims, and low-value observations.
Use focused retests and up to three founder-assisted rescan cycles to verify remediation and identify regressions.
Refresh the penetration test report as the product and findings change instead of treating the initial PDF as the end of the work.
An audit, customer review, launch, or security program calls for testing and current application-security evidence.
An engineering leader can authorize one real product boundary and serve as the designated technical reviewer.
The team wants a validated result and report, not the largest possible alert count.
One authorized repository, release, application, or API boundary that matters to the business.
One technical reviewer who can evaluate the findings and record the outcome.
One current deadline or security trigger that gives the assessment a clear purpose.
A coding agent can find and fix real bugs. The commercial question is whether your team also wants to build the authorization, skeptical review, human decision trail, remediation workflow, retesting, and reporting around every result.
| What the team needs | Coding agent or one-off prompt | ZeroQuarry | Build it internally |
|---|---|---|---|
| Primary job | Explore, explain, or change code in a developer session. | Run an authorized finding-to-fix security lifecycle. | Own and maintain a custom security platform. |
| Skeptical review | Depends on the prompt and context the operator assembles. | Separate investigator and adversarial-review roles, followed by human disposition. | Design, evaluate, and maintain the agent chain and quality bar. |
| Decision record | Usually a chat, patch, or ad hoc artifact. | Traceable evidence, confidence, status, rationale, remediation, and retest history. | Build the data model, controls, integrations, and reporting. |
| Engineering handoff | Suggest or implement a code change. | Route accepted work into issues or controlled patch proposals, then retest the original risk. | Connect every repository, approval path, ticketing system, and CI policy. |
| Customer or audit use | A useful input, but not a durable security operating record by itself. | A current report plus the evidence and human decisions behind it. | Create and govern your own evidence package and review process. |
| Best fit | A developer investigating or fixing a specific concern. | A software team under security pressure before dedicated AppSec-platform headcount. | A well-funded security team that wants platform engineering to be a core capability. |
The offer makes this a falsifiable purchase decision: the written success test is whether the assessment produces at least one previously unknown, valid security result worth recording.
The initial assessment has a written success test. The rest of the year is for remediation, changed-code review, rescans, and current evidence.
Agree the target, authorization, known findings, report audience, evidence requirements, technical reviewer, model funding, and token cap.
Run the assessment, inspect the attack-surface plan, and pressure-test findings through separate adversarial review.
Record which results are new and valid, assemble the first report, and apply the guarantee. A refund ends the Operations subscription.
Route remediation, run additional self-service reviews, and keep the decision and evidence history attached to the product.
Use up to three founder-assisted rescans and report refreshes during the subscription term.
ZeroQuarry will help scope the product, operate the initial assessment, investigate failures, pressure-test claims, produce the first report, and assist with three rescans and report refreshes during the year.
Participating teams provide an authorized target, disclose known findings at kickoff, name an accountable technical reviewer, fund model tokens, and record direct decisions about what was useful, wrong, novel, or commercially valuable. Public attribution or a testimonial is never required.
The scope and success test are agreed in writing before payment, so the guarantee does not depend on an undefined idea of “interesting.”
At the initial-assessment review, if the designated technical reviewer cannot identify at least one previously unknown, valid security issue or materially new security-relevant insight worth recording, ZeroQuarry reimburses the entire $2,000 first-year Operations fee. Findings disclosed as known at kickoff do not satisfy the guarantee. A refund ends the Operations subscription.
Model-token costs are paid directly through your provider key or under a written hosted-usage cap and are not reimbursed. Testing that cannot complete because access, authorization, or required review participation was withdrawn is handled under the written order form rather than the outcome guarantee.
The cohort includes 12 months of the Operations package, one founder-assisted initial assessment and report, and up to three founder-assisted rescans and report refreshes. Teams may also run additional self-service scans within the Operations plan limits. Model usage is separate.
The cohort price applies to the first 12-month term only. There is no automatic renewal under the cohort order form. Any renewal is agreed separately at the price and scope then offered.
Yes. The report records the tested scope, methodology, findings, evidence, decisions, remediation, and retest status needed for security and compliance review. Any organization-specific report requirements are captured during scoping.
One written, authorized product boundary agreed before payment: a repository or coherent codebase, a release artifact, or an application/API target. Scope, access, model choice, token budget, success test, and report audience are recorded before testing starts.
This is an annual Operations subscription, not a one-off scan. The $2,000 first-year price is paid upfront and includes the founder-assisted assessment and rescan support.
$6,000 over 12 months when purchased monthly. The standard annual Operations price is $4,800.
$166.67 per month effectively. Save $2,800 against standard annual billing and $4,000 against the monthly-list equivalent.
One founder-assisted assessment and report, plus three founder-assisted rescans and report refreshes during the 12-month term.
Model usage is separate. Bring provider keys or agree a hosted-usage cap. The cohort order form does not auto-renew; any second-year subscription is agreed separately. If the initial assessment produces no qualifying result and the $2,000 is refunded, Operations access ends.
Shane will review your request personally and reply to arrange a short scoping call.
Pay $2,000 upfront for 12 months of Operations, an initial founder-assisted assessment, and three founder-assisted rescans. If the initial assessment produces no qualifying result, the $2,000 comes back and the subscription ends.