All Webbed Labs

Most founders don’t find out
until it’s too late.

You just got off a call with Andy. What he told you about the Discovery Audit is real. This is the full picture of what it covers, and what happens to founders who skip it.

Most agencies take your brief, build what you ask for and send an invoice. Nobody checks whether you legally own the code. Nobody checks whether your payment setup will get your account frozen. Nobody checks whether you are sitting on a six figure compliance exposure. That is what the Discovery Audit is for.

You could spend $50,000 building something that looks fine, works fine, and is a liability underneath. You would not know. Until something goes wrong.

Every risk area the Discovery Audit covers.

Across the categories below, the combined regulatory and legal surface for a modern software product is broad. Most founders discover the extent of it late. The Discovery Audit exists so those questions land in front of the right specialist, us or one of our named partners, before build.

These are the risk areas the Audit walks through. Most founders don’t know they exist until they are facing the consequences.

01
Category · 5 risks

Payments and Money Movement

Merchant of Record

Platforms that route funds between buyers and sellers often need to weigh merchant of record status early. Our engineering team flags this for your payments counsel or a partner like Stripe compliance rather than proceed on assumption. Stripe and PayPal have frozen accounts of platforms that got the structure wrong, and we have seen founders lose access to their revenue overnight as a result.

AFSL Licensing

Products in financial advice, lending, insurance, investment or superannuation frequently raise AFSL questions. We do not opine on whether a licence is required. We build the system so a decision from your financial services counsel can be implemented cleanly, and we introduce you to specialist lawyers if you do not already have one.

Show 3 more risks in this category Show less

PCI DSS Compliance

Card data brings PCI DSS scope with it. We design payment flows so the sensitive path is minimised, typically via tokenised providers like Stripe or Adyen, and flag PCI relevant architecture to your compliance advisor before build.

Buy Now Pay Later

BNPL and deferred payment features sit close to the credit licensing perimeter under the NCCP Act. We flag them at scoping so your credit law adviser can weigh in before the architecture locks in.

Foreign Transaction Obligations

Cross border customers introduce indirect tax questions across jurisdictions, including EU VAT and US state sales tax. We build for the collection and reporting your tax advisor specifies; we do not determine your registration position.

02
Category · 5 risks

Data and Privacy

Australian Privacy Act

Privacy Act penalties have been raised significantly in recent years. Our architecture default is data minimisation, encryption at rest and in transit, and audited access on personal information. Drafting your privacy policy and confirming your obligations sits with your legal counsel.

GDPR

GDPR applicability turns on facts your data protection counsel is best placed to assess. Where EU users are in scope, we default to designing DSAR, consent and erasure machinery so the compliance position your lawyers set can be operationalised.

Show 3 more risks in this category Show less

Health Data

Health data attracts a heavier privacy regime in every jurisdiction we build in. We map controls to the standards your health law counsel identifies, including the Privacy Act and My Health Records Act, and HIPAA where US patients are in scope. The notification and audit trail your obligations demand is designed in from the start.

Children’s Data

Platforms accessible to users under 13 tend to trigger COPPA and equivalent AU obligations. We build age gating, parental consent flows and data collection limits to a spec your counsel confirms.

Tracking and Cookie Consent

Analytics, ad pixels and retargeting increasingly need consent flows to run cleanly. We audit what your site fires today and can implement the consent model your privacy adviser signs off on.

03
Category · 5 risks

Cybersecurity

API Security

Exposed or unauthenticated API endpoints are the number one attack vector in modern applications. Most early stage products have zero API security strategy. Your data, your users’ data and your business logic are all accessible to anyone who knows where to look.

Cloud Misconfiguration

Publicly exposed S3 buckets, unsecured Firebase databases, unprotected environment variables and missing access controls are how most startups get breached. It looks fine from your dashboard. It is wide open from the outside.

Show 3 more risks in this category Show less

OWASP Top 10 Vulnerabilities

The ten most critical web application security risks are present in the majority of freelancer built apps. Most MVPs fail at least three of these out of the box without the developer or the founder knowing.

Dependency Vulnerabilities

Every open source library in your tech stack is a potential attack vector. If those libraries haven’t been audited, you’ve inherited someone else’s security problem.

No Penetration Testing

Launching without a penetration test is the equivalent of opening a business without ever checking whether the locks work. You are inviting the first person who tries.

04
Category · 4 risks

Intellectual Property

IP Ownership of the Codebase

IP assignment gaps are one of the most common issues we surface when we take over another team’s codebase. We do not draft IP assignment paperwork; that is your IP lawyer. What we do is map who has touched the codebase so any gaps are visible before they become a due diligence problem.

Open Source Licence Compliance

GPL family licences carry obligations that many commercial teams do not intend to accept. We produce a licence inventory of your dependencies so your legal counsel can rule on whether a given dependency’s terms are compatible with your product.

Show 2 more risks in this category Show less

Third Party API Terms of Service

Building a business on top of another platform without understanding their commercial use terms is a significant risk. Platforms change terms, restrict commercial use or shut down APIs with limited notice. Your business model may not survive it.

Trademark Clearance

Launching under a name without checking whether it is already registered is one of the most common and most expensive mistakes founders make. A cease and desist six months after launch with a brand and marketing spend behind you is a serious problem.

05
Category · 5 risks

Legal Structure and Liability

Limitation of Liability

Limitation of liability clauses are one of the higher leverage items in a SaaS contract. Drafting is a job for commercial counsel. We mention it here so it is on your list before launch.

App Store Compliance

Apple and Google have their own rules on subscriptions, in app purchases, data collection disclosures and content. They will remove your app without warning. We have seen products with tens of thousands of users pulled overnight.

Show 3 more risks in this category Show less

Terms of Service and Acceptable Use Policy

Product terms and an acceptable use policy are what your operations team relies on when they need to remove a bad actor. We build the tooling to enforce them; the drafting sits with your commercial lawyer.

Australian Consumer Law

The ACL is one of the frameworks a well drafted set of terms has to sit alongside. We flag it because founders sometimes assume a US style disclaimer clears everything; your commercial lawyer will tell you exactly how it applies to you.

Dispute Resolution

Governing law and dispute resolution clauses are boilerplate for a reason. Drafting is your lawyer’s job; we mention it here for completeness.

06
Category · 2 risks

Tax and Financial

R&D Tax Incentive

R&D Tax Incentive rates are published by AusIndustry and the ATO. Australian conducted development work is generally eligible for consideration. Your claim is lodged by your registered R&D tax agent; we structure the technical evidence, including uncertainty registers, experiment logs and time allocation, so that agent has something defensible to work from.

GST on Digital Services

Overseas customers can introduce indirect tax registration questions. We build for whatever collection and remittance rules your tax adviser confirms.

07
Category · 3 risks

Employment and Contractor Risk

Sham Contracting

Contractor versus employee status is an area we see founders trip on. It is a question for your employment lawyer or accountant. We mention it because the answer changes what your equity, IP assignment and superannuation setup should look like on day one.

IP Assignment Gaps

IP assignment is the paperwork side of the codebase inventory we run. Drafting sits with your IP lawyer; we make sure our own contribution is fully assigned to you at handover, and we surface gaps in anyone else’s.

Show 1 more risk in this category Show less

Equity and Co Founder Agreements

Vesting schedules and cliffs are drafted by commercial counsel, not by us. We raise it here because unresolved cap table paperwork is the single most common blocker when a founder we work with goes to raise.

08
Category · 4 risks

Regulated Industry Triggers

Health and Medical Apps

Therapeutic claims and clinical use are the two triggers we see push a build into TGA territory. It is a regulatory affairs consultant’s call, not ours. We design the system so their scope determination can be honoured.

Legal Tech

AI features in a legal tech product raise unauthorised practice of law questions. That is a call for your legal counsel; on our side, we build guardrails, disclaimers and human in the loop review to whatever spec they set.

Show 2 more risks in this category Show less

Education and Child Safety

Platforms serving minors sit on top of state by state child safety regimes. We build the identity, safety and reporting flows to the spec your safeguarding advisor or legal counsel provides.

Property and Real Estate Features

Some property features sit near the real estate licensing perimeter. It is a call for a licensing lawyer; we flag it at scope so it does not surprise you post launch.

09
Category · 1 risk

Accessibility

WCAG 2.2 Compliance

WCAG 2.2 is our baseline on every build. Government tenders typically require it explicitly, and the DDA sits behind it as the anti discrimination framework your legal team will be familiar with. Retrofitting accessibility into an existing product is significantly more expensive than building it in from the start.

10
Category · 3 risks

Architecture and Scalability

Wrong Tech Stack

A freelancer builds in what they know, not what is right for your scale, your use case or your long term roadmap. Rebuilding from scratch because the original architecture cannot handle growth is one of the most common and most expensive problems we see.

No Disaster Recovery Strategy

If your database goes down, what happens? Most early stage products have no backup strategy and no defined recovery time. One infrastructure event can mean permanent data loss.

Show 1 more risk in this category Show less

Vendor Lock In

Building entirely on one cloud provider or proprietary platform with no exit strategy means that provider controls your costs, your uptime and ultimately your business continuity.

11
Category · 2 risks

Insurance

Cyber Liability Insurance

The average cost of a data breach in Australia is now over $4 million. Most early stage founders have no cyber liability coverage. One breach can exceed the cost of the entire build.

Professional Indemnity

Professional indemnity is a call for your insurance broker. We mention it because operators are sometimes surprised at how quickly they need it once enterprise clients start asking for certificates of currency.

The standards we audit against.

These are the internationally recognised frameworks AWLabs applies to every project. This is what enterprise clients, investors and acquirers will ask for. Most founders have never heard of them.

ISO 27001
Information Security Management
Every project. Gold standard for data security.
ISO 27701
Privacy Information Management
Any project collecting personal data.
ISO 27017
Cloud Security
All cloud hosted projects.
ISO 27018
Personal Data in the Cloud
Any project storing user data in the cloud.
ISO 25010
Software Product Quality
Every project.
ISO 12207
Software Lifecycle Processes
Every project. Internationally auditable build process.
ISO 29119
Software Testing
Every project requiring pre launch verification.
ISO 31000
Risk Management
Every project. The framework underpinning the DA itself.
PCI DSS
Payment Card Industry Standard
Any app touching card data.
SOC 2 Type II
Service Organisation Control
B2B SaaS targeting enterprise or US clients.
ISO 13485
Medical Devices Quality Management
Health and medical apps.
ISO 14971
Risk Management for Medical Devices
Software as a medical device.
HL7 FHIR
Health Data Interoperability
Health apps integrating with clinical systems.
ISO 42001
AI Management System
Any project with AI or machine learning features.
EU AI Act
AI Regulatory Compliance
Any AI feature accessible to EU users.
WCAG 2.2
Web Content Accessibility Guidelines
Every project.
ISO 9001
Quality Management Systems
Every project.

What happens when founders skip it.

First person because we have seen them.

Merchant of record misclassification

We had a client whose marketplace hit $2M in GMV before Stripe froze their account due to undisclosed platform transactions. They couldn’t pay their vendors for six weeks. The business nearly collapsed.

IP ownership gap

A founder paid $60,000 to a development agency under a poorly drafted contract. When the relationship broke down, the agency retained ownership of the codebase. The founder had to rebuild from scratch.

Privacy Act breach

A Sydney based startup suffered a data breach affecting 4,000 users. Without a mandatory breach response plan, they notified the OAIC 47 days late. The investigation cost more than the original build.

Cloud misconfiguration

A Firebase misconfiguration exposed the personal data of 100,000 users of an Australian fintech app. The database had been publicly readable for eight months before anyone discovered it.

App store removal

A consumer app with 30,000 active users was removed from the App Store for undisclosed data collection. It took four months and a full rebuild to get it reinstated. Four months of zero new users.

Open source licence violation

A SaaS founder built their core product on a GPL licensed library. When they went to raise their Series A, legal due diligence flagged the violation. They had to open source their product or rebuild the affected components before the round could close.

What the Discovery Audit delivers.

01

Full Scope and Risk Audit

We go deep on your idea or existing product. Every feature mapped. Every risk area across security, cyber exposure, legal liability, compliance and architecture identified and addressed.

02

Investor Ready Roadmap Document

A formal strategic document you can take to a VC, investor, bank, accelerator or board. Not a quote. A proper document showing what is being built, how it is being built, what the risks are and how they are mitigated, and what the path to market looks like. This document alone can open doors.

03

Pitch Deck and Strategy Session

We prepare a full pitch deck and present it to you in a dedicated strategy session. You are not getting an email with a number. You are getting a proper presentation of how we see your project playing out, including timeline and full investment required.

Code, capital and compliance. One team, one roof.

AWLabs is a full end to end delivery partner. Development and marketing are ours; capital and legal are coordinated with our named third party partners, all working from the same brief. You are not stitching four vendors together and hunting for handovers. You are talking to one team.

The Discovery Audit is the point where that comes together. Every risk we surface is something one of these four pillars addresses. Nothing is thrown over a fence.

01
Development Custom software, app builds, AI integration. Delivered in house.
02
Marketing User acquisition through our in house team at All Webbed Up.
03
Capital Coordinated with our named R&D tax and grants partners. We structure the technical documentation, they lodge the claim.
04
Legal Coordinated with our named commercial and IT law partners so contract, IP assignment and privacy drafting keeps pace with the build.

Not everyone gets to this point.

Every week you build without this audit is another week of compounding exposure.

Andy is personally across every Discovery Audit we take on. We work with a limited number of clients at a time and we are selective about who we take on, because the DA only works when we can go deep.

If you are reading this, it means Andy thinks there is something real here.

The Discovery Audit is a fixed fee. If we proceed to build, that fee is credited in full to your build, so it is not an extra cost. It is money toward your project.

For what it protects you from, what it sets you up with and the doors it can open, whether you proceed with us or not, it is one of the most important line items you will approve on this project.

AWLabs and All Webbed Up have served over 150 Australian clients. Rated 5.0 on Google across 118 reviews.

Or call 1800 714 148