Ten places, no charge

A free security audit for ten companies building with AI-generated code

We announced this in a press release on 17 September and needed somewhere to send the people who replied. This is that page. It says what you get, who qualifies, and what we cannot promise.

10 places. Capacity, not a deadline: we work through applications in the order they arrive.

Why we are doing it

Code generated by a model needs checks that a functional test suite was never built for. Prompt injection and data exfiltration are live problems today, and a green regression run says nothing about either. We built the toolkit for our own engagements and want it pointed at more real codebases than our client list gives us.

There is nothing to buy afterwards. If you want to keep working with us, good, but the audit is finished when we hand you the findings.

What the audit covers

Our security toolkit runs and correlates around 20 open-source scanners in one pass, then filters what they produce so you get findings rather than a raw dump.

CheckWhat we look at
SAST Your source code, read for injection points, unsafe handling and secrets committed by mistake.
DAST Your running application, probed the way an outsider would reach it.
SCA Your dependencies, checked against known vulnerabilities and licence problems.
OWASP LLM Top 10 The model-specific ones: prompt injection, insecure output handling, training data leakage, excessive agency.

You get a written report with each finding described, where it sits and what we would do about it. We will talk it through with you if that helps.

Who qualifies

  • You are shipping code that a model wrote a meaningful part of.
  • You own the systems being audited, or you hold documented authorisation to have them audited. No authorisation, no audit.
  • You can give us code access or access to a running environment, arranged under a mutual NDA we sign before any work starts.

Size, sector and stage do not matter to us. A pre-launch product is as useful to look at as a live one.

What this is not

Not a penetration test, not a certification, not an attestation. There is no badge or seal at the end. You get findings describing what the toolkit found on the systems you gave us. That is not a guarantee your systems are secure, and it is not a claim that there is nothing else to find.

What happens after you apply

  1. We reply and check the fit

    Usually within two working days. A short call or an email exchange, whichever you prefer.

  2. We sign a mutual NDA

    Ours or yours. Nothing starts before it is signed.

  3. You give us access

    A repository, a staging environment, or both. We tell you exactly what we need and what we will run.

  4. We run the toolkit and read the output

    Typically a few days, depending on how large the codebase is and how quickly access lands.

  5. You get the report

    Findings, where each one sits, and what we would do about it. Then we are done, unless you want more.

Apply

Tell us your company name, what you are building, and roughly how much of the code was model-generated. Two or three sentences is enough to start.

Or email [email protected].

BetterQA is an independent software testing company in Cluj-Napoca, Romania, founded in 2018. We hold ISO 9001, ISO 27001:2022, ISO 14001 and ISO 13485 certification and are members of the Avetta Consortium.

Need help with software testing?

BetterQA provides independent QA services across manual testing, automation, security audits, and performance testing. ISO 27001, 9001, 14001 and 13485 certified.

Explore our services Get in touch