← Andrii Naidenko

Code audits

Know what to fix in your codebase, and what can wait.

An independent audit before a launch, a fundraise or a handover. I run it on Auditdesk, a workbench I built for it: scanners first, then an AI agent per aspect, and my own review of every finding before you see it.

See a sample reportOrder an audit

F-031 in the sample report, a critical finding: its recommendation in view, then its details and the evidence with line numbers
F-031 in the sample report, a critical finding: its recommendation in view, then its details and the evidence with line numbers

A sample report

The full report from an audit of OWASP Juice Shop, an online shop built to be insecure on purpose, so its count of findings is not a typical client's.

Open the sample reportDownload it as a PDF

How it works

  1. 1.Scanners first

    gitleaks searches every branch's history for secrets, osv-scanner checks your dependencies for known vulnerabilities, and Semgrep runs its rules.

  2. 2.An AI agent per aspect

    Then a Claude agent reads the code for each aspect you choose, through read-only tools and against a checklist, and files each finding with its evidence.

    Starting an audit: the repository, its detected stack, and the aspects to examine
    Starting an audit: the repository, its detected stack, and the aspects to examine
  3. 3.My review of every finding

    I accept, edit, merge or reject every finding. Only what I accept reaches the report.

    Reviewing findings: each with its evidence and the auditor's decision
    Reviewing findings: each with its evidence and the auditor's decision

What you get

What it covers

Security always, plus the aspects you choose: dependencies and supply chain, architecture, data model and database, code quality and tests, production readiness, API design, performance, accessibility, LLM integrations and multi-tenancy.

With a front end and its API in separate repositories, one more pass reads them together: the front end's calls against the back end's routes, authentication across both, and secrets in the bundle.

For an app written largely with AI tools, extra checks for what is typical of such code: uneven checks, packages to verify, copies that drifted apart.

Your code

The audit runs on my machine. Auditdesk never installs, builds or runs your code, and every secret gitleaks finds is masked before the model sees it.

Two things leave my machine. What the agents read goes to Anthropic, which keeps it for 30 days and does not train on it: a map of your repository, the brief you give me, the scanners' findings, and the code the agents open or search. Your dependencies' names and versions go to OSV's vulnerability database.

If your policy calls for it, the audit runs on your own Anthropic API key, under your own commercial terms with Anthropic and with every call on your account.

I delete my copy of your code when the engagement ends.

Order an audit

If we met through Toptal, the audit goes through Toptal.

Otherwise: online payment is coming soon. Until then, write to me at hello@naidenko.dev with a link to your repository or a few lines about your product, and I will reply with a scope and a quote.

Or use the contact form