Skip to content

Fixed-price sprint

Your happy path is green. That is not the question.

A passing test suite proves your system accepts what it should accept. It says nothing about whether it refuses what it must refuse — and that is the half that costs money when it is missing, because a wrongly accepted request looks exactly like a correct one in every log you have.

In 5 working days we build the other half: a corpus of input that must fail, one case per rule, each with its expected rejection recorded next to it — and a test that turns red the moment one of them is accepted.

Who this is for

Teams running AI agents, MCP servers or business-critical API integrations — where a wrong acceptance moves money, releases data, or files something with a regulator.

The six axes

The matrix is bounded before we start. We agree which axes are in scope and how many rules each one covers; nothing is open-ended.

Identity
A token that is valid, unexpired and signed by the right issuer — but belongs to someone else.
Scope
A caller with real credentials reaching an operation those credentials do not cover.
Amount
A quantity, price or total that is internally inconsistent while every field is present.
Audience
A token minted for a different service, replayed against yours because nobody checks the audience.
Replay
The same signed request delivered twice. Once is a payment; twice is a refund conversation.
State
An operation that is legal in the abstract and illegal right now — cancel after settle, refund after refund.

What you get, within 5 working days

  • A reproducible corpus of failing input, one case per agreed rule, with the expected rejection recorded per case. It is yours and it runs in your CI.
  • A test harness that fails loudly when a case that should be rejected is accepted, so a future refactor cannot quietly reopen the hole.
  • A written findings report: which rules your system does not enforce today, with the evidence per rule.
  • A priority order, separating what touches money or compliance from what is cosmetic.

What this is not

  • Not a certification, and not a conformity statement.
  • Not a guarantee of compliance, of an audit outcome, or of any regulator’s opinion.
  • Not unlimited fixes. We deliver the evidence and the tests; changing your code is a separate conversation.
  • Not a penetration test. No active attack, no production access, and no third-party personal data.

Price

1,750 fixed, excluding VAT, for the scope agreed in the fit-check. Not an hourly rate, and not an estimate that grows.

Start with a fit-check

A short written exchange, free, to establish whether this is the right thing for your system at all. If it is not, we will say so — that answer is worth more to both of us than a badly scoped sprint.

Request a fit-check

Writes to sprint@inbound.jithox.com, which a person reads. Please do not include credentials, tokens or customer data in a first message — describe the shape of the problem instead.

Jithox — Victor Charlier, Belgium. Reference NPA-2608.