Skip to content
← All services
Global AI and Software Audits / from 48 hours

Know what your vendor actually shipped.

Choose the depth that matches the decision you need to make. This page shows the shape of each audit without pretending every product needs the same checklist. Send a brief and we will recommend a tier, then put the exact coverage, access, limits, price, and delivery date in writing.

/ Offer overview

Three depths. One clear next step.

Start with the decision you need to make, not a technical checklist. We will recommend the lightest audit that can answer it.

01 / Surface Audit48 hours

A fast independent view

A focused review of what a customer can see, what the vendor claims, and whether the basic ownership and continuity picture makes sense.

From $399
From ₹34,000 / applicable taxes quoted separately
Best when

An early check before accepting delivery, renewing a vendor, or deciding whether a deeper review is justified.

Broad coverage
  • Product experience and vendor claims
  • Ownership and continuity basics
  • Performance and discoverability
You receive

A concise findings report with severity, evidence notes, and the next actions worth taking.

02 / Deep AuditFour days

Evidence behind the claims

A closer review when important security, recovery, and data-handling claims need more than an outside-in check.

From $999
From ₹89,000 / applicable taxes quoted separately
Best when

A product that holds important data, depends on several services, or has become difficult to challenge or understand.

Broad coverage
  • Everything covered by Surface
  • Security and recovery evidence
  • Data flows and external dependencies
You receive

An evidence-backed risk report with senior-reviewed findings and a prioritized fix order.

03 / Full AuditOne week

Business-critical assurance

The broadest review for software or AI systems that affect operations, compliance readiness, vendor dependence, or runway.

From $2,499
From ₹2,19,000 / applicable taxes quoted separately
Best when

A business-critical system, a major vendor decision, or a team that needs technical risk and technology spend reviewed together.

Broad coverage
  • Everything covered by Deep
  • Architecture, AI, governance, and privacy readiness
  • Vendor continuity and technology spend
You receive

An executive summary, technical report, cost opportunities, and a re-audit of agreed fixes.

This is the public overview, not the working checklist. Your written quote names the systems, included areas, required access, exclusions, deliverables, price, and delivery date before you commit.
/ Delivery

How the clock works.

01 / Tell us the concern

Send the product URL, what was promised, and what worries you. Do not email passwords, API keys, or production data.

02 / Get a recommendation

We reply in writing with the tier we recommend, exact coverage, exclusions, access needs, fixed price, and delivery date.

03 / Review securely

After scope and authority are signed, access is arranged through a secure handoff and we review only the agreed systems and evidence.

04 / Use the report

You receive findings, evidence, severity, and a practical fix order. The report is useful whether your vendor, your team, or GattyWorks handles the fixes.

/ Good fit

Bring this kind of brief.

  • A founder or team that paid for software and cannot see inside it
  • A business about to sign, renew, or challenge a software vendor
  • A team that needs its AI systems, data practices, or cloud spend checked against what was promised
/ Boundaries

What changes the scope.

  • You must own the target or have written authority for the agreed tests. Credentials use secure handoff, never email
  • The written quote caps the scope. Larger products and estates are quoted separately
  • An audit is a point-in-time, evidence-limited findings report. It is not certification, an AI safety guarantee, a penetration-test attestation, or legal advice
  • Fixing what we find is your vendor's work or a separately quoted build
/ Questions

Before you send the brief.

Why audit software I already paid for?

Because the invoice does not tell you whether the encryption is real, where your data flows, whether backups restore, or whether the vendor controls your domain. An audit turns those unknowns into a written, severity-ranked list.

Do I need to choose a tier before contacting you?

No. Tell us the decision you need to make and what worries you. We will recommend the lightest tier that can answer it.

Why is the full checklist not public?

The exact review depends on the product, access, evidence, risk, and business decision. A universal checklist would look more precise than it is. Your written quote names every included area, required input, exclusion, deliverable, price, and date before you commit.

Can you check DPDPA, GDPR, or UK GDPR readiness?

The Full Audit maps observable technical controls and gaps, and reports evidence, gaps, and unknowns. Where restricted personal data is accessed from India, the required data-processing and transfer terms are signed before access. Readiness mapping is not a legal opinion or certification.

Will my vendor know you audited them?

That is your call. We work with the access you arrange and report to you. Many clients share the fix list with their vendor; the re-audit pass on Full exists exactly for that loop.

The written-reply guarantee

Every brief gets a written reply within 24 hours.

If we miss it, the website or audit fee on your first project is refunded 100%.

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.