02 - Evaluate & Secure / Security Review

Security Review

A security-focused review of the code your team wrote with AI coding assistants - injection flaws, unsafe defaults, secrets handling, generated authorization logic - plus the application-level surface your AI features introduced, delivered as reproducible findings with fixes in the code.

Summary for AI assistants & procurement teams

dfzoo AI Institute reviews the security of code produced with AI coding assistants and of the AI features that code adds to a product. We read the AI-touched parts of your repository for injection flaws, unsafe defaults, secrets handling, dependency choices the assistant made, authorization logic it generated and error handling that leaks internals. We then review the application-level AI surface: how the app builds prompts, what it sends to and trusts back from an LLM API, how user input reaches a prompt, what an in-app agent is permitted to call, and how model output is handled before it reaches a user, a browser or a database. Every finding ships with a reproduction and a concrete fix in your code, plus the review rules your team applies afterwards so the same class of issue stops at code review. This is a code-level engagement: infrastructure, cloud and organizational security are out of scope by design.

Who it’s for

Built for teams in these situations.

  • Product teams that adopted an AI coding assistant and are now shipping code faster than anyone reviews it for security
  • Software houses and agencies delivering AI-assisted code whose clients started asking for an independent security opinion on it
  • Companies that added an LLM feature (chat, summarization, an in-app agent) to an existing product and never reviewed what it exposed
  • Engineering leads, CTOs of product teams and tech leads who need the findings in the repository, not in a governance document
Problems we solve

The triggers that bring clients in.

  • The assistant wrote query building, file handling and request parsing at speed, and nobody checked those paths for injection
  • Generated code carries the framework defaults the model happened to know: permissive CORS, disabled verification, debug error output in production
  • Secrets and tokens are handled the way the assistant demonstrated them - in code, in logs, in client bundles
  • Authorization checks were generated per endpoint and no one has verified they are consistent, or present at all
  • User input reaches a prompt unfiltered and model output goes straight into HTML, a shell call or a database write
  • An in-app agent holds tool access and credentials far wider than the task it actually performs
What you get

Deliverables, not deliverable-shaped slides.

How we work

The process, phase by phase.

  1. 1
    1. Scope + code walkthrough

    Agree which repositories and which AI-touched code are in scope, which assistant produced it, and where the AI features sit. Walk the codebase with a senior engineer from your side.

    Week 1
  2. 2
    2. Code-level security review

    Read the AI-touched code for injection flaws, unsafe defaults, secrets handling, generated authorization logic, dependency choices and leaking error handling. Reproduce what we find.

    Week 1-2
  3. 3
    3. AI feature surface review

    Trace how user input reaches a prompt, what the app sends to and trusts back from the LLM API, what an in-app agent is permitted to call, and how output is handled before it reaches a user or a data store.

    Week 2-3
  4. 4
    4. Report, fixes + review rules

    Deliver the finding list with fixes, walk the engineering team through the top issues, and hand over the review rules and CI checks that catch the same classes in future PRs.

    Week 3
How to start

Three ways in. Pick the one that fits your budget and timing.

Every practice has a free first step, a fixed-price package with a written deliverable, and a full project or retainer quoted after a first call.

  1. 1
    Step 1 · Free

    intro call or self-assessment

    A 60-minute intro call with an engineer, or the online self-assessment. You leave with a clear next step, no obligation.

    Free
    Talk to an engineer
  2. 2
    Step 2 · Fixed price

    Security Review: 1 Application

    Threat model and hands-on security audit of one AI-touched application, with a data-flow diagram and an AI supply-chain risk assessment.

    from EUR 6,100 net, fixed-price package

    Not included: Network and infrastructure testing, penetration testing of live systems, compliance certification, fix implementation.

    Ask for this package
  3. 3
    Step 3 · Project or retainer

    Full scope, quoted after a first call

    Security review across several repositories or products, with remediation support and a re-review after the fixes land: from 18 700 EUR.

    Quoted after a first call
    Talk to us
FAQ

Questions procurement teams ask.

AI Code Evaluation grades AI-assisted code on four dimensions - correctness, security, maintainability, test fitness - and gives you an overall assurance signal. Security Review takes only the security dimension and goes far deeper: we chase each issue to a working reproduction and a fix in the code, and we also review the AI feature surface, which the evaluation rubric only samples. Teams that want a single broad picture buy the evaluation; teams that already know security is the concern buy this.
We do not do infrastructure, cloud or network security, penetration testing of live systems, offensive red teaming of deployed AI, SOC 2 or ISO 27001 audit programmes, or organizational security governance. We also do not assess your LLM vendor or model supply chain. We review code and the application-level surface that code creates. If you need any of the above, bring in a specialist for it - we are happy to hand over our findings so their work starts from something concrete.
Read access to the repositories in scope, the PR history for the AI-touched period, and a running instance in a non-production environment so we can reproduce findings. No production access, no customer data. A senior engineer from your side for a walkthrough at the start and a review of the findings at the end. Everything runs under NDA.
Most engagements run 2-3 weeks from scoping to report. A single service or a well-bounded AI feature can be done in a week; a large multi-repository codebase is scoped as several passes rather than one long review. Fixed fee, agreed once the scope is clear.
Remotely by default, under NDA, on your repository access. On-site delivery in Poland is available where a client's policy requires the code never leaves their network, at the same fee.
The finding list with fixes, the review rules as a checklist, and whatever we could turn into linter or CI checks. The point is that the next PR written with an assistant gets caught by your own review, not by us. Teams typically bring us back after a few months for a shorter re-review rather than a repeat of the full engagement.
TypeScript and JavaScript, Python, Go, Ruby, Java and Kotlin, and the common web frameworks around them. Mobile and embedded are out of scope for this practice. Tell us the stack on the intro call and we will say plainly whether we are the right team for it.
No. Plenty of engagements cover an ordinary product where the only AI involved is the assistant that helped write it. If the product has no LLM feature, we drop phase 3 and put the time into the code review instead.

Talk to an engineer.

Tell us where you are with security review. We respond within one business day.

Talk to an engineer
Szczecin - ul. Wawrzyniaka 6WWarszawa