Code audits
Know what to fix in your codebase, and what can wait.
An independent audit before a launch, a fundraise or a handover. I run it on Auditdesk, a workbench I built for it: scanners first, then an AI agent per aspect, and my own review of every finding before you see it.
A sample report
The full report from an audit of OWASP Juice Shop, an online shop built to be insecure on purpose, so its count of findings is not a typical client's.
How it works
1.Scanners first
gitleaks searches every branch's history for secrets, osv-scanner checks your dependencies for known vulnerabilities, and Semgrep runs its rules.
2.An AI agent per aspect
Then a Claude agent reads the code for each aspect you choose, through read-only tools and against a checklist, and files each finding with its evidence.
3.My review of every finding
I accept, edit, merge or reject every finding. Only what I accept reaches the report.
What you get
- For founders and leadership: what to fix before sign-off and what can wait, with an estimate of the effort for each.
- For your engineers: each finding with its evidence by file and line, the fix, and links to the OWASP Top 10, ASVS and CWE.
- One HTML file with filters and search, and a PDF.
- The accepted findings as issue drafts for Linear or GitHub, and as SARIF for code scanning.
- After your fixes, a re-audit of the new commit re-checks every finding the last report listed.
What it covers
Security always, plus the aspects you choose: dependencies and supply chain, architecture, data model and database, code quality and tests, production readiness, API design, performance, accessibility, LLM integrations and multi-tenancy.
With a front end and its API in separate repositories, one more pass reads them together: the front end's calls against the back end's routes, authentication across both, and secrets in the bundle.
For an app written largely with AI tools, extra checks for what is typical of such code: uneven checks, packages to verify, copies that drifted apart.
Your code
The audit runs on my machine. Auditdesk never installs, builds or runs your code, and every secret gitleaks finds is masked before the model sees it.
Two things leave my machine. What the agents read goes to Anthropic, which keeps it for 30 days and does not train on it: a map of your repository, the brief you give me, the scanners' findings, and the code the agents open or search. Your dependencies' names and versions go to OSV's vulnerability database.
If your policy calls for it, the audit runs on your own Anthropic API key, under your own commercial terms with Anthropic and with every call on your account.
I delete my copy of your code when the engagement ends.
Order an audit
If we met through Toptal, the audit goes through Toptal.
Otherwise: online payment is coming soon. Until then, write to me at hello@naidenko.dev with a link to your repository or a few lines about your product, and I will reply with a scope and a quote.


