An audit of how your
team actually uses AI
We audit how your team actually uses tools like Claude, Copilot, and ChatGPT by analysing the sanitised findings from your on-premises codebase scan. Then we turn what we find into four detailed reports including team-wide training guidance and a code of conduct your whole team can actually follow.
What the audit covers
Four stages, from one local scan to four client-facing reports.
On-premises codebase scan
Your team runs a simple point-and-click app on your own infrastructure. It scans against 20 specific rule types: 7 kinds of hardcoded secrets, code quality markers like TODOs and untested files, and 6 AI-usage signal patterns including co-authored AI trailers, hallucinated dependencies, boilerplate comments, and generic commit messages. The tool uses only local Git commands, and the scan itself makes zero network connections. It strips every secret, code snippet, and real name before writing anything to disk. You send us only one sanitised JSON file. Your source code never leaves your premises.
- warningScans 7 types of hardcoded secrets
- psychologyDetects 6 AI-usage signal patterns
- dnsRuns on your own infrastructure
Findings analysis and team audit
We take the sanitised data and map how your team uses AI day to day. The scanner gives us the raw signals: co-authored AI trailers, hallucinated dependencies, boilerplate comments. We connect the dots into a team-wide picture: how much of the codebase shows careful use, how much shows AI pasted in without a second thought, how much shows avoidance, how much shows AI used well but inefficiently. Every finding is tied to a specific file and commit, so the report speaks to real behaviour, not generalisations - no individual developer is ever named or identifiable.
- person_searchTeam-level risk signal
- local_fire_departmentFlags AI overuse patterns
- hourglass_bottomIdentifies AI avoidance and waste
Report and policy delivery
You get four branded PDFs. The technical audit report lists every finding with file, line number, and commit. The management summary puts the same facts in plain language with urgency-ranked actions. The best practices plan gives your leads a blueprint for internal standards. And the AI training guide gives your team focus areas and suggested practices based on real patterns in your codebase. No developer is ever named in any of the four reports.
- descriptionDrafts a practical policy
- groupsPlans for team adoption
- summarizeDelivers a final audit report
Repeat scans, same flat fee
AI tools and team habits keep moving, so a scan from six months ago goes stale. Book another one-off scan whenever you want a fresh read: it's the same flat fee every time, not a subscription. Each report compares against your original audit baseline so you can see exactly what changed.
- paymentsOne flat fee, no subscription
- radarDetects new leakage
- trending_upTracks drift from audit baseline
Ready to see how your team is really using AI?
Tell us about your team and we'll scope an audit. It's one flat fee, paid once, and there's no subscription to sign up for.