A redacted security review and its technical appendix.
Our existing security review pairs a plain-language report with a technical appendix. Each serves a different reader.
Read both reports
These public copies retain every page of the original security review. Client names, target URLs, endpoint paths, and phone numbers are redacted.
The historical findings and recommendations show the delivery format. They do not establish current exposure or a completed fix.
Security report · 3 pages
The finding, business impact, and proposed next steps.
Loading report…
Technical appendix · 16 pages
Reproduction detail, engineering analysis, and proposed fixes.
Loading report…
Report and appendix
- The decision report
- Explains what went wrong, why it matters to the business, and the next steps to consider.
- The technical appendix
- Gives the engineering team reproduction detail, analysis of the implementation, and a proposed fix.
- The scope boundary
- Separates the observed issue from wider questions that require more investigation.
What an AI audit can cover
For an AI workflow audit, we agree the checks and access before starting. The report can cover these areas within that scope.
- Model behaviour: Test inputs, expected outcomes, observed responses, and evaluation limits.
- Tool permissions: Which actions the agent can take, how access is enforced, and where approval is required.
- Failure handling: Retry behaviour, uncertain outcomes, recovery steps, and operational visibility.
- Delivery to engineering: Evidence, priority, proposed changes, and checks to run after a fix.
A proposed fix is separate from a verified fix. Retest results need their own evidence.
Public build work
See public website screenshots and feature summaries for Gazette Intel, Fear of Wife, Edible Factor, Metrics, and Deep Research.
Explore the projectsWhat do you need to decide?
Bring your workflow and main concern. We will discuss the evidence needed for a useful review.
Discuss your audit