Code audit services

Code audit services: a written report you can act on

Easital Technologies Ltd. audits source code for companies that need an independent view of what they have: before a launch, a funding round, an acquisition or a change of development team. We read the repository, test what can be tested and deliver a written report with findings ranked by severity, the evidence for each and a remediation plan.

What a code audit is

A code audit is a structured review of a software codebase by engineers who did not write it. It reports what is wrong, how serious each problem is and what to do about it.

A software code audit differs from a code review and from a penetration test. A code review looks at one change before it is merged. A penetration test attacks the running application from outside. A source code audit reads the whole repository from inside, so it also finds problems that are not yet visible from outside: a missing access rule, a dependency with a known vulnerability, a module nobody can safely change.

Code review, penetration test and code audit compared
Code reviewPenetration testCode audit
What is examinedOne changeThe running application, from outsideThe whole repository, its configuration and its history
WhenBefore each mergeBefore or after a releaseBefore a launch, an investment, a handover or a rescue
What it findsDefects in that changeHoles an attacker can reach todaySecurity, design, maintainability and cost problems, exploitable or not
ResultComments on the changeA list of weaknesses that were exploitedA ranked report with a remediation plan

The three complement each other. An audit does not replace a penetration test, and it is not a compliance certification.

What a rebuild looks like

A short film from the Easital team: an application taken from broken to modern. An audit is where that work starts.

Video: From broken to modern: a day of rebuilding
From broken to modern: a day of rebuilding Easital Technologies Ltd., 51 seconds Watch on YouTube

What the audit covers

A full audit covers eight areas. A code security audit on its own covers the first four.

  • Security

    Input handling, injection, cross-site scripting, request forgery protection, security headers, and rate limiting on login and on costly endpoints.

  • Access control

    Who can read and write which records. We test as a logged-out visitor, as a normal user and as a second user trying to reach the first user’s data.

  • Secrets

    Keys and tokens in the client bundle, the repository history, configuration files and coding-tool settings, with a list of what has to be rotated.

  • Dependencies

    Packages with known vulnerabilities, abandoned packages, package names that do not exist in the registry, and licenses that conflict with your use.

  • Architecture

    How the code is divided, where the data model works against the product, how much logic is duplicated, and which parts will resist the next feature.

  • Tests and release process

    What automated tests cover, what runs before a deploy, how environments are separated and whether a backup has ever been restored.

  • Performance

    Slow queries, missing indexes, work done during a request that belongs in a background job, and behavior under load.

  • Cost of AI calls

    For products that call language models: tokens and spend per request and per user, caching, the model chosen for each step, and the limits that stop a runaway bill.

How an audit runs

An audit runs in six steps and ends with a conversation as well as a document.

  1. Short repository review and quote

    You give us read access, under a confidentiality agreement if you want one. We look at size, languages, structure and deployment setup, agree the scope with you and send a fixed quote.

  2. Access and context

    Read access to the repository and hosting configuration, a test account, and a short call about what the product does and what worries you.

  3. Automated passes

    Secret scanning over the full history, a dependency audit and static analysis. These produce candidates, not findings.

  4. Manual review

    Engineers read the code that matters most: authentication, authorization, payments, data access and anything that calls an AI model. Each automated candidate is confirmed or dismissed.

  5. Report

    Findings are written up with severity, evidence and a recommended fix, then ordered into a remediation plan.

  6. Walkthrough

    We go through the report with your team and adjust the plan to your constraints. You can carry out the fixes yourself or ask us to.

The engineering behind the audit

Auditors need experience of running software as well as reading it. These live systems, built by Easital, involve the areas an audit reviews.

  • Easital product

    Manob.ai

    Built and run by Easital

    A multi-step agent task costs more to run than a simple prompt, and Easital did extensive work on the token cost of this product. Cost per task is what the AI-cost part of an audit looks for in a codebase.

  • Client project

    Calldone

    Built by Easital for a client in the United States

    Its privacy policy states that call recordings, transcripts and other customer content are not used to train AI models. An audit checks a statement like this against what the code does.

  • Easital product

    StepVideo

    Built and run by Easital

    A browser extension, a web app and a media pipeline that calls language and speech models from more than one provider. Systems with several providers need the closest review of secrets and AI cost.

See all of our work

What you receive

You receive a written report in which every finding has a severity, the evidence that supports it and a recommended fix.

How findings are ranked
SeverityMeaningExampleResponse
CriticalData or money is exposed nowA table readable without login; a live secret key in the client bundleFix first; rotate affected keys
HighExploitable with modest effort, or one mistake away from an outageA user can read another user’s records by changing an ID; no backupsFix before launch
MediumWeakens the system without a direct path to harmNo rate limit on login; a vulnerable dependency in an unused pathSchedule
LowMaintainability and hygieneDuplicated logic; missing tests on a stable moduleFix when the code is next changed
  • A summary that a non-technical reader can follow.
  • Each finding with file references, steps to reproduce where relevant, and the fix.
  • A remediation plan in priority order, with the effort of each item sized relative to the others.
  • A list of what was not reviewed, so the limits of the audit are explicit.
  • A note of what is sound and should be left alone.

AI code security: auditing code written with AI tools

Code written with AI assistance needs the same audit as any other code, with extra attention where current models are measurably weak: authorization, input validation and anything that depends on the application’s own rules.

In Veracode’s 2026 GenAI Code Security Report of July 28, 2026, the average security pass rate across the models tested was 56%, against 55% in its first report, and the highest-scoring model reached 68%. Models averaged 83% on SQL injection tasks and 15% on cross-site scripting. Tenzai built 15 apps with five coding agents and reported on June 25, 2026 that it found 69 vulnerabilities and that none of the 15 apps had proper protection against cross-site request forgery.

Both companies sell security products, and both used tasks chosen to be security-relevant, so these are not failure rates for all AI-written code. The practical reading is narrower. Generated code is usually tidy and plausibly named, which makes a missing permission check harder to notice by eye, so we test access rules directly. When an audit shows that an app needs more than a list of fixes, the follow-on work is described under vibe coding rescue.

How an audit is scoped and priced

The price depends on the size of the codebase and the depth you need, so we give a fixed quote after a short review of the repository. Some audit providers publish one fixed price. We quote per repository because a small prototype and a large platform are different amounts of work.

  • Size: lines of code and the number of services and repositories.
  • Languages and frameworks in use.
  • Depth: security only, or all eight areas.
  • Reach: the repository alone, or the running application and its hosting as well.
  • AI features: the number of model calls and prompts to review.
  • Purpose: internal planning, investor due diligence or a handover to a new team.

The short review also shows when an audit is the wrong purchase, for example when an app is small enough that fixing it directly costs less than reporting on it.

Methods and tooling

An audit combines automated checks, which are fast and noisy, with manual review, which is slow and precise. Tools are listed by category and chosen for the languages in the repository.

Automated checks
  • Secret scanning
  • Dependency vulnerability audit
  • Static analysis
  • License check
Manual review
  • Access-rule testing
  • Authentication and sessions
  • Payment flows
  • Prompts and model calls
Reference lists
  • OWASP Top 10
  • OWASP Top 10 for LLM Applications

Products that embed a language model are checked against the OWASP Top 10 for LLM Applications 2025.

Ways to work with us

There are three forms of audit, and the short repository review tells us which one fits.

  • Full code audit

    All eight areas, the written report and the walkthrough.

    Best for: a launch, a funding round, an acquisition or a new technical lead taking over a codebase.

  • Security-focused audit

    Security, access control, secrets and dependencies, with the same report format.

    Best for: startups about to put real customer data into an app, and apps that are already live.

  • Audit plus remediation

    After the walkthrough, Easital engineers carry out the remediation plan or the part of it you choose.

    Best for: teams without the capacity to fix what the audit finds.

Code audit services: questions and answers

What is a code audit?

A code audit is an independent, structured review of a codebase. Engineers who did not write the code read it, run automated checks, test access rules and report what is wrong, how serious each problem is and how to fix it.

What do code audit services include?

A full audit from Easital covers security, access control, secrets, dependencies, architecture, tests and release process, performance, and the cost of AI calls. The deliverable is a written report with ranked findings and a remediation plan, followed by a walkthrough with your team.

What do I receive at the end of a code audit?

A written report. It contains a summary for non-technical readers, each finding with its severity, evidence and recommended fix, a remediation plan in priority order, and a list of what was outside the scope.

How much does a code audit cost?

It depends on the size of the codebase, the languages used, the depth of the audit, whether the running application is in scope and how many AI features there are. Easital does not publish a price. We send a fixed quote after a short review of the repository.

Is AI-generated code secure?

Not by default. In Veracode’s July 2026 benchmark the average security pass rate across models was 56%. Models are strong on some classes of flaw, such as SQL injection, and weak on others, such as cross-site scripting and authorization. Review and testing after generation decide whether the code is safe.

How can you tell if code is AI generated?

Not reliably. A repository can carry signals, such as co-author lines in commit messages and configuration files left by coding tools, but they are incomplete and easy to remove. An audit applies the same checks whoever wrote the code.

Do you offer code audit services for startups?

Yes. Startups most often need the security-focused audit before launch or a full audit before investor due diligence. The scope is set by the repository, so a small codebase gets a small audit.

Ask for a quote on your repository

Tell us what the product does, how large the codebase is and why you want it audited. We reply by email with questions and the next step toward a fixed quote.

Easital is an AI and SaaS engineering company that takes AI software to production, and runs AI products of its own. Founded in 2019.