A reference guide to all 9 governance stages applied to AI-generated code — what we examine, what we test, and what we deliver at each step. For the narrative journey, see Our Process.
We review and refactor your AI-generated codebase for readability, modularity, and maintainability — applying industry coding standards, naming conventions, dependency auditing, and performance optimisation before any other governance work begins.
Static analysis for OWASP Top 10 vulnerabilities, authentication review, input validation, secrets management, and API endpoint exposure. AI-generated auth logic and permission structures are a common source of exploitable flaws.
GDPR compliance review, data residency documentation, privacy-by-design audit, error handling and logging checks, and ISO 27001 alignment where required. Compliance gaps are invisible until they're regulatory findings.
Active OWASP-mapped penetration tests against your staging environment — authentication bypass, IDOR, privilege escalation, API abuse, business logic vulnerabilities, and data exposure. Every finding gets a severity rating and remediation plan.
Load simulation, stress testing, database query performance under concurrent load, CDN and asset review, API rate limit mapping. We give you a specific user growth ceiling — with the architectural changes needed to extend it.
AI tools don't document. We do. Full inline and external codebase documentation, architecture decision records, API reference, developer onboarding guide, maintenance runbook, and a technical debt register — so any engineer can pick it up.
WCAG 2.1 AA compliance audit, keyboard navigation and screen reader testing, colour contrast review, form and focus management, mobile responsiveness, and usability review against core user journeys. Accessibility is increasingly a legal requirement.
If your product includes AI components — recommendations, scoring, generation, classification — those outputs need validation. We test for consistency, bias across protected characteristics, hallucination risk, and edge case behaviour.
AI tools may reproduce GPL or similarly licensed code. We audit your full dependency tree and generated code for IP risk, open-source licence conflicts, and legal exposure — before these become costly findings in an investor's legal review.
When all stages are complete and findings remediated, we issue a final governance certification — a verifiable record of the governance process delivered by Logic Software Ltd — CREST Approved and Cyber Essentials certified. Then we help you launch — or set up the full CI/CD pipeline.
Not every product needs all 9 stages. We scope each engagement to your codebase, your timeline, and what you need to satisfy. Talk to us.