The same handful of mistakes, over and over.
AI coding tools let you ship in a weekend what used to take a team a quarter. They also ship the same handful of mistakes, over and over: keys in the browser, databases anyone can read, logins that only look like they check anything. Most of it is invisible until a customer, an investor, or an attacker finds it first.
Here's the thing most consultants won't tell you: you've already done the hard part. You've worked out what the product should do, and real users have proved it right. That's a matter of taste and judgement, and on that you're the authority, not me. What's left is engineering: making the thing you designed safe, solid, and able to grow.
I find it first. Then I help you fix it — without taking the tools away.
Who it's for
- Founders whose AI-built MVP now has paying users, or a funding round coming
- Teams whose internal tool has quietly become business-critical
You probably need this if
- A customer has sent you a security questionnaire and you don't know the answers
- Your AI or cloud bill jumped and you can't explain why
- It works for 10 users and falls over at 50
- Every fix the AI makes breaks something else
- You couldn't say where your users' personal data actually lives
How it works
- 01
Defuse
Automated scans plus expert manual review. You get a prioritised findings report and a Keep / Fix / Rebuild verdict.
- Length
- 2–3 days
- Price
- £950, fixed
- 02
Remediate
I close the critical and high findings, working in your repo with your tools.
- Length
- 1–2 weeks
- Price model
- Fixed scope, time-boxed
- 03
Stabilise
Proper data model, migrations, tests, CI, logging and backups — or a managed rebuild if that was the verdict.
- Length
- 2–6 weeks
- Price model
- Scoped per engagement
- 04
Guardrails
CI security gates, AI rules files tuned to your codebase, and a monthly review so you can keep building fast, safely.
- Length
- Ongoing
- Price model
- Monthly retainer
Most clients start with Defuse, at a fixed £950. It stands on its own: you own the report and can take it to any developer.
What you get from Defuse
It's a full assessment, not a scanner dump — the work and the evidence, for a fixed £950.
- Attack-surface recon — exposed services, DNS and email, TLS and security headers, and secrets left in public places
- Automated scanning — static analysis, secret scanning, and a dependency audit for known-vulnerable libraries
- Manual code and architecture review — a person reading the code, config and data model, for the logic flaws scanners miss
- A findings report, risk-ranked in plain English, with a Keep / Fix / Rebuild verdict and the reasoning shown
- A remediation plan your AI tool can follow, in fix order
- Every scan and recon artefact, annotated — each result marked and explained, so you own the evidence, not just the conclusions
- A 45-minute walkthrough call, and the report is yours to take to any developer
Want to see one first? Read a sample Defuse report, run against a deliberately flawed demo app.
Questions people ask
Will you tell me to stop using AI?
No. AI-built software is fine; unreviewed software isn't. I help you keep the speed and reduce the risk.
Do you need access to live customer data?
Ideally not. I prefer a staging copy or anonymised data. Where production access is unavoidable, we sign a data processing agreement first. If you have other requirements, talk to me.
Is this a penetration test?
It's broader and earlier: code, configuration, and architecture review. If you need a formal pen test for compliance, I'll tell you, and help you get value from it.
Do you guarantee the app is secure afterwards?
Nobody honestly can. You get a thorough, expert assessment and a clear record of what was checked and what was found or fixed.