Skip to content
Farhat Ullah.
Security & Infrastructure Audit

Find the multi-tenant hole before your users do.

The deliverable manifest.

  1. 01Findings report on tenant isolation, access control and privilege paths
  2. 02Remediation pull requests for the issues found
  3. 03Server and infrastructure configuration review
  4. 04Malware or compromise root-cause analysis, where relevant
  5. 05Prioritized task sheets your own team can execute from

Your backend was written by an AI. Who reviewed the tenant isolation?

What you get

A findings report covering the places generated and hand-written code most often get wrong: tenant isolation, storage bucket permissions, and privilege-escalation paths in access-control policies. In a recent audit of an AI-generated Supabase backend, this class of review found four critical issues in two days — including a path that let one tenant write into another tenant's data. Catching that before launch is a two-day review; catching it after launch is an incident. Findings come with remediation, either as pull requests I write directly or as prioritized task sheets your own team can execute from, depending on how you want to run the fix.

How it works

Audits run read-only against production wherever possible — scripts that pull state and check it against expected behavior without ever writing to the system being reviewed, so the audit itself introduces zero risk. For infrastructure audits, that extends to server configuration, SSL and certificate management, and monitoring setup. For application audits, it means checking access-control policies against the access patterns the application actually generates, not just the ones the documentation describes. The engagement ends with a report separated from remediation, so you see the risk clearly before anything gets changed.

Who this is for

Teams shipping a backend that was substantially AI-generated and hasn't had a systematic security review, teams that inherited infrastructure or an Odoo estate with unknown state, and anyone who wants a second set of eyes on tenant isolation before their first serious customer finds the gap for them.

Questions about this service.

Do you audit AI-generated codebases?
Yes, it's a dedicated service. Common findings in AI-generated backends include broken tenant isolation, unprotected storage buckets, and privilege-escalation paths in generated row-level security policies — the boundary conditions generated code tends to get wrong.
What does a security audit actually deliver?
A findings report describing what's wrong and how severe it is, followed by remediation — either pull requests fixing the issues directly or prioritized task sheets your own developers can work through, depending on what fits your team.
Is the audit safe to run against a live production system?
Audits are typically read-only against production, using scripts that pull state without ever writing to the system under review, so the review itself carries no risk to what's running.
How much does a security audit cost?
Entry-level audits start from $80 for a scoped review. Larger infrastructure or multi-tenant audits are priced after a discovery call once the scope is clear.

Ready to start with security & infrastructure audit?

Start a project

Have a system that needs to work in production?

Tell me what's breaking — or what you're building.

Chat on WhatsApp