Terms of sale

Terms and refunds

Who sells

Audit AI (auditai.sh) is run by its founder, a private individual based in Bangkok, Thailand. Write to hello@auditai.sh about an order, and to security@auditai.sh about a vulnerability in Audit AI itself. How we handle what you send us is on the privacy page.

Night watch: what you buy

One year of checks of one Supabase project, about once a day from the day the payment is confirmed, with an email when a check finds something new open. It is a one-time purchase for 12 months and does not renew by itself. You start it on the order page by creating a role in your database with the SQL we show, and by giving us your project's pooler connection string, so it needs a Supabase project you own. The role is granted nothing and cannot read or change your tables; like every role in Postgres it can read your schema. Before every check we ask your database what the role can do and stop if that changes. We keep the role's password encrypted, and what the checks found; stopping the watch deletes both. See the night watch page.

Services done by us

These two are work done for you rather than software you use. They are invoiced by email or ordered on their page, and paid in cryptocurrency.

Fix & re-check

For one Supabase database: we read the snapshot of your schema that you send us, the same one the free database check reads, and write one migration that closes what it shows open, with the lines that undo it where an exact undo exists and a read-only query that shows the result. You apply the migration yourself and send a new snapshot; we check it and tell you what is still open. We work from the snapshot only: we never connect to your project, never ask for a key or a password, and do not review or change your application code. We send the invoice within one working day of your email, the migration within two working days of payment, and the re-check result within one working day of your new snapshot. The price is on the Fix & re-check page in US dollars.

Verified audit

One audit of one GitHub repository by Audit AI: a scan with every finding checked by a person, sandbox proofs for the holes that can be reproduced, minimal fixes with regression tests, and a report that states what was covered and what was not. The price is shown on the order page in US dollars.

After payment a person writes to you from hello@auditai.sh to agree on access and timing. A public repository needs nothing more; for a private one you give access, for example by adding the GitHub user audit0 to that repository only (in an organization, with the Read role) and removing it when the audit is done. We use your code only to perform the audit and do not publish findings about your repository without your permission.

Payment

You pay in cryptocurrency through CryptoBot or xRocket, or by sending USDT on TRON or TON. For Fix & re-check we send you an invoice by email. The order is paid once the payment is confirmed; the order page or an email tell you when. Network and provider fees on your side are yours.

Refund policy

Refunds are paid in USDT to an address you name, within 7 days of your request. Write to hello@auditai.sh and quote your order code; for Fix & re-check, reply in the email thread with your invoice.

Fix & re-check

Full refund if you cancel before we deliver the migration, if we cannot write one for your snapshot, or if the re-check shows the same hole still open after you applied our migration as written.

Night watch

Full refund if the watch cannot connect to your project at setup and we cannot fix that together, or within 14 days of payment if you ask. After that the year is not refundable, and stopping early does not refund the rest.

Verified audit

Full refund if you cancel before we start, or if we cannot run the audit on your repository (for example, it is not a supported stack or we cannot get access). Once the report is delivered, the audit is not refundable.

No guarantee of no other holes

Each of these finds and closes specific classes of problems. Fix & re-check and the night watch look at what your database allows, not at your application code; an audit covers the stack we support. None of them guarantees that your application has no other vulnerabilities.

Contact

hello@auditai.sh. Quote your order code, or for Fix & re-check reply in the thread with your invoice.