Muji Lab

PredatorbyMuji Lab

« Production ready. »Are you sure?

Be sure.

In plain terms: ready to take real customers, real data, real days.

The audit that proves it, in two forces:

Track reads your code.

Hunt attacks it on a copy.

Order my audit

A question? Write to us.

  • From €99, paid once, no subscription.
  • We change nothing and never ask for your passwords.
  • The report is yours, with or without us.
Muji, spear in hand, watching from dense jungle
Muji leaping, spear forward, at a shadow creature

PredatorbyMuji Lab

Track or Hunt

One service, two forces.

Track

Track. Audit. Report.

  • We read your code line by line, and never touch it.
  • A password left inside, a door left open: that is exactly what we look for.
  • You get a plain list, worst first.

Included in every audit. Nothing to install.

Hunt

It breaks in. It breaks things.

  • We rebuild your application on our own machines, and we try to get in.
  • Stealing another customer's data, paying nothing, passing for you: we try it all.
  • You see what actually gave way, not one more theoretical alert.

Included from Pro, free on Hobby during launch. Your live site is never touched.

Choose your audit.

Track is included in every tier. Launch pricing, 50% off: Hunt free on Hobby, and Pro at €290 instead of €590.

HobbyLaunch price · 50% off198 99once

Track + Hunt · free

Your project is live, so bots already scan it.

  • Complete report, ranked by risk
  • Ready to paste into your AI tool
  • Your questions, in writing, for 7 days

For projects with no clients and no other people's data.

ProLaunch price · 50% off590 290once

Track + Hunt

You deliver AI-written work to clients. Your name is on the invoice.

  • Everything in Hobby
  • Hunt: we attack a copy of your application
  • One sheet per issue: the prompt that fixes it
  • You fix, we verify again: the attestation ships

All in writing. Zero meetings.

Enterprise1,990once

Track + Hunt

Your product takes payments, stores customer data. Nobody ever checked.

  • Everything in Pro
  • Prioritised remediation plan, ready to arbitrate
  • Leadership debrief: what to approve, what to block
  • One direct contact, start to finish

This profile hires at $130 to $200k a year. You get it per mission.

RescueQuoted

We recover. We verify. You take back control.

The contractor is gone. The application runs. You no longer hold the keys.

  • Code, access, domain name: we recover what belongs to you
  • Full picture: what runs, what threatens, what is missing
  • The complete audit, once the keys are back
  • A clear plan: take over, stabilise, or restart clean

Quote after a free chat, no commitment.

The price follows the project, not the box you tick: three questions upfront confirm it. Secure payment, invoice provided.

A preview of what you receive

The full report is ranked by what it can cost you. You start from the top.

Audit report · 1 checkpoint of 154, redacted · all tiers3 blockers
45 passing38 partial38 failing33 not applicable

154 points checked on this project. Every verdict is sourced, none skipped.

PRED-INFRA-005Production server hardenedCriticalFail

The connection log of records 8,759 failed password attempts in the last 24 hours alone. The machine is under continuous attack and nothing bans the attackers.

Password access was left open where only keys should get in. Accounts verified one by one on .

Passing checkpoint: the firewall is active and opens only three ports.

Every checkpoint carries its finding, its evidence and its severity. Paste the report into your AI tool: it is written for that.

Excerpt from a client report, redacted before publication. We protect every report the same way.

Fix sheet · excerpt · Pro tier1 sheet per issue

8,759 login attempts in 24 hours, no automatic banning

On the production server: install fail2ban and enable its SSH protection (1-hour ban after 5 failures). Then close password access in the SSH configuration so only keys get in, and reload the service. Verify the result: the configuration must refuse passwords, and fail2ban must already list banned addresses.

Paste the sheet into Claude, Cursor or your terminal. We verify again. The attestation ships when everything is green.

Four steps.

  1. 01

    Order.

    Three questions confirm your tier, one box authorises the Hunt. Payment is online and secure.

  2. 02

    Hand over your code.

    GitHub, zip, or two clicks from Lovable, Bolt or v0. Never your passwords.

  3. 03

    We track, then we hunt.

    Read access is all we need. With Hunt, a copy of your application set up on our machines takes our attacks: your live site is never touched.

  4. 04

    Receive the report.

    Your 3 most expensive risks first. Your copy: deleted within 14 days, confirmed in writing.

Frequently asked questions

Track or Hunt, which one do I need?

Track reads your code and finds what is dangerous. Hunt proves what holds when someone forces the door. During launch, your audit includes both, whatever the tier.

What changes between tiers?

The deliverable. Each tier contains the previous one.

  • Hobby : Track: the complete report, yours to fix, in order. Hunt is free during launch, instead of +€99.
  • Pro : Hunt on a copy of your application, one ready-to-paste fix sheet per issue, our re-check, and the attestation when everything is green.
  • Enterprise : the remediation plan and the leadership debrief.

The attestation, what does it prove?

Your proof of diligence: a dated fact. On this version of your code, the issues raised were fixed and re-checked.

  • Neither certification nor insurance : it does not guarantee your product.
  • One version, one date : what you change afterwards is not covered.

I know nothing about tech, is that a problem?

No. The guide walks you through step by step. If you get stuck, we unstick you on WhatsApp.

Are you going to upsell me afterwards?

No hard sell. The report stands on its own: you fix everything without talking to us again. Would you rather we did it? We quote, no obligation.

What about my data, my code?

Your code is read, never changed, and we ask for no passwords.

  • Hunt : runs on a copy set up on our machines, with test data, never on your live site or your customers' data.
  • Deletion : our copy is deleted 14 days after delivery, confirmed in writing.
  • Exposed secret : a password found in your code is flagged immediately, without waiting for the report.

What if my code is a disaster?

That is the most common case, and it is why Muji Lab exists. We do not judge your code: we list what must be repaired, in order.