Service reference

Get an AI code review where every line is read and every finding is proven

AI reads your whole codebase in hours. An engineer reproduces every finding before it reaches you, and signs their name to the report.

Clear scope · friendly support · practical advice

The short version

Included as standard

Everything here is covered by the agreed fee. Anything outside it is quoted in advance.

  • Full-codebase review, not a sample
  • Every finding reproduced before it is reported
  • Security review against the OWASP Top 10
  • Findings ranked by business impact, not tool severity
  • An experienced engineer signs off every report
  • Nothing changed in your code without written approval
  • Fixes implemented and verified, quoted separately
  • Full audit trail of what was reviewed, found and fixed

What an AI code review finds that your own team misses

Every developer has had the experience of staring at a bug for an hour, then watching a colleague spot it in ten seconds. Familiarity is comfortable, and comfort is exactly what hides faults.

Now consider the scale. A modest business application is tens of thousands of lines. Nobody reads all of it. Reviews sample the parts that changed recently, which means the quiet corners are never looked at again after the day they were written.

That is where the expensive things live.

How an AI code audit works, step by step

We use AI to read all of it. Not a sample, not the recent commits — the whole codebase, in hours rather than weeks.

Then we throw most of it away.

A raw AI sweep produces hundreds of observations. Many are stylistic. Some are simply wrong. A handful are real, and one or two might be costing you money right now. The work that matters is separating those, and that work is done by an engineer, not a machine.

Every finding we report has been reproduced. We show you the fault happening before we tell you it exists. If we cannot reproduce it, it does not go in the report.

The AI reads your code, it never writes to it

The AI has read access. That is all.

It never commits, never opens a pull request, never touches your repository. Every proposed change is written up, reviewed by an engineer, put in front of you, and applied only once you have agreed to it — on a branch, so it can be undone.

This matters more than it sounds. The risk with AI-assisted development is not that the code is bad. It is that nobody can explain what changed, or why, six months later when it matters. An audit trail is not bureaucracy. It is the difference between a system you own and a system you merely host.

How findings are ranked, and by what they cost you

Most security tools rank findings red, amber and green. That tells you how the tool scores severity, not what a fault is costing you.

We rank by business impact. A theoretical vulnerability in an admin page three people can reach ranks below a validation rule quietly rejecting a segment of your customers at checkout. One is a risk. The other is a bill you are already paying.

To make that judgement we look beyond the code — at your logs, your analytics and where your traffic actually comes from. Faults that matter show up as numbers before they show up as errors.

Code review alongside Cyber Essentials and pen testing

Code review sits naturally alongside the rest of our security work. If you are already certifying under Cyber Essentials or running penetration testing, a code review answers the question those cannot: not “could someone break in”, but “is this code doing what you think it does”.

Many clients take it once, as a baseline. Others attach it to their managed IT support so that every significant release gets a second, independent pass before it reaches customers.

What an AI code review is not

It is not a rubber stamp. If your code is in good shape we will say so, and the report will be shorter and cheaper than you expected.

It is not a tool subscription. You are not buying access to a scanner. You are buying the judgement applied to its output.

And it is not a replacement for your developers. It is the second, independent pass that gives a codebase the distance your own team cannot easily bring to it.

AI code review scope and pricing

Tell us what the code does and roughly how large it is. We will come back with a fixed scope and a fixed price before any work begins, and you will know exactly what you are getting and what it costs.

Tell us what would make IT easier

Share what is causing problems or taking up time. Our London team replies during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report

What you get from us

AI reach with engineer judgement

AI reads in hours what would take a team weeks. What it cannot tell you is which findings matter, or whether they are real. So we use it for reach and people for judgement. Every finding is reproduced before you see it, so your developers never spend a day chasing a ghost.

Repository access and control

The AI never writes to your code. It reads, and it reports. Every proposed change is reviewed by an engineer, approved by you in writing, and applied on a branch you can roll back. You are never left with a change nobody can explain.

A full audit trail

You get a written record of what was reviewed, what was found, what was fixed and what was deliberately left alone. It is the evidence pack your insurer, your auditor or your next investor asks for, and it is yours to keep and reuse.

The faults that look fine in review

Most reviews find code that looks wrong. The expensive faults rarely look wrong at all. They pass every test, throw no errors, and sit quietly in production costing you money. Those are the ones we go looking for.

FAQ

Frequently asked questions

Is an AI reviewing our code safe?

The AI reads your code. It never writes to it. Every change is proposed in writing, reviewed by an engineer, approved by you and applied on a branch you can roll back. We agree the handling rules for your code before we begin, and we can work within your own environment if your policy requires it.

How is this different from a tool like SonarQube or GitHub Copilot?

Automated tools produce a list, and most of those lists go unread because nobody has separated the findings that matter from the noise. We make that separation, reproduce each real finding and have an experienced engineer sign off the report.

What do we actually receive?

A written report of every verified finding, with the steps to reproduce it, ranked by what it costs your business rather than by a tool's severity score. Plus a list of what we checked and found sound, so you get the full picture rather than only bad news. Then a fixed quote for the fixes, so you can plan the work with us or with your own developers.

Do you fix what you find?

Yes, quoted separately so an audit never becomes an open-ended bill. Fixes are applied on a branch, verified before and after, and we add the test or the logging that would have caught the problem sooner. Leaving your team able to catch the next one is part of the job.

How long does it take?

Most codebases are reviewed within a week. The AI sweep is the fast part. Verification is what takes the time, and it is the part worth paying for, because a finding nobody has reproduced still leaves your team to work out whether it is real.

Our developers are good. Why would we need this?

Because good developers are the ones who write code that looks right. Reviews between colleagues catch style and logic, but they rarely catch the fault that only appears when a real customer arrives from a real ad click. A second, independent pass is not a comment on your team. It is how the faults nobody was looking for get found.