A security-focused review of the code your team wrote with AI coding assistants - injection flaws, unsafe defaults, secrets handling, generated authorization logic - plus the application-level surface your AI features introduced, delivered as reproducible findings with fixes in the code.
dfzoo AI Institute reviews the security of code produced with AI coding assistants and of the AI features that code adds to a product. We read the AI-touched parts of your repository for injection flaws, unsafe defaults, secrets handling, dependency choices the assistant made, authorization logic it generated and error handling that leaks internals. We then review the application-level AI surface: how the app builds prompts, what it sends to and trusts back from an LLM API, how user input reaches a prompt, what an in-app agent is permitted to call, and how model output is handled before it reaches a user, a browser or a database. Every finding ships with a reproduction and a concrete fix in your code, plus the review rules your team applies afterwards so the same class of issue stops at code review. This is a code-level engagement: infrastructure, cloud and organizational security are out of scope by design.
Agree which repositories and which AI-touched code are in scope, which assistant produced it, and where the AI features sit. Walk the codebase with a senior engineer from your side.
Read the AI-touched code for injection flaws, unsafe defaults, secrets handling, generated authorization logic, dependency choices and leaking error handling. Reproduce what we find.
Trace how user input reaches a prompt, what the app sends to and trusts back from the LLM API, what an in-app agent is permitted to call, and how output is handled before it reaches a user or a data store.
Deliver the finding list with fixes, walk the engineering team through the top issues, and hand over the review rules and CI checks that catch the same classes in future PRs.
Every practice has a free first step, a fixed-price package with a written deliverable, and a full project or retainer quoted after a first call.
A 60-minute intro call with an engineer, or the online self-assessment. You leave with a clear next step, no obligation.
Threat model and hands-on security audit of one AI-touched application, with a data-flow diagram and an AI supply-chain risk assessment.
Not included: Network and infrastructure testing, penetration testing of live systems, compliance certification, fix implementation.
Ask for this packageSecurity review across several repositories or products, with remediation support and a re-review after the fixes land: from 18 700 EUR.
Tell us where you are with security review. We respond within one business day.