Decision depth

Buy the smallest amount of evidence that can change the decision.

The tiers are not “more safety for more money.” They answer different owner questions with different evidence ceilings. Choose the cheapest scope that can resolve the uncertainty you actually have.

Qualification
Free
20 minutes

Scope / Authority Triage

Use when the first unknown is whether the workflow is even a useful audit target. We isolate the external action, the authority owner and the staging/test boundary.

Evidence ceiling
  • 1 critical action identified
  • Authority owner identified
  • Staging/test fit check
Not purchased
  • No tested finding
  • No written security conclusion
  • No deep evidence review
Book a free 20-minute triage Send a short scope →Prepare triage brief →
Narrow decision
$1,500
fixed

Entry Audit

Use when one suspected failure controls the decision. We test one action chain and one primary hypothesis to determine whether it is reproducible and worth repairing.

Evidence ceiling
  • 1 critical action chain
  • 1 primary failure hypothesis
  • Bounded reproduction
  • Concise finding memo
Not purchased
  • No full Authority Ledger / Evidence Contract
  • No multi-scenario failure plan
  • No included retest
Open Entry Audit Prepare Entry Audit scope →See sample report →
How the work works

How do you get access?

Access is agreed with the client for the engagement and fixed in the written scope.

Do you sign an NDA?

Yes. BitEvo can sign an NDA.

What do we get at the end?

Finding memo · Expected-vs-observed test matrix · Reproducible evidence pack.

Sample audit evidence also exposes a machine-readable pack and a JSON download.

Who does the work?

Robert runs BitEvo.

Parallel specialist path
Security Control Validation · fixed $1,500

Use this when the owner question is whether one consequential staging/test control produces the expected ALLOW / DENY / HOLD / ESCALATE outcome and the real downstream state can be verified. Open Security Control Validation →

Parallel BUILD path
BUILD Workflow Exception Diagnostic · $3,000 / 5 business days

Use this when one recurring operational exception has a named owner and the next decision needs a frozen workflow boundary, review states, evidence handoff and measurable baseline before deeper implementation. The first phase does not require production-system mutation. Open BUILD Workflow Exception Diagnostic →

Human business handoff
Ready to discuss a bounded scope?

Email opens your mail app; nothing is sent automatically. Choose a scope or prepare the local brief first, then share only the details you intend to send. Contact Robert ?

Public-site handoff
This page does not book a triage, submit an audit request or authorize testing.

The Free triage CTA opens the verified external Cal.com booking page, where the visitor can choose a time and complete the booking. The Free, Entry and Primary scope-preparation CTAs remain separate from the external booking flow. The Scope Handoff form sends only the fields you fill after explicit consent. Accepted records are stored privately for up to 30 days. Submission through the Scope Handoff form does not create a booking and does not authorize testing. The dedicated Entry Audit CTA additionally opens the exact $1,500 bounded scope before the buyer chooses whether to submit intake. Payment and written Rules of Engagement continue only through an agreed business channel.

Authority Budget

What permission surface are you deciding about?

Scope expands when the owner needs a defensible answer about more actions, objects, approvals or integrations — not because a higher price buys a stronger guarantee.

Evidence Before Effect

How much proof must exist before the action?

The commercial ladder buys different evidence depth. The primary audit tests whether decision-time evidence and external confirmation are strong enough for the authority being exercised.

False Green

How broadly do we test apparent success?

A narrow audit may test one suspected mismatch. The primary audit can include multiple agreed scenarios where internal success, freshness or external state may diverge.

Selection rule

Start from the owner decision, then buy the evidence.

Free
“Should we spend time auditing this workflow at all?”

Use triage when the action, owner or staging boundary is still unclear.

$1.5k
“Is this specific failure real enough to act on?”

Use the Entry Audit when one hypothesis dominates the engineering decision.

$4.9k
“Should this workflow keep, gain or lose authority?”

Use the primary audit when the answer requires multiple failure scenarios, an Authority Ledger + Evidence Contract, evidence-at-decision-time and a retestable owner backlog.

Decision matrix

Scope grows because the question gets harder.

This matrix is designed for budget or procurement review. The commercial difference is evidence depth and decision breadth — not a larger guarantee.

DimensionFree triageEntry auditPrimary audit
Owner questionIs this worth auditing?Is this one failure real?Has this workflow earned its Authority Budget?
Audit object1 proposed action1 critical action chain1 staging/test workflow
Failure depthNo failure tested1 primary hypothesis10–20 agreed scenarios
Authority analysisOwner + boundary onlyOnly what the finding requiresAction/object/approval map included
Evidence depthQualification evidence onlyEnough to accept/reject one findingEvidence Before Effect + confirmation + recovery
False Green coverageNot testedOnly if part of the hypothesisExplicitly tested where applicable
Primary outputAudit / do not auditRepair / reject hypothesisExpand / constrain / repair / retest
RetestNoNot included1 included
Hardening

Repair follows evidence.

Implementation is quoted separately only after a finding identifies the real control gap. The repair scope is tied to the owner decision, rollback risk and retest criteria; there is no fixed “make it safe” package.

Claim boundary

Engineering evidence, not certification.

The work can support decisions about logging, traceability, authority and control behavior inside the tested scope. It does not certify the system, guarantee security, guarantee defect absence or replace legal advice.

Before access

Start with one action and one owner.

The public intake prepares a scope brief only. It does not authorize testing. Do not submit credentials, private keys, wallet seeds, production secrets or customer secrets.