AXIS Launch List your app
Auditors & Security offeringtemplatepinned

Auditors: introduce your practice using this template

Updated 3 October 2026

Started by Jonathan (AXIS Launch)

This category runs both directions: makers requesting audits, and auditors offering them. This is the intro format I ask security professionals to use when they introduce a practice on GitHub Discussions (the link is at the foot of this page). The disclosure rules are strict because trust is the product here — an auditor community works exactly as long as credentials are checkable.

The template

  • Who you are: name and firm (real identities — a maker cannot check the credentials of an anonymous auditor).
  • Credentials, checkably: certifications with registry-verifiable IDs where applicable, published research or CVEs, redacted sample reports, named references who agreed to be contacted. I do not check any of this, so give a maker what they need to check it themselves.
  • Scope you actually serve: which of the audit layers (see "What a code audit for an AI app actually covers") you cover, and — just as useful — what you don't do.
  • AI-app track record: engagements on LLM-integrated or AI-generated codebases specifically. "None yet, here's my adjacent depth" is an acceptable, honest answer.
  • Engagement shape: typical duration, deliverables, re-test policy, and a price range or your basis for quoting. Ranges are fine; "contact for pricing" alone is not.
  • Conflicts, disclosed: if you also sell development, remediation, or retainer services, say so here — per community rules, an auditor recommending work they'd then perform must have disclosed that up front.

How engagements work

Directly between you and the maker — the platform doesn't broker, take a cut, vet or certify auditors. What I don't do: check the claims in an intro, publish intros on this site, or keep a list of providers. An intro is a thread its author starts on GitHub Discussions. There is no auditor directory on AXIS Launch and no "Security Audited" badge: none of the badges at /verification says anything about security.

For makers reading

An auditor's intro on GitHub Discussions has been checked by nobody at AXIS Launch — not the credentials, not the work quality. Ask for the sample report. Ask the references. The thread "Reading an audit report as a buyer" covers what good looks like.

Auditors: what would you want a maker to check about your peers before hiring one? Put the answer in your intro on GitHub Discussions.

Replies (4)

AXIS Editorial

Follow-up question: "Certifications say little about LLM-security skill — the certs barely cover it. What signal should I actually weight?"

Agreed, and worth saying publicly: current security certifications predate most of the prompt-injection era, so treat them as evidence of professional baseline, not AI-app competence. The stronger signals for this niche, per practitioners: published analysis of LLM-app vulnerabilities (writeups beat credentials), familiarity with the OWASP LLM Top 10 demonstrated in the sample report rather than name-dropped, and specific answers to 'walk me through how you'd map my injection surface.' Weight your own checks accordingly — checkable work products over checkable acronyms.

Jonathan (AXIS Launch)

On why the template asks for a price range or a pricing basis: information asymmetry is worst exactly here, where buyers can't judge the work and sellers know it. Solo makers get quoted 4x apart for equivalent scope, and can't tell whether the delta is quality or opportunism. Ranges in intros ('$X-Y for a 3-day grey-box review of a typical solo-maker app') let the market see its own spread. Auditors whose value justifies premium pricing can say why — that's a better position than opacity anyway.

AXIS Editorial

Follow-up question: "What questions should I ask in a first call with an auditor?"

Six that discriminate: (1) 'What will you NOT look at in this scope?' — good auditors answer instantly; (2) 'Walk me through a finding from the sample report — how did you rate its severity?'; (3) 'What's your re-test policy after I fix things?'; (4) 'Have you audited AI-generated codebases — what did you find that surprised you?'; (5) 'Who does the work — you, or someone junior under your brand?'; (6) 'If you find nothing serious, what does the report say?' — the answer reveals whether they sell findings or assessment. Then check one reference with 'what did the engagement miss?' rather than 'were you happy?'

AXIS Editorial

Moderation note for this thread, so the rules are on the record: we verify no auditor's credentials and publish no intros on this site — an intro is a thread its author starts on GitHub Discussions (the link is at the foot of this page). AXIS Launch keeps no list of auditors. A dispute with an auditor goes to the admin: message Jonathan Arvay on LinkedIn. And per the conflicts rule: an auditor who answers a security question on GitHub Discussions and also sells audits says so in that post (Rule 3 of /legal/community-guidelines). Helpful participation is welcome; undisclosed selling is not.

Nobody can post or reply on these pages. New threads start on GitHub Discussions, which needs a GitHub account. A thread posted there appears at once and is moderated afterwards. The six categories are not set up on GitHub yet, so a "Start a thread" link opens GitHub's own list of categories. Pick the closest one and name the category in your title.

This page keeps its address. What is posted on GitHub follows the community guidelines, and About this community says who writes and moderates here.

Start a thread in Auditors & Security →