From: NovaCTO
Re: what you're actually paying for · Read time: about five minutes
You're the only person at your company who doesn't know what happened last week.
Somewhere right now, a founder is approving a $42,000 invoice for a sprint she cannot describe. She isn't careless — she closed a seed round in a bad market and can read a term sheet upside down. But the work she's buying arrives as a link to a GitHub repository, and to her it may as well be sheet music.
We built NovaCTO for her. Probably for you.
1The problem nobody says out loud
Your developers aren't lying to you. Mostly.1 But every report you receive about the engineering — the standup, the sprint demo, the "almost done" — is produced by the same people whose work it describes. In any other department you'd call that what it is: self-reporting. Finance doesn't work that way. Sales doesn't work that way. Engineering does, at nearly every company under fifty people, because the founder can't check.
So you develop workarounds. You learn to read faces on the Friday call. You count how often the demo looks the same as last time. You ask a technical friend to "take a quick look" and he says the code is, well, fine, sort of, hard to say from a quick look. None of this is oversight. It's astrology with extra steps.
2What we do about it
NovaCTO connects to your GitHub and your cloud account with read-only access — it can look, it can't touch2 — and reads everything: every commit, pull request, deploy, and line of the AWS bill. Then, every Monday at 9am, it writes you a memo in English. Not "refactored the auth middleware." English.
Your Monday Brief
Your AWS bill jumped $2,840. A test cluster from three weeks ago was never shut down. It's doing nothing. ask your team: "Can we kill the staging-v2 cluster today?"
Shipping speed dropped 38% this month. Most of it traces to one refactor that's been open for 16 days. ask your team: "What's blocking the checkout refactor?"
Security: clear. Last week's vulnerable dependency was patched Thursday. Verified in production.
That's the product. A five-minute read, once a week, plus an immediate alert when something genuinely can't wait — a leaked API key, a security hole, a cloud bill doing something strange at 2am. There's a health score so your board deck has a number in it, and each finding ends with the exact question to ask your team, worded so you sound like you know what you're talking about. Because, at that point, you do.
There is no dashboard to learn.3
3What we deliberately don't do
- We don't write or change code. Read-only isn't a setting we chose, it's the architecture. There is no code path from NovaCTO to your production systems.
- We don't rank your developers. You'll never see a leaderboard of who committed the most. Commit counts are a garbage metric, and surveillance ruins teams. We report on the health of the work, not the humans.
- We don't replace technical leadership. A real CTO decides, hires, and argues with you about strategy. We do the watching part — which is most of what you're missing, and none of what you should pay $250,000 for.
- We don't pretend to be finished. We're in early access. SOC 2 Type II is in progress, not done. The security page says exactly where things stand.
4Who this is for, specifically
If you're a founder without a CTO — you raised money, you hired developers, and you now approve work you can't evaluate. You're our center of the target. Start with the product page.
If you pay a development agency — you should know that the most common pattern we see is output quietly dropping after a contract renews, while the invoices don't. It's rarely malice; the senior people just get rotated to the next sale. You'd never catch it, because the status report is written by the agency. We wrote a whole page about this. Some agencies won't love it.
If you're a fund — you monitor ARR monthly and technical risk never, and the difference shows up as a write-down every couple of years. There's a portfolio version.
5What it costs, and why
$149 a month for up to three repositories; $449 for fifteen plus the agency-oversight and benchmarking work.4 We priced it by asking what a founder would pay without having to ask anyone's permission — this should be a line item you never think about, sitting next to Notion, not next to payroll. The first two briefs are free, no card. If two weeks of briefs don't change a single conversation you have with your team, leave. You'll have learned something anyway.
Early-access prices are locked for as long as you stay. That's not a marketing gimmick so much as a bribe for tolerating our rough edges while we build.
— the NovaCTO team
the CTO who never sleeps
P.S. — If you run a dev agency and this page annoyed you: your best future clients are precisely the ones who can verify you're good. Send them here. The mediocre agencies are the ones who should be nervous.
1 The honest version: engineers round "70% done" up to "almost done" the way everyone rounds at self-checkout. The problem isn't dishonesty, it's that nobody's checking the receipt.
2 Read-only OAuth scopes, verified on every connection. Your source code is analyzed in ephemeral environments and never stored — we keep the conclusions, not the code. Full details on the security page.
3 There is technically a dashboard. Nobody uses it, including us. The product is the memo in your inbox; the dashboard is where the memo's receipts live when you want to click into one.
4 Funds and acquirers: portfolio pricing is custom because portfolios are. Details on the investors page, or the pricing page has the full comparison against hiring, fractional CTOs, and one-off audits.