Auditd
Ship fast · Audit faster

Nobody audits the code they didn't write. That's the whole problem.

Auditd exists because AI writes code faster than anyone reads it.

[A.04/11]//WHAT THE MODEL SKIPPED

Four Ways AI-Generated Code Fails In Production

[01]

YOU SHIPPED IT IN A WEEKEND

The model wrote your auth flow in four seconds and you merged it in ten. Nobody checked whether the session actually expires, or whether it's checked at all. We check.

[02]

IT WRITES CODE THAT RUNS

Not code that holds. Keys in the client bundle, endpoints with no rate limit, database rules left open from day one. The model was never asked what happens under load.

[03]

FINDINGS, NOT OPINIONS

Every issue has a severity, a location and the steps to reproduce it. If we can't show you the break, it doesn't go in the report.

[04]

WE FIX WHAT WE FIND

Most audits end with a PDF. Ours ends with the code patched, retested, and written confirmation of what changed.

Every line you didn't read is a line you shipped on faith. Auditd reads all of them, on every push.

[N.11/11]//THE PROCESS

Three Simple Steps

Point Auditd at a repo or a pull request. It reads the diff the way a reviewer would, not the way a linter does.

Learn more

Each finding comes with the failing input, the affected path, and the reason it slipped past review.

Learn more

Take the suggested patch as-is or adapt it. Re-scan runs automatically on the next push.

Learn more
[N.08/11]//PRICING

Fixed Prices. Nothing Discretionary.

Starter

For one site you'd rather not think about.

$197

Request An Audit

Includes:

  • Monthly full review
  • Written summary of anything new
  • Async advisory over email
  • Dependency and CVE watch
Most Popular

Growth

For a product with real users and a release cycle.

$397

Request An Audit

Everything in Starter, plus:

  • Weekly reviews
  • 48-hour incident response
  • Priority remediation on new findings
  • A direct line to the engineer who audited you

Scale

For teams shipping to live traffic.

$797

Request An Audit

Includes Everything in Growth, plus:

  • Continuous monitoring
  • 4-hour incident response
  • Quarterly architecture and load review
  • Team & collaboration features
  • Pre-release review on major deploys
[N.08b]//ADD-ONS

Minor & low-risk pack

£345

Everything below high severity, cleared out in the same pass.

Hardening pack

£445

Security headers, TLS configuration, access control on admin paths, dependency updates.

Compliance pack

£447

UK and EU: consent handling, data subject requests, privacy policy review.

Performance & load

£647

Load testing and architecture review.

Redesign

On request

Quoted on page count, functionality and integrations.

[N.07/11]//TESTIMONIAL

Less Talk, More Shipping. See what they are saying.

Verso

It's not just a linter with a chat box bolted on. It's baked into our process now, catching things before they touch everything downstream.

Emily Carter

Frontend Engineer

1:30 min
Verso

It's not just a linter with a chat box bolted on. It's baked into our process now, catching things before they touch everything downstream.

Emily Carter2

Frontend Engineer

Verso

It's not just a linter with a chat box bolted on. It's baked into our process now, catching things before they touch everything downstream.

Emily Carter2

Frontend Engineer

Verso

It's not just a linter with a chat box bolted on. It's baked into our process now, catching things before they touch everything downstream.

Emily Carter2

Frontend Engineer

[N.11/11]//QUESTIONS

Have Questions? We've Got Answers

A written report covering every page and endpoint we review. Each finding has a severity, where it is, how to reproduce it and what to do about it. There's a plain-language summary at the front for anyone who doesn't write code. Fixes are a separate, separately priced step, so you're never paying to be told you have a problem and then cornered into buying the cure.

No. It's most of our work. AI writes code that runs, which isn't the same as code that's safe. The gaps are consistent enough that we know where to look first: auth that checks the wrong thing, keys sitting in the client bundle, endpoints with no rate limit, database rules left open from the first day of the project.

No. The audit is read-only. Nothing is changed, deployed or taken down. If you go ahead with remediation, we work on a branch, you review the diff, and it ships when you say it ships.

A single-site audit usually comes back within [X] working days. Remediation depends on what's in the report. You get the timeline with the findings, before you commit to anything.

You get that in writing, and you can hand it to a client, a customer or an investor. It happens less often than you'd hope.

Read access to the repo and a staging environment gets you the most depth. If that's not possible we can work black-box against a live URL, and you'll get less for it. NDA first if you want one, no argument.

Nothing, unless you want it. The retainer exists because code keeps changing, and the next thing you ship is written the same way the last thing was. Monthly or weekly reviews, and someone to call when something looks wrong.