How our audits work

The audit process

A four-stage audit of how your team actually uses AI coding tools. Your source code stays on your machines: you run our scanner locally, send us only a sanitised summary, and get back four detailed reports including team-wide training guidance and a practical policy your whole team can follow. Here’s a video demo of how the audit works too.

01

On-Premises Codebase Scan

Your team runs a simple point-and-click app on your own infrastructure. It scans your repository against 20 specific rule types covering 7 kinds of hardcoded secrets, code quality and maintainability checks, and 6 AI-usage signal patterns. The tool uses only local Git commands and the scan itself makes zero network connections and sends no telemetry. It strips every secret, code snippet, and real name before writing anything to disk. You send us only one sanitised JSON file. Your source code never leaves your premises.

  • Scans for 7 types of hardcoded secrets
  • Detects 6 AI-usage signal patterns
  • Zero network connections during the scan itself
  • Runs in under a minute on your infrastructure
02

Findings Analysis

We take the sanitised data and map how your team actually uses AI day to day. Some people paste everything into ChatGPT without a second thought. Some refuse to touch it. Some use it well but burn through tokens doing it inefficiently. We track hardcoded secrets in source files, hallucinated dependencies, co-authored AI trailers in commit messages, and untested code. Every finding is tied to a specific file and commit - no individual developer is ever named or identifiable.

  • search_insightsTeam-level risk signal, no individuals named
  • search_insightsSecrets and proprietary code leakage flagged
  • search_insightsHallucinated dependency detection
03

Report and Policy Delivery

You get four branded PDFs, not one generic summary. The technical audit report lists every finding with the file, line number, and commit it came from. The management summary puts the same facts in plain language with actions ranked by urgency. The best practices plan gives your leads a blueprint for internal standards. And the AI training guide gives your team focus areas based on real patterns in the codebase, with no developer named in any of the four reports.

  • Technical audit report with per-instance tables
  • Management summary with urgency-ranked actions
  • Best practices plan for team leads
  • Team-wide AI training guide, no names attached
04

Repeat Scans, Same Flat Fee

AI tools and team habits keep moving, so a scan from six months ago goes stale. Book another one-off scan whenever you want a fresh read: it's the same flat fee every time, not a subscription. Each report compares against the baseline from your original audit.

verified
Audit Complete
New leakage detection

Built From Real Data

Every recommendation traces back to a specific commit and file in your actual codebase. Not a generic checklist.

No Workflow Disruption

The scanner runs on your infrastructure in under a minute. Your team keeps shipping. You send us one small JSON file and get back four detailed PDFs.

One Flat Fee

A one-off audit gets you the full picture and a policy, for one flat fee. Come back for another one-off scan whenever you want a fresh read. It's never a subscription.

Ready to see how your team uses AI?

Book an audit