Package 1

AI code audit and security

Your team writes code with AI. We review what reaches production.

A fixed-price audit of code security and quality. You receive a list of findings ordered by risk and a remediation plan with a quote.

Outline your case
Starting point

When an independent review is warranted

Before the production release

The code was written under deadline pressure and has never been reviewed outside the team.

After the MVP stage

The prototype has proven itself and is now expected to run as a production system.

Before an acquisition or investment

You are taking over software or a company and need an assessment of its technical condition.

Loss of system knowledge

The authors have left, the documentation is incomplete, and lead times for changes keep growing.

Scope

Six areas we examine

Each area has its own criteria and its own section in the report.

SecurityThe ten categories of OWASP Top 10:2025 — from access control to the mishandling of exceptional conditions. Findings are mapped to OWASP ASVS 5.0.0 requirement numbers, which gives a verifiable result for each of them.
Dependencies and licencesKnown vulnerabilities in third-party libraries and the compatibility of open source licences with your business model. We analyse the full dependency tree, including components pulled in indirectly.
Credentials and keysA scan of the repository for passwords, tokens and API keys. It also covers the change history, where data removed from the current version remains accessible.
Architecture and maintainabilityAn assessment against the ISO/IEC 25010 quality model: maintainability, flexibility, compatibility. Technical debt, complexity and duplication are measured in SonarQube.
PerformanceResponse times, database queries and memory use, measured at the points that actually put the system under load.
Tests and the CI/CD pipelineThe scope and effectiveness of the tests in relation to the real risk. We check whether the pipeline stops a change that does not meet the agreed quality criteria.
Process

Four steps, a fixed deadline

1Enquiryinitial assessment and scope 2Proposalfixed price and deadline 3Auditsix areas, two engineers 4Debriefreport and remediation plan
Outcome

Deliverables

A report with a risk assessment — findings ordered by priority, each referenced to an OWASP category.
A remediation plan with a quote — the order of the work, its cost and its duration.
Raw scan results — the tool reports, ready to be verified on your side or by another auditor.
A walkthrough with your team — a meeting with the engineers who maintain the system.
Questions

Frequently asked questions

Do we have to give you access to the repository?

Yes, in read-only mode. The code does not leave your infrastructure other than as the fragments an engineer deliberately examines. The rules are set out in the document “Data, GDPR and AI tools”, handed over before the work begins.

Do you hold an ISO certificate?

No. We apply ISO/IEC 25010 and OWASP as a reference point for our own process. ISO/IEC 25010 is a product quality model — it defines the characteristics against which software is assessed. Certification applies to management system standards, for example ISO/IEC 27001 for information security; we do not hold such a certificate. The details are in the document “Engineering quality and standards”.

What if the audit finds nothing?

You receive a report stating this, with the scope and the assessment criteria. Such a document serves as evidence of due diligence towards a client, an insurer or an investor.

Do you fix the defects you find?

Yes, as a separate engagement with its own quote — the “Refactoring and technical debt” package. The audit is billed independently of the repair work, so the number of findings has no bearing on our fee.

Whether an audit is justified in your case

Tell us which system is involved and what needs to be verified. We assess the enquiry first and propose a conversation with an engineer where the work has a clear purpose.

Outline your case