Know if your software holds up.
Before someone else finds out.
Trust. But verify. Your software was built with AI tools or by an outside team, and you can't check the code yourself. In an AI code audit, I review it and tell you in plain language where it is at risk and what to fix first. Report in five working days.
Without obligation. You know the price before anything starts.
What an audit checksWhy people get in touch
You might recognize one of these.
- You built your software fast with AI tools, and you're happy with it. You just don't know what's inside.
- An agency or freelancers built it for you. The invoices are clear. The code isn't.
- An investor, a buyer or a large customer is about to ask questions you can't answer yet.
- Your developer says everything is fine, and you'd like to hear that from someone who didn't build it.
What a code audit is
An audit is an independent review of your software by someone who didn't build it. I read the code and look at how it runs. You get a written report that says in plain language what is fine, what is risky and what to fix first.
What I check
- Security. Who can get in, see or change what they shouldn't.
- Your data. Where it is stored, who can reach it, and whether it is saved and calculated correctly.
- Outside building blocks. The third-party code your software relies on, and whether parts of it are outdated or have known holes.
- Speed and running costs. How the software copes with more users, and what each new customer costs you in servers.
- Maintainability. Whether another developer could take over the code tomorrow.
- Tests and releases. How changes are checked before they go live.
- Operations. Backups, monitoring, and how passwords and access keys are handled.
- Technology choices. Whether the chosen tools fit what the software has to do.
“My software works”
It does what you can see. An audit looks at what you can't see. Software can work every day and still:
- show one customer's data to another,
- slow to a crawl at 1,000 users when it was tested with ten,
- cost more in servers every month than it needs to,
- depend on the one developer who understands it.
Problems like these stay invisible until a customer, an investor or an attacker runs into them.
None of this means you did something wrong. Building fast with AI tools or an outside team is a sensible choice. Having the result checked is the next one.
“I can ask my agency or the AI”
You can, and you should. Two things get in the way.
- You have to know what to ask. The risks that matter have names only engineers use: injection, privilege escalation, vulnerable dependencies. If you don't ask, nobody answers.
- The answer comes from whoever built it. An AI model can sound certain and still be wrong. An agency is grading its own work. Both may be right, and you can't tell which answers to trust.
An audit gives you an answer from someone who didn't build the software and has no reason to make it look good.
Trust. But verify.
Questions you have probably not asked
These come up in software that works fine every day. The small line under each question is what an engineer would call it.
-
Can a normal user give themselves admin rights?
Privilege escalation
-
Can someone send commands to your database through a form on your website?
Injection
-
Can a customer see another customer's data by changing a number in the web address?
Broken access control
-
Are passwords or access keys written into the code, where anyone with access to it can read them?
Secrets in code
-
Which of the outside building blocks in your software have known security holes?
Vulnerable dependencies, supply chain risk
-
If your database were deleted today, how much would be lost, and how long until you're back?
Backup and recovery
-
Where is your customers' data actually stored, and who else can reach it?
Data location, GDPR
-
Would you notice an attack, or would your customers tell you?
Logging and monitoring
-
What does each new customer cost you in servers, and does that grow faster than your revenue?
Efficiency, scalability
-
Could another developer take over the code tomorrow?
Maintainability
Each of these can be checked and fixed. The hard part is knowing where to look.
Find out which of these apply to you.
What is at stake
- 45% of coding tasks in Veracode's test of more than 100 AI models produced code with a security flaw (2025). Source: Veracode via Business Wire
- €45,370 was the average loss per cyber insurance claim in Germany in 2023. Source: GDV
- $4.99M is the average cost of a data breach worldwide (IBM, Cost of a Data Breach Report 2026). Source: IBM
- €20M or 4% of worldwide annual turnover, whichever is higher, is the upper limit for GDPR fines. Source: GDPR, Article 83
And if the code has to be rewritten: two engineers for six months at €95 an hour come to €182,400 (2 × 960 hours × €95, with 960 hours = 6 months × 20 days × 8 hours).
Software is never finished
Software that is safe today can be unsafe next month without anyone touching it. New security holes are published every day in software and in the building blocks it is made of: 48,185 in 2025, about 132 a day (2025 CVE data review; 48,185 ÷ 365 = 132). Software needs updates, regular checks and someone who keeps an eye on it. An audit shows you where you stand today and what to do first.
The risk stays with you
If something goes wrong, nobody blames the AI or the agency. Customers, partners, investors and authorities hold your company responsible.
From 9 December 2026, software is a product
- New EU product liability rules (Directive 2024/2853) count software as a product, whether installed, in the cloud or sold as a service, AI systems included. They apply to products placed on the market after 9 December 2026, in every EU country. Germany is implementing them with a new Product Liability Act.
- If an agency built the software you offer your customers, you count as its manufacturer.
- The manufacturer is liable without fault when defective software harms people, their property or their private data. The liability cannot be limited by contract or by national law. Claims are possible for ten years, for some injuries 25.
- Missing security and missing security updates can make software defective.
- Courts can order a manufacturer to disclose evidence. If it does not, the product is presumed defective.
An audit documents that you had your software checked, by whom and with what result.
This is a summary, not legal advice. The report shows which rules your software touches and gives you the questions for your lawyer.
Know where you stand before 9 December.
What you get
-
A one-page verdict. A traffic light per area and an overall verdict in plain language, written for the person who decides.
-
Every finding ranked by urgency: fix now, within 30 days, later.
-
A cost range for fixing each point.
-
A liability map: which rules your software touches (product liability, the Cyber Resilience Act, GDPR, the rules of your industry), written as questions for your lawyer.
-
A 90-day plan: what comes first and who should do it.
-
A signed summary you can hand to investors, buyers and large customers.
-
A 60-minute walkthrough. Bring your team, your agency, your investor or your lawyer if you like.
-
A re-check within 90 days, once the urgent points are fixed.
How it works
-
First call, 15 minutes
You tell me where you stand. I ask a few questions and tell you honestly whether an audit makes sense for you. If it does, you get a fixed price before anything starts. If it doesn't, I'll say so.
-
Access
Read access to the code and the documentation, an overview of the infrastructure and 30 minutes with the person who knows the system best.
-
Review, five working days
I lead the review and sign the report. For larger systems, senior engineers from my team join.
-
Walkthrough, 60 minutes
You get the report, the summary and the liability map, and we go through them together.
-
Re-check
Once the urgent points are fixed, I take another look.
Who reviews your software
- Startups, bootstrapped and venture-backed. I have worked in both. As head of engineering at Flowcarbon, a New York startup backed by Andreessen Horowitz, I built platforms that had to scale. As a mentor at Techstars Berlin, I see what investors look for, which is why the report is written so that an investor can read it.
- Banks, an exchange and global brands. I have delivered software for Deutsche Börse, Landesbank Berlin and Berliner Sparkasse, and for Daimler, HUGO BOSS and Amazon. I know what large organizations expect from software before it goes live.
- Agencies, from the inside. I built a software agency and sold it. I know how agency projects are planned, priced and handed over, and which questions to ask.
- Health care under strict rules. Today I build health platforms that have to meet Germany's strict requirements for security and data protection. Looking for risk is part of my daily work.
I lead every audit and sign every report. For larger systems, senior engineers from my team join me. You always talk to me.
Two guarantees
On time
Your report arrives five working days after I have everything I need to start. If it is late, you pay half.
Worth it
You decide whether the audit was worth its price. If it wasn't, tell me within 14 days of receiving the report and you pay nothing.
Conditions
- On-time guarantee. The five working days start once complete read access to the code and documentation, the infrastructure overview and the kickoff call are in place. Working days are Monday to Friday, excluding public holidays in Brandenburg. If the report is delivered later, the fixed price is reduced by 50%. Delays caused by the client (missing access, contacts not available) extend the period accordingly.
- Value guarantee. If the client feels the audit was not worth its price, the client can say so within 14 days after receiving the report. The fixed price is then refunded in full, or not charged if it has not been paid yet.
- The audit is a professional assessment at the time of review. It is not legal advice and does not warrant that the software is free of defects or compliant with any law.
When I'm not the right fit
-
You need legal advice
That's a lawyer's job. I give your lawyer the right questions.
-
You want a certificate or a guarantee that your software has no defects
Nobody can honestly give you that.
-
Your software is a prototype without users, revenue or funding
The cost won't pay off for you yet.
Questions
What does the audit cost?
A fixed price that depends on the size of your software. I name it in the first call, before anything starts.
Do you need access to our data?
No. I review the code, the documentation and how your software is set up. I don't ask for access to your live data, and I don't need it. Your customers' data stays where it is.
An agency built our software. Will they take this as an attack?
A good team welcomes a second opinion. The audit is about the code, and the report gives your agency a clear list to work through.
We have our own developers. Is this still worth it?
Your team reviews its own code from the inside. An outside review finds different things, and you have it on record if you later need to show what you did.
What happens after the audit?
You decide. Your team or your agency fixes the points, with the report as a guide. If you prefer, my team does it, or I stay on as your part-time CTO.
Do you also work for investors?
Yes. If you want to invest in or buy a software company, I review it before you sign. The process is the same, and the report adds points for the term sheet or the purchase agreement.
You've already taken the first step
You're here because you want to know where your software stands. The next step is a 15-minute call with me. You tell me what you've built and what's coming up. I ask a few questions and tell you honestly whether an audit makes sense. If it doesn't, I'll tell you that too.
Nothing to prepare, and no code needed for the call.
Without obligation. Prefer to write first? hello [at] alexgutjahr.com