What to send after payment

Mini-Audit Intake

Do not send passwords, private keys, payment credentials or production admin access. Redacted screenshots and config snippets are preferred.

Questions

  1. What does the agent do?
  2. Who uses it?
  3. What sensitive data can it see?
  4. Which tools, APIs, browser sessions, filesystems or databases can it call?
  5. Which actions can change data, send messages, spend money or export records?
  6. Where are prompts, outputs, screenshots and tool logs stored?
  7. What human approval gates already exist?
  8. What specific concern should be checked first?
  9. What would make the USD 59 report pay for itself: launch blocker, customer/security answer, engineering prioritization or low-risk confirmation?
  10. After the report, which first fix would you want checked in the included follow-up?

Accepted evidence

  • Redacted screenshots.
  • Architecture notes.
  • Tool/API scope list.
  • Demo flow or short screen recording.
  • Config snippets with secrets removed.
  • Existing security notes, customer questions or launch criteria if available.

Included follow-up

The USD 59 mini-audit includes one short follow-up on the first recommended fix within 7 days. Send a redacted screenshot, config snippet or test result; do not send secrets or production access.