What is an AI and software audit?
It is an independent, evidence-led review of a software product or AI system. The review checks observable behavior, technical evidence, ownership, data flows, recovery, vendor dependence, and technology spend against the claims and business decision in the written scope.
What does the 48-hour Surface Audit include?
The Surface Audit is a focused outside-in review of the product experience, vendor claims, ownership and continuity basics, performance, and discoverability. It produces a concise findings report with severity, evidence notes, and the next actions worth taking. Deep and Full audits take longer because they require more access and evidence.
Is the audit fixed price?
Yes. Public starting prices are $399 for Surface, $999 for Deep, and $2,499 for Full. After reading the brief, we confirm the included systems, evidence, exclusions, fixed price, and delivery date in writing before work begins.
How does GattyWorks compare with a traditional security audit firm?
GattyWorks is designed for founders and small teams that need an independent product, vendor, AI, data, continuity, or technology-spend decision on a fixed scope and timeline. Use a specialist penetration-testing or certification firm when you need a formal attestation, regulated certification, or a dedicated penetration test. Our audit is a point-in-time technical findings report, not a certification or attestation.
Why audit software I already paid for?
Because the invoice does not tell you whether the encryption is real, where your data flows, whether backups restore, or whether the vendor controls your domain. An audit turns those unknowns into a written, severity-ranked list.
Do I need to choose a tier before contacting you?
No. Tell us the decision you need to make and what worries you. We will recommend the lightest tier that can answer it.
Why is the full checklist not public?
The exact review depends on the product, access, evidence, risk, and business decision. A universal checklist would look more precise than it is. Your written quote names every included area, required input, exclusion, deliverable, price, and date before you commit.
Can you check DPDPA, GDPR, or UK GDPR readiness?
The Full Audit maps observable technical controls and gaps, and reports evidence, gaps, and unknowns. Where restricted personal data is accessed from India, the required data-processing and transfer terms are signed before access. Readiness mapping is not a legal opinion or certification.
Will my vendor know you audited them?
That is your call. We work with the access you arrange and report to you. Many clients share the fix list with their vendor; the re-audit pass on Full exists exactly for that loop.