new: drive vas from your AI agent over MCP · Cursor, Claude Code, Windsurf

Remediation

Get your findings fixed

A scan tells you what is wrong and how to fix it. If you would rather not do it yourself, Thunkle does the work. Same team that builds vas.

Worth saying plainly: Thunkle built vas. This is not a referral to a third party, it is the same people. Every finding already comes with a fix you can apply yourself for free, and most of the time you should.

What Thunkle does

Senior engineering for apps built with AI tools. The work usually starts because something shipped faster than it hardened.

Security and code audits

From $750

A senior review that goes past what a scanner can see. Access rule failures, logic flaws, and the problems that only show up when someone reads the code with intent.

Platform migrations

From $1,000

Move off Lovable, Bolt, Replit or Base44 onto infrastructure you own, with your data intact. The usual reason people do this is that they outgrew the builder, not that they disliked it.

Feature development

Custom quote

Ongoing engineering on a live product. New features, integrations, payments, auth, and the bug fixes you have been putting off.

MVPs from scratch

From $5,000

Brief to launched product, built on infrastructure designed to scale rather than something that has to be rebuilt at the first sign of traction.

When it is worth paying someone

A critical finding you do not understand well enough to be confident you fixed it

Access control that needs redesigning rather than patching

A migration off a builder platform, with live data, that you do not want to attempt yourself

You have the fixes and simply do not have the time

If none of those apply, apply the fixes in your report and keep your money.

Send your scan

Include the link to your report and you will get a quote within 24 hours, with a view on which findings actually matter for your app.

Common questions

Is Thunkle the same team as vas?

Yes. vas is built by Thunkle. We are telling you that up front because a scanner that sends you to its own agency without disclosing it would deserve the scepticism. The upside is that the people who wrote the checks are the people fixing what the checks found, so nothing gets lost explaining the report.

Do I have to pay someone to fix my findings?

No, and most people should not. Every finding in a vas report ships with a specific fix written to paste into your AI coding tool. If you are comfortable applying them yourself, do that. This page is for the cases where you are not: a critical finding you do not understand, a migration you do not want to attempt live, or simply not wanting to spend the weekend on it.

What does an audit cover that the scanner does not?

Automated scanning is good at configuration and access-control problems visible from outside the application. It cannot evaluate business logic, spot a permission model that is coherent but wrong, or tell you that a feature should not exist. A human review covers that, and reads the code rather than the deployed surface.

How fast do you respond?

Quotes within 24 hours. If a scan turned up something critical and you want it looked at the same day, say so in the message and include the scan link.