
AI code audit & setup
AI code audit for apps built with AI
Softblues reviews AI-generated and vibe-coded applications before launch or when problems emerge in production. You receive prioritised findings and a remediation plan. Implementation is scoped separately, so you can decide what to fix and who should do the work.
Fixed-price review, scoped in advance · Findings report you keep · Remediation priced separately
- OpenAI Select Partner
- Google Cloud Services partner
- Anthropic Partner Network member
- Member of the Microsoft AI Cloud Partner Program
What does an AI code audit examine?
We examine the application around the code: how access is enforced, how information moves, what happens when a dependency fails and how the team releases changes. The scope is agreed against the system and its intended use.
Where the application uses an AI model at runtime, the review can also cover output evaluation, prompt injection exposure and the actions the model is allowed to trigger. AI-generated code and an AI-powered application are different things; the audit scope reflects which you have.
What do you receive, and what is a separate piece of work?
The review and the changes are two commitments. The table separates them so you can commission one without the other.
| Audit deliverable | Optional implementation |
|---|---|
| Prioritised findings with affected areas and recommended fixes | Remediation of the agreed security and reliability issues |
| Go-live risks and limitations within the reviewed scope | Refactoring or a scoped rebuild where justified |
| Gaps in tests, evaluation and release checks | Test suites, relevant AI evaluations and CI setup |
| A remediation plan and handover discussion | Monitoring, deployment improvements and team documentation |
An urgent finding is raised promptly. Changes to a live system require an agreed scope and authorised access. An audit is not a guarantee that every vulnerability has been found or a substitute for a separately scoped penetration test.
Before and after: what should improve?
This comparison describes the intended changes from a scoped remediation engagement. It is not the result of a review on its own.
| Before | After the agreed work |
|---|---|
| Important changes are checked only by clicking through the app | Critical flows have repeatable tests and release checks |
| Permissions rely on what the interface hides | Agreed permissions are enforced at the relevant service and data boundaries |
| A large, tangled codebase makes each change difficult | The agreed areas have clearer structure and documented responsibilities |
| Failures are discovered by users | Agreed monitoring and response ownership make failures visible |
Who is it for?
Four situations where a review is usually worth commissioning.

- Teams approaching launch with an AI-built MVP
- Founders whose prototype works in a demo but breaks on real tasks
- Engineering teams accumulating defects in AI-generated code
- Technical leaders preparing for a security or production-readiness review
The source tool may be Claude Code, Cursor, Copilot or another AI coding tool. The review focuses on the resulting application and how it is operated.
What did a recent audit find?
In an anonymised food-production application, we reviewed 58,000 lines of code and identified four priority findings, including two go-live blockers. The urgent storage exposure was closed in the first week. The broader rebuild was proposed separately.
Stage: audit delivered; rebuild proposed. The rebuild is set out and has not been delivered, so nothing here describes a completed go-live or a post-launch result.
How are the audit and fixes priced?
The review is fixed price for an agreed scope. System size, access, integrations and the depth of testing determine the effort. You keep the findings report whether your team implements the recommendations or asks us to scope the fixes.
The AI code audit: at a glance
- What it is
- A review of an AI-generated or vibe-coded application: security and access, reliability, maintainability and release readiness, scoped against the system and its intended use.
- What you receive
- Prioritised findings with affected areas and recommended fixes, go-live risks within the reviewed scope, gaps in tests and release checks, and a remediation plan you keep.
- What is separate
- Implementation. Remediation, refactoring or a scoped rebuild, test suites, evaluations, CI, monitoring and documentation are scoped and priced as their own piece of work.
- Price
- The review is fixed price for an agreed scope. System size, access, integrations and the depth of testing determine the effort.
- Timetable
- Agreed after reviewing system size, access and the required depth. The audit and any implementation may have different schedules.
- Access
- Confidentiality, access, approved tools and retention arrangements are agreed before access is granted, including how access is removed at completion.
- Limits
- An audit is not a guarantee that every vulnerability has been found, and it is not a substitute for a separately scoped penetration test.
Request a code-audit call
Tell us what the application does, whether it is live and what is causing concern.
Common questions about the code audit
What is a vibe-coded system?
A system built substantially with AI coding tools, often through natural-language instructions. That method alone does not establish its quality. A review examines the resulting code, security controls, tests and operation.
Do you just review, or fix it too?
The audit produces the findings and remediation plan. We can scope implementation separately, or your team can use the report to make the changes.
Will you set up our AI coding agents properly?
We can include coding conventions, project instructions, testing and release checks in a separate implementation scope. The setup should help your team continue developing and reviewing changes.
How long does it take?
We agree the timetable after reviewing system size, access and the required depth. The audit and implementation may have different schedules.
How is our code handled?
Confidentiality, access, approved tools and retention arrangements are agreed before access is granted. We use the permissions required for the review and define how access will be removed at completion.
What do we get at the end?
Prioritised findings and a remediation plan for the agreed scope. If you commission implementation, its deliverables and acceptance criteria are set out separately.
Not sure the application is safe to run on?
Tell us what it does, where it runs and what is causing concern. We will agree the review scope against the system rather than a standard checklist.
The review is fixed price for an agreed scope, and implementation is scoped and priced separately.