// services — 04_assurance

secure code review

AI-generated code, reviewed like it matters. Threat modeling, dependency and supply-chain checks, and hardening before anything reaches production — from a practice that does this for a living.

// scope

what we review

ai-generated code

Code written with Claude, Copilot, or any other assistant — reviewed for the failure modes AI actually produces, not just the classic ones.

dependencies & supply chain

What your code pulls in, what that pulls in, and whether any of it should worry you.

architecture & access

Threat modeling, authentication and authorization, secrets handling, and the blast radius when something fails.

// deliverables

what you get

  • Findings ranked by severity, each with a concrete fix — not a wall of raw scanner output.
  • Fixes applied by us or fix guidance your team executes — your choice.
  • A re-review that confirms the fixes actually landed.
  • A threat model your team can keep updating after we’re gone.
  • The same scrutiny verrou applies to client production systems — same hands, both jobs.
// approach

how it runs

phase 1 — scope

agree the target

We scope the codebase, the deployment, and what an attacker would actually want from it.

phase 2 — review

read it like an attacker

Manual review backed by tooling — threat model first, then the code, the dependencies, and the configuration.

phase 3 — harden

fix and confirm

Findings become fixes, fixes get re-reviewed, and you end with a report you can show customers and auditors.

// next step

shipping ai-written code?

Before it reaches production, let people who break software for a living read it. Thirty minutes is enough to scope the review.

Book a consult