Auditors: introduce your practice using this template
This category runs both directions: makers requesting audits, and auditors offering them. This is the required intro format for security professionals who want to take engagements from this community. The disclosure rules are strict because trust is the product here — an auditor community works exactly as long as credentials are checkable.
The template
- Who you are: name and firm (real identities — anonymous auditors can't be verified, so anonymous intros aren't published).
- Credentials, checkably: certifications with registry-verifiable IDs where applicable, published research or CVEs, redacted sample reports, named references who agreed to be contacted. Claims we can't check get edited out — same policy as listing metrics.
- Scope you actually serve: which of the audit layers (see "What a code audit for an AI app actually covers") you cover, and — just as useful — what you don't do.
- AI-app track record: engagements on LLM-integrated or AI-generated codebases specifically. "None yet, here's my adjacent depth" is an acceptable, honest answer.
- Engagement shape: typical duration, deliverables, re-test policy, and a price range or your basis for quoting. Ranges are fine; "contact for pricing" alone is not.
- Conflicts, disclosed: if you also sell development, remediation, or retainer services, say so here — per community rules, an auditor recommending work they'd then perform must have disclosed that up front.
How engagements work at this stage
Directly between you and the maker — the platform doesn't broker, take a cut, or (yet) certify auditors. What we do: verify the checkable claims in intros before publishing, host the thread, and remove providers on substantiated complaints. If audit volume grows, a formal directory with published verification standards is the natural next step — same model as listing badges.
For makers reading
An intro thread here means the stated credentials checked out — not that we vouch for work quality. Ask for the sample report. Ask the references. The thread "Reading an audit report as a buyer" covers what good looks like.
First auditors posting: what verification would you want us to run on your peers before publishing their intros? The standard gets built from those answers.
Replies (4)
Follow-up from an auditor, via intake: "Verifying registry IDs is fine, but certifications say little about LLM-security skill — the certs barely cover it. What signal should makers actually weight?"
Agreed, and worth saying publicly: current security certifications predate most of the prompt-injection era, so treat them as evidence of professional baseline, not AI-app competence. The stronger signals for this niche, per practitioners: published analysis of LLM-app vulnerabilities (writeups beat credentials), familiarity with the OWASP LLM Top 10 demonstrated in the sample report rather than name-dropped, and specific answers to 'walk me through how you'd map my injection surface.' We'll weight intro verification accordingly — checkable work products over checkable acronyms.
On why we publish prices or pricing bases: information asymmetry is worst exactly here, where buyers can't judge the work and sellers know it. Solo makers get quoted 4x apart for equivalent scope, and can't tell whether the delta is quality or opportunism. Ranges in intros ('$X-Y for a 3-day grey-box review of a typical solo-maker app') let the market see its own spread. Auditors whose value justifies premium pricing can say why — that's a better position than opacity anyway.
Follow-up from maker intake: "What questions should I ask in a first call with an auditor from this thread?"
Six that discriminate: (1) 'What will you NOT look at in this scope?' — good auditors answer instantly; (2) 'Walk me through a finding from the sample report — how did you rate its severity?'; (3) 'What's your re-test policy after I fix things?'; (4) 'Have you audited AI-generated codebases — what did you find that surprised you?'; (5) 'Who does the work — you, or someone junior under your brand?'; (6) 'If you find nothing serious, what does the report say?' — the answer reveals whether they sell findings or assessment. Then check one reference with 'what did the engagement miss?' rather than 'were you happy?'
Moderation note for this thread, so the rules are on the record: intros that assert credentials we couldn't verify get published only after those claims are removed, with the auditor's agreement — or not at all. Disputes about a listed auditor go to the flag queue (24h review), not the comments; substantiated problems end in removal, logged with a reason like every moderation action. And per the conflicts rule: an auditor participating elsewhere in this category — answering questions, recommending scopes — must link their intro thread in each such comment. Helpful participation is welcome; undisclosed selling is not.
Threads are permanent — locked, not deleted, once resolved. New posts go through a submission form and are published by moderators, usually within 1 business day.