Skip to main content

Run an audit

Start a source code audit from the dashboard. The Run your first code audit guide has the full walkthrough; this page is the short version.

Steps​

  1. Click New Assessment in the dashboard.
  2. Enter a name (for example, "api-gateway security audit").
  3. Select Code Audit as the assessment type.
  4. Choose your source:
    • Connected repository — select from the repositories your integration syncs.
    • Public repository URL — paste a public https://github.com/{owner}/{repo} URL.
    • Upload archive — upload a tar.gz of your codebase.
  5. Optionally tick a regulated regime (GDPR, HIPAA, or PCI DSS) to add its checks to the methodology checklist. See Coverage.
  6. Optionally add additional instructions to steer the agents. See Steer the audit.
  7. Click Create draft, review the draft configuration, then click Start assessment.

AISafe validates the source (clones the repository, resolves the ref), then starts isolated sandboxes and runs the AI agents. See How it works for the stages.

While it runs​

AISafe streams progress through the stages. The time grows with codebase size: about an hour and a half for a small repository, ten hours or more for a large monorepo. You can navigate away and come back — the audit runs in the background.

After it finishes​

The assessment completes and you land on the findings list. Review and triage each finding, then generate a report. See Findings and Concepts: Finding.

The report also includes the audit's coverage record: every check on the methodology checklist and the answer it got. Read it alongside the findings, so that you know which vulnerability classes were examined and which do not apply to your application. See Coverage.