Code audits for Claude Code projects.
Claude Code can build an entire application with minimal supervision, which means entire applications now ship that no engineer has read. We read them: every route checked for authorisation, every secret traced, every access rule tested with real accounts.
Why it matters
The stronger the agent, the bigger the diff nobody reviewed. Claude Code produces coherent, working systems, and the failure mode changes accordingly: not broken syntax, but decisions that were never surfaced. Which routes require auth. Whether one user can read another's records. Where the service key lives. The agent resolves each of these somehow, plausibly, and moves on. Testing your own app will not reveal the wrong choices, because from one account everything looks correct. Of the 1,236 AI-built apps we have scanned, 21 came back clean, and agent-built codebases are not the exception.
What you get.
Access control review
Every route, action and endpoint checked for authorisation, then verified live with two real accounts, including admin surfaces that check a session exists but never check the role.
Secrets and key handling
Keys in client bundles, credentials in the repository or its history, and privileged tokens reachable from the browser. Anything that has shipped to a client is treated as already compromised.
Logic review of money and data paths
Payments, auth flows and data writes traced end to end, looking for the edge cases the agent's happy path never met.
Configuration and leftovers
Security headers, CORS, rate limiting, source maps, debug endpoints, and the agent's working files, prompts and notes that sometimes ship to production and hand an attacker a head start.
Prioritised report
Every finding rated by severity with a concrete fix, written precisely enough to hand straight back to the agent if that is how you work.
Free re-review
Once the fixes land, we verify them at no extra cost and confirm nothing new opened up.
How it works.
- 01
Access
You give us read access to the repository and a short walkthrough of what the app does and who should see what.
- 02
Review
We read the codebase and test the live app by hand, with real accounts, not just with automated scanners.
- 03
Report
You get a clear, prioritised write-up within days, plus a call to walk through it and the fix for each finding.
- 04
Re-review
After the fixes are applied, by you, by us or by the agent, we verify they hold.
Common questions.
- Claude wrote the code. Can't Claude audit it?
- Asking an agent to review its own output inherits its blind spots: the decisions it never surfaced the first time will not surface in review either. And the expensive flaws live between two accounts, which takes a person signing in twice and comparing what comes back. Automated review is a useful first pass; it is not this.
- What do you check?
- Authorisation on every route verified live with two accounts, secrets in bundles and repository history, the logic of payment and data flows, database access rules, and deployment configuration including leftover agent artifacts. Every finding comes with a severity and a fix.
- What do you need from me?
- Read access to the repository and a short walkthrough of what the app is meant to do. If the app has real users, two test accounts help, though we can usually create our own.
- Can you fix the issues, not just find them?
- Yes. We can make the fixes ourselves, or write each finding as an instruction you feed back to Claude Code. Either way the free re-review confirms the result held.
- How much does a Claude Code audit cost?
- It is scoped to a fixed quote up front, with no hourly meter, and typically starts around $750 depending on the size of the codebase. You will know the price before we begin.
Related services.
Let's build something real.
Tell us about your app or idea. You'll get a clear plan and a fixed quote back within 24 hours.
