AUDIT · 3 DAYS · €2,400 EXCL. VAT

AI-generated codebase audit: what holds, what has to be redone

Your product was built fast, often with the help of an AI assistant. It works. But you have a threshold to cross — first real users, a raise, an enterprise client’s audit, a sharp rise in user numbers — and nobody can tell you what will hold.

Who it is for

Founder or technical director whose product is already running, and who has to answer to someone — an investor, an enterprise client, a board — for what happens next.

Ce que je fais

I first surface the rules your system is supposed to guarantee in all circumstances: yours, those of your trade, rather than a list of generic good practice. “A validated invoice can no longer be modified.” “A client never sees another client’s data.” “A displayed price never differs from the price charged.” You give me three or four in two minutes: these are your fears, and they are written down nowhere. I then examine the paths by which you would lose data or money, the separation between your different clients’ data, your dependence on components you do not control, and what you would know of an outage at the precise moment it happens.

  1. D1

    Reading

    I take the measure of the system and surface its implicit rules — what your business forbids, and that nobody has written down anywhere.

  2. D2

    Testing

    I look for what prevents those rules being breached. Nine times out of ten, nothing prevents it: they hold because nobody has tried yet.

  3. D3

    Reporting back

    I rank, I cost in days, and I write it all in a language a non-technical decision-maker can read without a translator.

What you receive

  • A written report: what to keep, what to redo, what to throw away
  • For each point, what it costs if it is ignored
  • A sequenced repair plan, estimated in days
  • An hour of reporting back, with your team if you wish

The scope

The audit stops at the map and the plan: where to go, in what order, and what each postponement costs. Three days are enough to know, and that is what keeps it readable. The repair work is the next job, which you entrust to your team, to someone else, or to me.

Après

The guardrails, if the audit concludes that the problem is not this or that line of code, but the absence of everything that should have refused it.

The questions I get asked

Why three days, when others propose two weeks?

Because three days are enough to say where to go. The audit is deliberately short: it leaves you free on what follows. You entrust the repair work to your team, to someone else, or to me — and it is in my interest that this be a choice.

Will my team take it as an inspection?

The report names rules, not people. What is written is that a rule can be breached with nothing to signal it: that is a failure of apparatus, not of discipline. The report is presented to your team during the hour of reporting back, and whatever they had already identified is noted there as such.

Who can read the report?

You. That is the writing criterion: what to keep, what to redo, what to throw away, and for each point what it costs if it is ignored. The technical detail is in an appendix, for your team.