Mihály Tari.

AI transparency

How I work with AI

The first question I usually get about an audit is where the code ends up. So here's what touches yours, what happens to it, and where I sit in the process.

  1. 01

    In short

    For audits and rescues I use Claude Code, which sends your code to Anthropic's machines over the API — the connection programs use to talk to each other. Model training is switched off on my account — the setting that would let what you send become training material — and Anthropic states that the data is then not used for training and is deleted after 30 days. I write every finding myself, by hand. If no AI may touch your code at all, I do that too, for a surcharge.

  2. 02

    What touches your code

    Two things reach the code, and only one sends anything off my machine. Claude Code calls Anthropic's API, so whatever goes to it lands on Anthropic's machines. The rest runs here: my scripts, Semgrep (which matches known bug patterns in source code), the usual open-source dependency checkers, and OWASP ZAP, which probes the running site from outside. Those are not AI, they send no code anywhere, and the dependency checkers only look up package names and versions. On client code I use no other AI running on someone else's servers: no ChatGPT, no Cursor, no Copilot.

  3. 03

    What happens to the data

    Client code goes through Claude Code to Anthropic's API under my own account, where model training is switched off. Anthropic is the processor here, handling the code on my instructions, and states that the data is not used for training and is deleted within 30 days. Anthropic also states that the code travels over an encrypted connection (TLS) and sits encrypted where it is stored (AES-256). Processing happens in the United States under Anthropic's privacy policy, and that matters if your contract says where your data may be handled. Claude Code keeps session logs on my machine — a record of what I asked and what came back — for 30 days, and I delete them when the audit closes. I don't send those logs to Anthropic as feedback.

    • Anthropic, PBC (USA)

      This is the company that runs the Claude models and the API. Its privacy centre sets out the retention periods and the training setting.

      privacy.claude.com

    If we sign a data processing agreement, this section goes into the clause that lists the sub-processors.

  4. 04

    Automations are different

    The promise above is about my own work: how I read your code. An automation is a different thing, because it doesn't run once on my machine but continuously at your company: wherever a language model does the processing, every incoming email, order, document or phone call is sent to the provider running it. That's why I build it on your own account with that provider, under your own data-processing agreement, and I work inside that account as an invited user: at handover I remove my own access if you want me to. With Monitoring it stays, because I'm the one reading the alerts. Every chatbot and phone agent says at the start of the conversation that it's AI, and nothing about the caller is analysed beyond the request itself.

  5. 05

    Where I sit

    The AI is good at saying where to look and what is suspicious, but part of that is wrong, so I check it all. I read the repo (the place the code lives) end to end, and write every finding myself: the evidence, how it bites, the fix and how long it takes. If it's in the report, I looked at it; if I didn't get to something, the report says so.

  6. 06

    Available without AI

    Some contracts, and some investors, rule out any AI touching the code, and I don't argue with that. In that case the audit is done without it: my scripts and Semgrep run on my machine, and the rest I read. You get the same report, with the same limits. The price is €420 more, and it takes 2–3 weeks instead of 1–2, because I do the first pass through the code by hand too. When you ask for a quote, just say you want it without AI.

  7. 07

    What I do not do

    There are a few things I deliberately don't do, and it's better to know that upfront. I don't hand over an AI-written report unread, and client code doesn't go into model training. I don't invent testimonials, and there are no AI-generated pictures of me. If any of that changes, it's written here, with a date.