Who it is for
- →Public SaaS and consumer products with self-serve signup
- →Products shipping AI features or agent workflows
- →Teams preparing for SOC 2, ISO 27001 or enterprise vendor review
- →Boards asking a straight question: what could an attacker do to us today?
How it runs
- Week 0
Scope in one hour
A senior researcher looks at your public deployment live and agrees the scope with you. NDA signed inside 24 hours.
- Week 1
Assess
Read-only access. We map how data and money move through the product and run 1,200+ patterns across identity, spend, data exposure, automation, availability and AI-written code.
- Weeks 2–3
Protect
Every finding becomes a proposed change your engineers review and merge. We pair on the fix; you keep control of what ships.
- Day 21
Rules and evidence
Each fix is locked as a plain-English rule and re-testable on demand. You receive one page for the board and a control map for auditors.
What you get
- 01
- Findings reportRanked by bill, headline or outage, not by CVSS score. Each finding names the business outcome.
- 02
- Merged fixesPull requests reviewed and approved by your team.
- 03
- Plain-English rulesOne line per protection, such as "a user must never act on another user's account", each with a passing test.
- 04
- Board page and control mapWhere you stand today, what changed, and which SOC 2 and ISO 27001 controls each rule satisfies.
Questions
What is an AI security audit?
An AI security audit tests a software product against the techniques AI models now use to find and exploit vulnerabilities: enumerating every endpoint, chaining weak checks, and automating at scale. MATT runs 1,200+ such patterns against your live product with read-only access, then fixes what it finds with your team.
How long does a MATT security audit take?
Three weeks from the first call to merged fixes and written rules: one week of assessment and two weeks of protection work alongside your engineers.
Do you need access to our code or customer data?
Read-only access to your public deployment and, where useful, your repository. No agents are installed and no customer data leaves your environment; we observe behaviour, not records.
How is this different from a penetration test?
A pentest is one consultant for one week, once a year, ending in a PDF. A MATT audit uses researchers plus the same models attackers use, produces merged fixes, and leaves behind rules that are re-tested on every release.