You shipped it fast with AI. Here’s what to check before it becomes a problem.
The most common failure modes in AI-assembled stacks — exposed keys in git, RLS disabled by default, Stripe webhooks without signature verification, LLM endpoints with no rate limiting — aren’t exotic. They’re what happens when you move fast and nobody checked the configuration. We review your code and stack with read-only access, find what’s broken, and tell you what it’ll cost to fix. £595 fixed. Delivered in 10 business days.
A configuration and code review conducted with client-supplied read-only access — repo, staging environment, and cloud console. We work from what you hand us. We don’t attempt to breach anything we haven’t been given keys to.
What we don’t do
×Penetration testing — we’re not CREST-accredited and won’t claim to be
×SOC 2 certification — that requires a licensed audit firm
×Production access or any contact with live customer data
Required before we start
A signed one-page authorisation naming the exact systems, the date window, and the scope. In the UK, the Computer Misuse Act makes unauthorised access criminal regardless of intent. We take this seriously and you should too — it’s also what makes the engagement defensible if a finding is ever disputed.
§ 01 / Half one: technical posture
Where vibe-coded stacks typically break.
AI coding tools are good at making things work. They’re not consistently good at making things secure — especially auth, data isolation, and anything involving secrets or rate limiting. These are the checks we run on every review, because they appear often enough to be worth checking by default.
Authorisation and data isolation
Authorisation enforced server-side, not just hidden in the UI. Row-level security actually enabled and actually scoped. Object IDs scoped to the requesting user. In multi-tenant apps, tenant isolation is the finding that kills enterprise deals.
Secrets
What's in the client bundle, what's in git history, what's rotatable. Keys that shipped in a public repo don't become safe just because they've been rotated — the history is the risk.
Webhook signature verification
An unverified Stripe webhook means free subscriptions. It's missed constantly in AI-assembled stacks and is the kind of finding an enterprise security team spots in under a minute.
Rate limiting
On auth endpoints and on any LLM-backed route. The second category is a cost-blowout risk as much as a security one — unprotected inference endpoints can generate four-figure bills overnight.
Operational posture
Backups that have actually been restored from, admin MFA enforced, access review documented, audit logging in place, dependency and CVE status.
§ 02 / Half two: questionnaire gap analysis
Most startups don’t fail on code.
They fail because procurement asks for documents they’ve never written. The deal stalls in legal for three months while nobody knows why. We map your current state against SIG Lite and CAIQ — the frameworks enterprise procurement teams actually use — and flag every question you can’t currently answer.
Common gaps we find
✓Data-processing agreement
✓Subprocessor list
✓Incident response plan
✓Data retention and deletion policy
✓Access control policy
✓Vendor inventory
✓Where is our data stored? — the question that derails more deals than any technical finding
The policy pack
If you want us to produce the missing documents, we quote separately for a policy and questionnaire pack: DPA, incident response plan, subprocessor list, retention policy, access control policy, and a completed SIG Lite. Largely templated, tailored to your stack, and ready to send to procurement.
Policy & questionnaire pack — £900
§ 03 / The report
What you get back.
Structured so the CTO can read it and the founder can forward the verdict to the investor. No CVSS scores — nobody in the room understands them. Findings are split by deal-risk.
A one-line verdict
“You would fail a standard enterprise security review on four items. Three are fixable in a week.” That sentence is what gets forwarded to the board.
Blocker / Serious / Hardening
Blockers are findings that will lose you the deal. Serious findings will delay it. Hardening items are good practice that won’t derail procurement but should be on the roadmap.
Per-finding detail
What, where, why an enterprise buyer cares, and the fix. Written for a developer to action and a CTO to sign off.
SIG Lite / CAIQ gap list
Every question from the standard questionnaire frameworks, with your current answer and a flag for anything you can’t yet answer. This is the document that unblocks procurement.
Remediation quote
Fixed-price, scoped from the findings. Agreed before any work starts.
Policy pack quote
A separate line for producing any missing policy documents. £900 flat if you want us to do it.
§ 04 / Pricing
The audit is the diagnosis.
Item
Price
Notes
Enterprise Readiness Audit
start here
£595
Technical review plus SIG Lite / CAIQ gap analysis. Fixed fee, delivered in 10 business days.
Remediation
£1,500–£4,000
Scoped from the audit findings. Fixed price agreed before any work starts.
Policy & questionnaire pack
£900
Data-processing agreement, incident response plan, subprocessor list, retention policy, access control policy, and a completed SIG Lite. The documents that unblock the deal.
§ 05 / FAQ
Frequently asked questions.
Honest answers to the questions we get asked most.
Is this for vibe-coded apps specifically?
+
It's well-suited to them. AI coding tools produce working code fast, but they skip security considerations that aren't obvious from the prompt — RLS defaults to off in Supabase unless you explicitly enable it, LLM endpoints don't have rate limiting unless you add it, and secrets end up in repos because the AI doesn't know your .gitignore. Whether your stack was built by a team, an AI, or both, the checks are the same. The difference is that AI-assembled stacks have predictable failure modes, which makes the review faster and the findings more consistent.
What access do you need?
+
Read-only repo access, a staging environment, and read-only access to your cloud or Supabase console. Never production, never customer data. Before we touch anything, you sign a one-page authorisation naming the exact systems, the date window, and the scope.
Is this a penetration test?
+
No. This is a configuration and code review conducted with client-supplied read-only access. We don't attempt to breach anything we haven't been given keys to. We're not CREST-accredited, and we won't claim to be. What we do is a technical review and readiness assessment — which is what you actually need before a first enterprise deal.
What's SIG Lite? What's CAIQ?
+
SIG Lite (Standardised Information Gathering) and CAIQ (Consensus Assessments Initiative Questionnaire) are the security questionnaire frameworks enterprise procurement teams typically send to vendors. We map your current state against them, flag every question you can't yet answer, and quote to produce the documents that close those gaps.
What if I have no policies at all?
+
That's the normal starting point. Most seed-stage startups don't fail enterprise security review on code — they fail because they've never written a data-processing agreement or an incident response plan. The policy pack is where we produce those documents for you, templated and tailored to your stack.
Do you guarantee we'll pass an enterprise security review?
+
No. We identify what you'd fail today, prioritise it by deal-risk rather than CVSS score, and quote to fix it. Passing a specific review depends on that review's requirements, your remediation timeline, and the buyer's flexibility — none of which we control.
What do you mean by "blocker"?
+
A blocker is a finding that will lose you the deal — not a finding with a high CVSS score, which nobody in the procurement meeting understands. Examples: no DPA when the customer requires one, multi-tenant data not isolated, production secrets rotatable on customer request but no rotation process documented.
How long does the audit take?
+
Ten business days from receiving access credentials. We'll confirm a start date when you get in touch.
Should I get professional indemnity insurance before engaging?
+
You should — but that's advice for us, not you. We carry professional indemnity insurance on every engagement. If you're offering technical services to clients, it's worth having too.
§ Start
Find out what you’d fail before they ask.
Get in touch with a brief description of your stack and where you are in the sales cycle. We’ll confirm access requirements and get started within a week.