Fixed-price sprint
Your happy path is green. That is not the question.
A passing test suite proves your system accepts what it should accept. It says nothing about whether it refuses what it must refuse — and that is the half that costs money when it is missing, because a wrongly accepted request looks exactly like a correct one in every log you have.
In 5 working days we build the other half: a corpus of input that must fail, one case per rule, each with its expected rejection recorded next to it — and a test that turns red the moment one of them is accepted.
Who this is for
Teams running AI agents, MCP servers or business-critical API integrations — where a wrong acceptance moves money, releases data, or files something with a regulator.
The six axes
The matrix is bounded before we start. We agree which axes are in scope and how many rules each one covers; nothing is open-ended.
- Identity
- A token that is valid, unexpired and signed by the right issuer — but belongs to someone else.
- Scope
- A caller with real credentials reaching an operation those credentials do not cover.
- Amount
- A quantity, price or total that is internally inconsistent while every field is present.
- Audience
- A token minted for a different service, replayed against yours because nobody checks the audience.
- Replay
- The same signed request delivered twice. Once is a payment; twice is a refund conversation.
- State
- An operation that is legal in the abstract and illegal right now — cancel after settle, refund after refund.
What you get, within 5 working days
- A reproducible corpus of failing input, one case per agreed rule, with the expected rejection recorded per case. It is yours and it runs in your CI.
- A test harness that fails loudly when a case that should be rejected is accepted, so a future refactor cannot quietly reopen the hole.
- A written findings report: which rules your system does not enforce today, with the evidence per rule.
- A priority order, separating what touches money or compliance from what is cosmetic.
What this is not
- Not a certification, and not a conformity statement.
- Not a guarantee of compliance, of an audit outcome, or of any regulator’s opinion.
- Not unlimited fixes. We deliver the evidence and the tests; changing your code is a separate conversation.
- Not a penetration test. No active attack, no production access, and no third-party personal data.
Price
€1,750 fixed, excluding VAT, for the scope agreed in the fit-check. Not an hourly rate, and not an estimate that grows.
Start with a fit-check
A short written exchange, free, to establish whether this is the right thing for your system at all. If it is not, we will say so — that answer is worth more to both of us than a badly scoped sprint.
Writes to sprint@inbound.jithox.com, which a person reads. Please do not include credentials, tokens or customer data in a first message — describe the shape of the problem instead.
Jithox — Victor Charlier, Belgium. Reference NPA-2608.