← All field notes

AI app security audit cost: scope, report and fixes

Understand Thunkle's security audit starting price, what changes the scope, what your report includes and how remediation and a free re-review fit together.

Sep 19, 2026 · 4 min read


Field Notes from Thunkle, a studio that takes AI-built apps from prototype to secure, production-ready software.

Thunkle's security and code audits start at $750, with a written quote for the agreed application scope. The useful question is not just the price: it is which workflows will be reviewed, what evidence you receive and who will implement the fixes. Confirm the billing currency and terms in your quote.

Our pricing page gives the current starting point. This guide explains the scope behind it. It is not a promise that every app fits the minimum price or that a report certifies the entire business as secure.

What changes the scope

An app with one user role and a small set of records is different from a marketplace with customers, sellers, support staff, payments and scheduled jobs. The number of screens alone does not describe that difference.

A useful scope inventory includes:

  • Accounts, roles and how access is granted or removed.
  • Sensitive records, shared workspaces and file storage.
  • Backend routes, functions and privileged database operations.
  • Payments, webhooks, external APIs and background jobs.
  • The environments and source/configuration access available.
  • Whether writes, payments or integrations can be tested safely in an isolated environment.

A short function that issues refunds may require more scrutiny than a long component that displays public information. A senior developer uses the product rules and reachable behaviours to decide what to test.

Three illustrative scopes, not three price tiers

A customer portal: users upload private documents and staff review them. The review might focus on sign-in, document ownership, file delivery and staff permissions.

A subscription app: checkout changes entitlement and a background process consumes credits. Scope should consider trusted payment events, retries, duplicate processing, cancellation and the checks around paid actions.

A multi-tenant product: users join organizations with several roles. Invitations, membership changes, cross-organization access and administrative actions all need explicit expected outcomes.

These are synthetic examples to help describe your app. They are not completed client audits, priced packages or a guarantee that everything listed is covered by the starting price.

What the report should give you

A useful report explains the affected workflow, observed behaviour, impact, evidence and recommended remediation. It distinguishes validated findings from questions that could not be resolved with the available access.

It also lists scope, exclusions and limitations. A public-only check cannot establish every authenticated workflow. A source review alone does not prove the production configuration matches the repository. Good evidence makes those distinctions visible.

Read our illustrative security audit report to see the format before requesting a quote.

Does the audit include implementing fixes?

The audit provides findings and remediation guidance. Fix implementation is scoped separately unless your written proposal explicitly includes it. You can have your own developer apply the changes or ask Thunkle to quote that work.

The agreed fixes receive a free re-review. We repeat relevant checks and record the result. A changed code snippet is not, by itself, proof that a deployed permission boundary now holds. New features, a wider environment or unrelated changes may require additional scope.

Why pay for developer review if a scanner is available?

Use the platform's security checks and other useful automation. They can identify real issues and reduce repetitive work. The paid review adds a defined model of your product's permissions, contextual validation and tests of the agreed application paths.

For example, a customer may legitimately share a record with a teammate but not with another organization. The expected result depends on your membership rules. A reviewer needs to understand that requirement before deciding whether observed access is correct.

Our security audit service explains the engagement. The platform security guides help you prepare an inventory.

What to send for an accurate quote

Describe your platform, account roles, important workflows and the data categories the app handles. Tell us what is already live and what would make testing disruptive. Mention your deadline and whether you also want implementation support.

Do not attach production credentials, customer records or full database exports to an enquiry. We arrange the minimum necessary access securely after agreeing how the work will run.

Request a developer-led audit quote. You should know the scope, price, deliverables and exclusions before work begins.

Is the cheapest review the best place to start?

A small, clearly bounded review can be useful. A low price without defined coverage is harder to evaluate. Compare what is tested and delivered, not just the headline number.

Is this a compliance certification?

No. A code or application security audit is not automatically a certification, legal opinion or complete compliance assessment. Those requirements need separate expertise and scope.

Can an audit guarantee there are no vulnerabilities?

No audit can guarantee that. Findings describe the tested scope and version at the time of review, with explicit limitations. Ongoing changes need appropriate checks of their own.

Know what needs fixing before you ship.

Get a scoped developer review, evidence-backed findings and remediation guidance, with a free re-review of agreed fixes. Fix implementation is quoted separately.