Skip to main content
NEW GUIDEFour ways to make a regulated firm AI-nativeGet the deck
Softblues

AI code audit & setup

AI code audit for apps built with AI

Softblues reviews AI-generated and vibe-coded applications before launch or when problems emerge in production. You receive prioritised findings and a remediation plan. Implementation is scoped separately, so you can decide what to fix and who should do the work.

Fixed-price review, scoped in advance · Findings report you keep · Remediation priced separately

  • OpenAI Select Partner
  • Google Cloud Services partner
  • Anthropic Partner Network member
  • Member of the Microsoft AI Cloud Partner Program

What does an AI code audit examine?

We examine the application around the code: how access is enforced, how information moves, what happens when a dependency fails and how the team releases changes. The scope is agreed against the system and its intended use.

  • Security and access

    Authentication, permissions at the API and data layers, exposed secrets, dependencies and sensitive information handling.

  • Reliability

    Error handling, failure paths, external services and the behaviour of business-critical workflows.

  • Maintainability

    Code structure, types, dependencies and the ability to change one part without breaking another.

  • Release readiness

    Tests, deployment checks, monitoring, rollback and the evidence needed for a launch decision.

Where the application uses an AI model at runtime, the review can also cover output evaluation, prompt injection exposure and the actions the model is allowed to trigger. AI-generated code and an AI-powered application are different things; the audit scope reflects which you have.

What do you receive, and what is a separate piece of work?

The review and the changes are two commitments. The table separates them so you can commission one without the other.

Audit deliverables compared with optional implementation
Audit deliverableOptional implementation
Prioritised findings with affected areas and recommended fixesRemediation of the agreed security and reliability issues
Go-live risks and limitations within the reviewed scopeRefactoring or a scoped rebuild where justified
Gaps in tests, evaluation and release checksTest suites, relevant AI evaluations and CI setup
A remediation plan and handover discussionMonitoring, deployment improvements and team documentation

An urgent finding is raised promptly. Changes to a live system require an agreed scope and authorised access. An audit is not a guarantee that every vulnerability has been found or a substitute for a separately scoped penetration test.

Before and after: what should improve?

This comparison describes the intended changes from a scoped remediation engagement. It is not the result of a review on its own.

Before the agreed work, compared with after it
BeforeAfter the agreed work
Important changes are checked only by clicking through the appCritical flows have repeatable tests and release checks
Permissions rely on what the interface hidesAgreed permissions are enforced at the relevant service and data boundaries
A large, tangled codebase makes each change difficultThe agreed areas have clearer structure and documented responsibilities
Failures are discovered by usersAgreed monitoring and response ownership make failures visible

Who is it for?

Four situations where a review is usually worth commissioning.

  • Teams approaching launch with an AI-built MVP
  • Founders whose prototype works in a demo but breaks on real tasks
  • Engineering teams accumulating defects in AI-generated code
  • Technical leaders preparing for a security or production-readiness review

The source tool may be Claude Code, Cursor, Copilot or another AI coding tool. The review focuses on the resulting application and how it is operated.

What did a recent audit find?

In an anonymised food-production application, we reviewed 58,000 lines of code and identified four priority findings, including two go-live blockers. The urgent storage exposure was closed in the first week. The broader rebuild was proposed separately.

Stage: audit delivered; rebuild proposed. The rebuild is set out and has not been delivered, so nothing here describes a completed go-live or a post-launch result.

How are the audit and fixes priced?

The review is fixed price for an agreed scope. System size, access, integrations and the depth of testing determine the effort. You keep the findings report whether your team implements the recommendations or asks us to scope the fixes.

Key facts

The AI code audit: at a glance

What it is
A review of an AI-generated or vibe-coded application: security and access, reliability, maintainability and release readiness, scoped against the system and its intended use.
What you receive
Prioritised findings with affected areas and recommended fixes, go-live risks within the reviewed scope, gaps in tests and release checks, and a remediation plan you keep.
What is separate
Implementation. Remediation, refactoring or a scoped rebuild, test suites, evaluations, CI, monitoring and documentation are scoped and priced as their own piece of work.
Price
The review is fixed price for an agreed scope. System size, access, integrations and the depth of testing determine the effort.
Timetable
Agreed after reviewing system size, access and the required depth. The audit and any implementation may have different schedules.
Access
Confidentiality, access, approved tools and retention arrangements are agreed before access is granted, including how access is removed at completion.
Limits
An audit is not a guarantee that every vulnerability has been found, and it is not a substitute for a separately scoped penetration test.

Request a code-audit call

Tell us what the application does, whether it is live and what is causing concern.

Please do not paste source code, credentials or sensitive data into this form.

We will respond within one business day. No spam, ever.

Common questions about the code audit

What is a vibe-coded system?

A system built substantially with AI coding tools, often through natural-language instructions. That method alone does not establish its quality. A review examines the resulting code, security controls, tests and operation.

Do you just review, or fix it too?

The audit produces the findings and remediation plan. We can scope implementation separately, or your team can use the report to make the changes.

Will you set up our AI coding agents properly?

We can include coding conventions, project instructions, testing and release checks in a separate implementation scope. The setup should help your team continue developing and reviewing changes.

How long does it take?

We agree the timetable after reviewing system size, access and the required depth. The audit and implementation may have different schedules.

How is our code handled?

Confidentiality, access, approved tools and retention arrangements are agreed before access is granted. We use the permissions required for the review and define how access will be removed at completion.

What do we get at the end?

Prioritised findings and a remediation plan for the agreed scope. If you commission implementation, its deliverables and acceptance criteria are set out separately.

Not sure the application is safe to run on?

Tell us what it does, where it runs and what is causing concern. We will agree the review scope against the system rather than a standard checklist.

The review is fixed price for an agreed scope, and implementation is scoped and priced separately.