The Audit Process
A four-stage audit of how your team actually uses AI coding tools day to day, turning what we find into a practical policy everyone can follow.
Intake & Scoping
Intake & Scoping
We start by getting scoped access to what matters: recent pull requests, the codebase, and whatever AI tool logs or usage data your team already has. No disruption to anyone's workflow while we look.
- Access to the repositories that matter
- Recent pull requests pulled for review
- AI tool usage exports collected (Claude, Copilot, ChatGPT)
Usage Pattern Analysis
We map how the team actually uses AI day to day - who's careful, who's reckless, who's avoiding it entirely, and who's being safe but wasting time and budget doing it inefficiently.
Findings Review
Findings Review
The risky and wasteful patterns we found, laid out plainly with real examples pulled from your own PRs and prompts - not hypotheticals.
- Flagged: instances of unredacted API keys in prompts
- Flagged: proprietary source pasted into consumer AI tools
- Flagged: engineers not using AI tools at all
Report & Code of Conduct
You get a written audit report plus a practical internal AI usage policy your team can actually adopt. Want us to keep checking? We also offer ongoing monthly retainers for companies who want to catch new leakage or issues after the policy lands.
Built From Real Usage
Every recommendation traces back to something we found in your actual PRs and prompts, not generic best practice.
No Workflow Disruption
We review what's already there. Your team keeps shipping while the audit runs in the background.
Retainer Option
A one-off audit gets you the policy. A monthly retainer keeps checking the team stays compliant with it.