Secrets & credentials
Client bundles, repositories, history, and configs, swept for exposed API keys, tokens, and credentials, the classic vibe-code leak.
A fixed-price, two-week security audit and architecture review for products built with AI: vibe-coded apps, Cursor and Claude Code projects, AI-accelerated builds. AI does the exhaustive sweep. A senior engineer verifies and signs every finding. You get a report and a fix roadmap you can act on the same day.
of AI-generated code contains at least one vulnerability, across published studies
CVEs attributed to AI-written code by March 2026, up from 6 in January
API keys leaked to the public by a single vibe-coded app
The product works, users are in it, and the honest truth is that no senior engineer has ever reviewed what the AI wrote.
API keys in the client bundle, credentials in the repo history, tokens in a config file. The most common AI-code failure, and the most public one.
A due-diligence list or a security questionnaire landed, and there's no audit, no report, and no one who can answer with a straight face.
Every new feature stacks onto foundations nobody has inspected. The cost of looking never gets smaller.
Six passes over your product, from the code itself to the cloud it runs on.
Client bundles, repositories, history, and configs, swept for exposed API keys, tokens, and credentials, the classic vibe-code leak.
Auth flows, session handling, and authorization boundaries: who can see what, and what an attacker can reach by just changing an ID.
Prompt injection paths, model endpoints open to abuse and runaway spend, and customer data quietly flowing to third-party AI providers.
Every package checked against known CVEs, including the abandoned and hallucinated dependencies AI assistants love to import.
Storage buckets, CORS, security headers, TLS, and infrastructure-as-code, reviewed for the misconfigurations that turn incidents into headlines.
Data flows, tenancy boundaries, and scaling hazards: whether the shape of the system can carry the business you're building on it.
AI gives the audit its reach. Human judgment gives it its value. You get both, on a fixed clock.
Days 1 to 5. With read-only access, we run an exhaustive AI-assisted review of your code, dependencies, configuration, and public surface. Every file gets read, which is exactly what has never happened to this codebase.
Days 6 to 9. A senior engineer reproduces and triages everything the sweep surfaced, kills the false positives, and rates what's real by severity and exploitability. Every finding in your report is human-verified and signed.
Days 10 to 14. You get a written report with an executive summary you can hand to investors, plus a prioritized fix roadmap: what to fix now, what to fix soon, what to consciously accept. We walk you through all of it on a call.
Security work sold vaguely is security theater. Here is the exact shape of the engagement, so you can compare it honestly against a $15,000 pentest or a compliance program.
An application-layer security audit and architecture review for small and mid-sized products: code, dependencies, secrets, cloud configuration, and AI-specific risks, with a prioritized fix roadmap.
SOC 2 or compliance preparation, a formal attestation penetration test, or continuous monitoring. If that's what you need, we'll say so on the first call and point you to the right firm.
AI-generated security reports are notoriously noisy. Ours are verified, reproduced where safe, and signed by a senior engineer who has done security work since 2016.
Active testing against running systems happens only under a signed engagement with written authorization. That's non-negotiable, and it's how you should demand any security vendor behaves.
The audit is a fixed fee between $4,500 and $7,500, set on the first call based on the size of your codebase and surface area. Classic penetration tests for the same ground typically run $10,000 to $30,000: we can price below them because a boutique team running AI-native tooling doesn't carry their overhead.
Book a Free 30-Min Call →Two weeks: exhaustive sweep, human-verified findings, written report with executive summary, prioritized fix roadmap, and a walkthrough call.
If you want the findings handled for you, we remediate the roadmap and take ongoing ownership of your technology as your fractional CTO.
About the fractional CTO engagement →We're not a scanner with a landing page. As fractional CTO of a New York promotions agency, we built and still run Receipt Rewards, an OCR receipt-validation platform processing promotions for Unilever, Knorr, Hellmann's, Scotch, Fandango, and Novamex: 100,000 receipts across 3 to 6 national campaigns a year, in production for eight years. The same engineers who build systems like that are the ones reading your code.
“Always available, endlessly patient in explaining every decision, calm in every emergency, and the quality of the platform has never let us down.”
Anything shipped with heavy AI assistance: built with Cursor, Claude Code, Copilot, or Bolt, vibe-coded from prompts, generated by an agency racing on AI tooling, or an existing codebase that grew fast with AI in the loop. If most of the code was written faster than it was read, this audit is for you.
A fixed fee between $4,500 and $7,500, set on the first call based on the size of your codebase and surface area. No hourly meter, no scope drift. You know the number before we start.
No. AI gives us exhaustive coverage: every file, every dependency, every config gets read. But raw AI security output is notoriously noisy, so a senior engineer with an infosec background since 2016 reproduces, triages, and signs every finding in the report. You never see an unverified model dump.
The audit is primarily code, configuration, and architecture review under read-only access. Any active testing against running systems happens only under the signed engagement, with written authorization for exactly what will be tested.
No, and we say so up front. This is an application-layer security audit and architecture review for small and mid-sized products: code, dependencies, secrets, cloud configuration, and AI-specific risks. If you need a formal attestation pentest, SOC 2, or continuous monitoring, we'll tell you and point you to the right kind of firm.
You get a prioritized roadmap your team can execute on its own. If you'd rather have us fix it and run it, that's our fractional CTO engagement: we remediate the findings and take ongoing ownership of your technology.
Bring your product to a free 30-minute call. We'll tell you honestly whether the audit is worth it for your stage, and quote you a fixed number on the spot.
Book a Free 30-Min Call→