Know exactly what is wrong with the app, in writing, in a week.
A fixed-fee, independent check of an AI-built app: security, data handling, authentication, tests, hosting and cost. You get a written report with a fix, refactor or rebuild verdict, not a sales conversation dressed up as one.
- Fixed fee, no hidden scope
- 3-5 working days to a written report
- Fee credited if you go on to a rescue
An app can look finished and still be a liability.
A working demo tells you the happy path works. It does not tell you whether another user can read your customers' data, whether the database survives Black Friday traffic, whether a leaked API key is quietly running up a bill, or whether anyone could restore the last backup if they had to. Those questions do not show up by clicking around the app. They show up in the code, the infrastructure settings and the account dashboards behind it.
The diagnostic audit answers them in writing. It is the same process we run before any AI App Rescue, sold on its own for founders, boards and investors who want an honest, independent answer before they commit to a fix, a rebuild or an investment decision.
Seven areas, the same ones every time.
A named engineer works through your live codebase and infrastructure, not a questionnaire.
Security
Authorisation on every route, tenant and row-level isolation, where secrets and keys actually live, and whether admin functions are reachable by anyone who guesses the URL.
Data
Backup schedule and whether a restore has ever been tested, schema design against real volumes, and whether production and development share a database by accident.
Auth
How users are authenticated, whether sessions expire sensibly, and whether roles and permissions are enforced on the server rather than hidden in the interface.
Tests
Whether an automated test suite exists at all, what it actually covers, and how confidently a change can be shipped without a human clicking through everything by hand.
Hosting
Where the app runs, what happens under load, whether staging and production are properly separated, and how a deploy could take the site down.
Cost
What the current setup actually costs to run at today's volume and at ten times it, and where a metered API or database tier could produce a surprise bill.
Code quality
How maintainable the codebase is for the next developer, whether it was built with tests and structure in mind, and how much technical debt sits under the surface.
Three to five days, start to written report.
- 1
Access
You grant read access to the repository and the relevant dashboards: hosting, database, and any AI or payment provider in use. Nothing is changed at this stage.
- 2
The check
A senior engineer works through the seven areas against your actual code and configuration, not a generic checklist copied between clients.
- 3
The report
A written document scoring each area, listing specific findings with severity, and ending in one recommendation: fix, refactor or rebuild.
- 4
The call
Thirty minutes to walk through the findings and answer questions, with no obligation to book anything further.
Not sure which of these fits? Twenty minutes on a call usually settles it.
A report you can act on or hand to someone else.
| Included | |
|---|---|
| Format | A written PDF report, plain English, with a technical appendix for a developer |
| Findings | Every issue found, ranked by severity, with what it means in business terms |
| Verdict | One clear recommendation: fix in place, refactor parts, or rebuild |
| Estimate | An indicative range for the fix or rebuild, confirmed once scoped |
| Credit | The full £495 fee credited against the rescue if you go ahead within 60 days |
The report is yours regardless of whether you go further with us. Some clients take it to another developer to action.
Who commissions this, and when it is not needed.
A good fit
- An AI-built app now carrying real customers, data or payments
- A founder or board wanting an independent second opinion before investing further
- An investor or acquirer doing technical due diligence on a target
- A team unsure whether to fix, rebuild, or shut the project down
Not this, yet
- The app is a personal project with no real users or data at risk
- You already have a trusted developer who has reviewed it thoroughly
- You want ongoing code review rather than a one-off written verdict
Not sure which of these fits? Twenty minutes on a call usually settles it.
Most founders can tell you what their app does. Very few can tell you what happens when it goes wrong. The audit answers that second question in writing, before it becomes an incident.
A short, honest report, not a long engagement.
Included
- A written report within 3-5 working days
- A fix, refactor or rebuild verdict
- A follow-up call to talk through it
Not included
- Any code changes or fixes, unless a rescue is booked separately
- Ongoing monitoring or a retainer
- A penetration test against production traffic
Not sure which of these fits? Twenty minutes on a call usually settles it.
Questions people ask before they book.
Do you need the original developer involved?
No. Most audits are run on code we did not write and a builder we have never used before. It helps if someone can answer questions about intent, but it is not required.
What access do you need?
Read access to the code repository and the dashboards for hosting, database and any third-party APIs in use. We do not need write access or production credentials to run the check.
Is £495 the final cost?
Yes, for the audit itself. It is a fixed fee regardless of what is found. Any fix or rebuild that follows is quoted separately once the report is in.
What if we disagree with the verdict?
The report lists every finding with its severity so you can judge for yourself. You are free to take it to another developer, or to fix only the parts you agree matter.
How is this different from a normal code review?
A code review usually looks at the code alone. This also checks the live infrastructure, the account settings, the cost exposure and the data handling, because most of the risk in an AI-built app sits outside the code itself.
Can this be used for due diligence on an acquisition?
Yes. We run this for investors and acquirers assessing a target's technical risk, with the report structured for a non-technical board to read.
Does the fee really come off a rescue?
Yes, in full, if you book AI App Rescue work within 60 days of the report. There is no separate discovery fee on top.
The other ways in.
AI App Rescue
The fix or rebuild that follows the audit, when the verdict calls for one.
From £4,500AI Web & App Development
A from-scratch build, fixed price and date, when there is no existing app to audit.
From £4,500AI Governance & Compliance
For businesses that need the policy and audit trail alongside the technical fix.
From £2,500Get the written answer before you spend another pound on it.
Book a call to scope the audit, or go straight to booking one against your repository. Five days to a plain answer.