AI App Audit
Built something with AI? Find out what you actually shipped.
AI tools will happily build you an app. They won't tell you the repo is public, the API keys are committed, and there's no backup. The 25-point AI App Audit will.
$1,795 +GST · fixed price · report in 5 business days
Who this is for
- You (or someone on your team) built an app with Claude, ChatGPT, or Cursor, and it’s now doing real work.
- You’re about to put customer data into something that was built fast.
- You’ve inherited an AI-built app and nobody can tell you how it works.
- You're an IT provider whose client just showed you one of the above. (Partners can resell this audit at margin — see /partners.)
Apps built with AI assistance get to "working" fast. What they routinely skip: repository privacy, secrets handling, authentication done properly, tested backups, and any plan for the day the one person who built it isn't available. None of that shows up until it costs you. An audit surfaces it in a week, for a fixed price, with the fixes ranked by risk.
The 25 points
Five categories. Five checks each.
Repo & secrets
- 01 Repository visibility
- 02 Credential/API-key history scan
- 03 .env and secrets handling
- 04 Dependency vulnerabilities
- 05 Licence exposure
Auth & access
- 06 Authentication implementation
- 07 Session handling
- 08 Password storage
- 09 Role and permission model
- 10 Admin surface exposure
Data
- 11 PII identification and storage
- 12 Encryption in transit and at rest
- 13 Backups exist — and restore has been tested
- 14 Data retention
- 15 What third-party AI tools can see
Deployment & infrastructure
- 16 Hosting fitness for purpose
- 17 TLS
- 18 Environment separation (dev vs prod)
- 19 Error and log exposure
- 20 Update/patch path
Operations & continuity
- 21 Monitoring and alerting
- 22 Single-person dependency
- 23 Documentation
- 24 Disaster recovery
- 25 Ownership of the accounts, domains, and keys the app depends on
What you get
- A scored written report across all 25 points
- A prioritised fix list, ranked by risk, in plain English
- A 30-minute debrief call
- If you want it: a fixed quote to remediate — no obligation, and the report is written so any competent developer can action it
What happens next
Three paths. No pressure on any of them.
Path 1
Fix it yourself
Fix it yourself with the report — it's written so any competent developer can action it.
Path 2
Have us fix it
Have us fix it (quoted) — a fixed remediation quote, no obligation.
Common questions
Before you book.
What access do you need?
Read access to the repository and hosting, or a screen-share session if you’d rather not hand over credentials. The prep form covers it.
Will you judge the code?
No. The audit scores risk, not style. Plenty of AI-built apps are fine — the point is knowing which parts aren’t.
Is our code and data safe with you?
The audit runs under NDA on request, access is read-only, and nothing is retained after delivery beyond the report you receive.
What if the app is beyond saving?
That’s a finding, not a failure — the report will say so plainly and lay out the cheapest safe path forward.
AI App Audit