SERVICES AND RATES

Four formats, four published prices

From the one-hour diagnostic to the architecture engagement. Each one stops exactly where it says it will.

The four prices below are published, and they hold for everyone: the same rate, whatever your context.

Each format ends with a deliverable that belongs to you. A diagnostic concluding “these are your three risks, your team can handle them alone” is a successful diagnostic: you have what you need to decide — and that is what lets you believe me the day I recommend going further.

FormatDurationPriceWhat you leave with
Is your AI-generated code ready for production?1 hour, by video€200 excl. VATWithin 24 hours, a written and prioritised list of your three main risks
AI-generated codebase audit: what holds, what has to be redone3 days€2,400 excl. VATA written report: what to keep, what to redo, what to throw away
Putting the guardrails in: code, deployment, AI agents5 days€4,000 excl. VATThe apparatus in place and proven on your code
Architecture engagementper day€800 excl. VAT / dayThe decisions written down, with what they cost and what they close off

Prices excluding VAT. Quote and invoice issued by the company for any service booked directly. My written commitments on access to your code are annexed to the quote, where they carry contractual force.

Where you stand

  • You do not know whether it is serious —take the hour.
  • You know it is serious, you do not know where to start —the audit.
  • You know where to start, and you want it to stop happening —the guardrails.
  • What will need protecting does not exist yet —the architecture engagement.

Each format can be taken on its own; they follow one another where that is useful.

What you give me to begin with: nothing

For a one-hour service, nobody should have to open their code repository — the folder where their project lives — to someone they are meeting for the first time. The right answer is to design the session so it can do without access, rather than asking you to trust me.

For the one-hour session

I send you a reading script suited to your language. You run it yourself, on your own machine. It writes nothing into your project — its only write is a temporary system folder, deleted automatically on exit. It contacts no server. It installs nothing. It executes none of your project’s code.

It produces about a hundred lines of measurements: volume, a summarised Git history (no commit messages, no author names), apparent duplication, the state of the tests, dependencies and version ranges, deployment configuration, documentation, and an inventory of the places where a secret appears to be written — their location, their type, their number of occurrences. Never their value: the script is built to be incapable of it, it counts and it locates, it does not display.

It runs to six hundred lines. I will not promise you it can be read through in two minutes, which would be untrue. Its header lists precisely the commands that do not appear in it — no network access, no writing into the repository — so that you can check it yourself rather than take my word. That check takes thirty seconds.

The result goes into a text file, on your machine. Open it before sending it to me: I encourage you to. If a line troubles you, delete it and send the rest — I will tell you in the session if I miss it.

You can also come without sending anything. The session is then run as shared reading: “let us look together” rather than “here is what I found”. We cover two or three areas of the project, and my observations are hypotheses your team confirms afterwards. That is useful, and it is a different thing — better to know beforehand.

From the audit onwards, I need the code

Three days of analysis cannot be done over someone’s shoulder. My commitments are then written down, annexed to the quote, and they carry contractual force.

What I look at
The source code, the configuration, the dependencies, the Git history. Nothing else — not your databases, not your deployed environments, not your internal tools, not your customer data. If I come across real data in the repository, I tell you and I stop looking at that file.
A secret found
I do not open it, I do not note it down, I do not send it back to you in writing. You receive its location and its type; if we have to discuss it, that happens out loud, in session.
What leaves my machine
Nothing, apart from what is described in my note on the use of AI tools — the only transfer that exists, set out line by line, and one you can refuse.
What I delete, and when
Within seven days: the copy of your code on my machine if there was one, the output files, my working notes and my conversations with my AI tools. I send you a message when it is done. What survives is the report I handed you — of which you have a copy.
The access, if there was one
I tell you as soon as my analysis ends. Revoking it is yours to do; I remind you twice at most, and I do not reconnect in the meantime.
Your project as a reference
I cite it nowhere, in any form, even anonymised, without your written agreement.

On the confidentiality agreement: if you have one, send it. I read it, I tell you what I accept, and I sign if it is reasonable.

These commitments and this note on AI use fit on one page. Ask for them before signing anything.

IF YOU ARE UNSURE

If you are hesitating between two formats, take the smaller one: it gives you what you need to decide on the next.

Design Horizon & Development, a limited company registered in France. Prices excluding VAT. Remote work from Montpellier, travel possible. Quote and invoice issued by the company for any service booked directly.