Why is the assessment free?
The scope is limited to public, unauthenticated evidence. That keeps the work bounded while still giving you a useful first view across the public app. If a finding needs deeper access, we explain why. The PDF stands on its own, and any later work is a separate decision.
What happens to the details I submit?
We use your name and company to manage the request, the URL to review the public app and your email to send the result and one possible follow up about the findings. We do not send these details or your concern text to analytics or advertising platforms. If Google supplied an advertising click identifier, we may store it with the request so we can measure the campaign. We do not add you to a marketing list.
Is it safe for a live application?
We make read only, non destructive requests to public pages and files. We do not sign in, enter data, submit forms, change data or attempt to exploit a finding.
Can you review pages behind a login?
Not as part of this assessment. The codebase, logged in workflows, authenticated APIs and private infrastructure stay outside scope. We do not ask for credentials or treat those areas as checked.
Do I need to buy anything after the assessment?
No. The free PDF stands on its own. If you want us to inspect code, authenticated workflows or private infrastructure, we can scope a separate paid review after delivery. You decide whether that work happens.
Who performs the review?
A senior VibeZero engineer runs the external tools, reviews the public app at desktop and mobile widths, checks the evidence and writes the PDF. The result is not an unreviewed scanner export.
Does the app need to have been built with AI?
No. The same public checks are useful for conventionally built apps. The offer is aimed at teams shipping quickly with tools such as Cursor, Lovable, Replit, Bolt, v0, Base44 or Claude Code, but the build method does not determine eligibility.
What if the URL cannot be reached?
We will email you and ask for a working public URL. The 24 hour delivery period starts once the page opens without a login, password or private preview token.
Can I go straight to a paid app audit?
Yes. If you already need codebase, logged in workflow or private infrastructure testing, you can ask for a paid app audit without completing the free assessment first.
Does 24 hours mean calendar hours?
Yes. The PDF is due within 24 hours of a successful request with a working public URL. If we cannot honour that window, we will pause new requests rather than promise a delivery time we cannot meet.
Is this a penetration test or certification?
No. It is an external readiness assessment of the unauthenticated public surface. It does not certify the app, codebase, logged in workflows or private infrastructure.