Audit standards & assurances
Here is how we handle the standards and safeguards behind every audit, so your team's pull requests, codebase, and proprietary code stay on your premises throughout.
Confidentiality & data handling
The scan itself runs on your own machines with zero network connections. Your source code stays on your infrastructure throughout. Only one sanitised file ever leaves your premises - a findings summary with no real names, no secret values, and no code snippets - and only when your team sends it, whether through our optional one-click, consent-gated send or by emailing it yourselves. No individual developer is ever named or identifiable in that file or in anything we produce from it.
Every audit produces four documented reports and a usage policy, reviewed against a consistent internal reporting standard before they reach your team.
Methodology
- 01Audit methodology standard
Every audit follows a documented internal process for reviewing codebases and AI usage. Findings are consistent, repeatable, and defensible.
What the audit covers
Every engagement audits the same ground: pull requests, codebases, and day-to-day AI usage across the team. We check for hardcoded secrets, hallucinated dependencies, co-authored AI trailers in commit messages, boilerplate comments, and untested code, then assess it all against one consistent internal methodology.
How we protect your data
Book an audit
Book an audit and we will review the sanitised findings from your scan, map your team's AI usage patterns, and turn what we find into four detailed reports including a practical policy your team can follow.