AmuraAMURA Software
Service · AI code audit · Distribution & B2B industry

AI code audit for distribution and B2B industry.

You shipped an AI quoting tool on Cursor, a customer portal on v0 or an order assistant on Lovable. We audit before one customer sees what you priced for another, or before an ERP token leaks.

The workflows, examples and figures on this page are illustrative composites and modelled targets, not measured client results. In a real project, we define the baseline, thresholds and human review with your data before rollout.

What we solve

In B2B, a leak isn’t a bug, it’s lost margin.

Every B2B customer has their price, their discount, their payment terms, their reserved stock. The AI tools your team built (quoting tools, customer portals, order assistants) handle all of that. When the ownership filter fails, Customer Small can see the price you charge Customer Large. An external audit catches it before your sales team does.

We audit what your team built through the sector lens: strict isolation between customer accounts, custody of ERP tokens, exposure of cost and margin data, and the spots where an AI agent has more permissions on your ERP than it should.

Implementation contract

How it runs in production

Workflow and actors

With product, engineering and ERP and business owners, we trace the quoting tool, portal or agent from input to write, review controls, reproduce findings, and agree priority, remediation and retest.

Systems and data

Scope may cover code, APIs, authentication, database queries and policies, secrets, logs and ERP connectors handling accounts, prices, discounts, cost, margin and inventory.

Exceptions and risks

We avoid using real data or writing to production where a controlled environment is enough. An exposed secret or cross-account leak is reported immediately so it can be contained before the audit continues.

Human review

The business owner validates commercial impact and account boundaries; engineering approves the remediation. We only close a finding once the fix has passed a reproducible verification.

Implementation pattern

We start with a threat model and combine manual code review, authorisation and tenant checks, API testing and permission analysis. The report separates evidence, risk, remediation and acceptance criteria.

Relevant integration

We review the connectors and scopes the application actually uses in SAP, Holded, Odoo, Sage, Dynamics or another ERP; naming a vendor does not imply access to or coverage of modules outside scope.

What we build for this sector

Use cases that ship to production.

See full catalogue →
Isolation

Per-customer pricing and terms isolation

The target design limits each customer to their own prices, discounts and payment terms. We verify the control at the SQL layer, not just the UI, and across the public APIs exposed by the quoting tool or portal.

Modelled acceptance target: no cross-account price leaks
ERP

AI agent permissions on the ERP

Tokens to SAP, Holded, Odoo, Sage, Microsoft Dynamics. What the agent can read, what it can write, what it should never touch (chart of accounts, master agreements, vendor data). Explicit deny.

Modelled acceptance target: permission audit trail per write
Cost & margin

Cost, margin and stock data that shouldn't leave

Quoting endpoints returning internal stock, vendor cost or computed margin in responses customers can inspect. What the UI hides, the API sometimes reveals.

Modelled acceptance target: sensitive fields out of responses
Multi-tenant

Isolation in multi-entity setups

If your group runs multiple legal entities, brands or channels (wholesale vs. retail), we audit that a Channel-B customer can't reach Channel-A data by changing a subdomain or tenant ID.

Modelled acceptance target: tenant boundary verified in code
Illustrative composite scenario · modelled figures and targets, not client results

A distributor with 1,800 active accounts.

Hypothetical industrial-supply distributor with an AI quoting tool built on Cursor over PostgreSQL and a customer portal on v0 over Supabase. Illustrative composite scenario modelling cross-account pricing exposure; it does not describe a client, incident or actual findings.
Modelled audit hypothesis

Modelled risk to test: the interface might show each customer their catalogue while the query reads the full catalogue by customer_id and filters only in the UI, exposing other accounts' prices through DevTools. The Holded integration could also use a token with write access to chart-of-accounts entries outside its intended scope.

Modelled remediation target

Modelled illustrative outcome: an audit could identify 14 findings and prioritise 4 criticals: an ownership filter in SQL, responses without cost or margin, a minimum-permission Holded token and a policy preventing full orders from reaching external logs. The remaining 10 would be documented with priority, deadline and owner.

Modelled target: 4 criticals remediated before the next renewal cycle
Frequently asked

What clients ask us

  • 01

    We handle cost, margin and per-account terms. How do you treat it during the audit?

    Under NDA, with read-only repository access. We don't copy real commercial data. If the audit needs to probe a real flow, we use test accounts your team sets up in staging.

  • 02

    Our ERP is SAP / Holded / Odoo / Dynamics and the AI agent writes to it. Do you cover that?

    Yes. We audit the connector: which token it uses, which objects it can read, which it can write, how it tells apart environments (sandbox vs production), how it handles errors and retries. If the connector writes to chart-of-accounts or stock, we read closely what stops it from writing when it shouldn't.

  • 03

    Can you detect whether a customer is seeing another's prices right now?

    We audit quoting flows and API responses for price-exposure risk. It isn't real-time monitoring, which is a separate service, but the report prioritises controls that reduce the risk and explains how to look for historical evidence of exposure.

  • 04

    We run multiple channels (wholesale, retail, white-label). Do you audit isolation between them?

    Yes, and it's usually where the most findings cluster. B2B multi-tenant mixes legal entities, subdomains, shared tables and overlapping pricing rules. We map every boundary and verify the code respects it, not just the documentation.

  • 05

    What is the end-to-end process, and who closes the audit?

    At intake we agree scope, environments and owners. We combine static review with dynamic tests in staging using synthetic accounts across the quoting tool, tenant boundaries and ERP permissions; the report prioritises findings and assigns each remediation to an owner on your team. We then retest corrected controls, and the distributor's designated owner accepts closure against the agreed criteria.

Trust

Safe, traceable AI,
enterprise-ready.

We design for privacy from the start, human control, traceability, usage limits, permissioning and documentation. For sensitive processes, we help assess risk and applicable obligations under GDPR and the EU AI Act.

  • 01We never train models on your data without explicit authorization.
  • 02Human review built-in for processes where risk demands it.
  • 03Traceability: prompts, sources, permissions, errors and metrics, all documented.
  • 04Privacy, security and control integrated from day one.
  • 05Solutions engineered to be maintained, audited and improved over time.
GDPREU AI ActAEPDISO 27001 readyEU data residency
Personal diagnosis

We work with
few clients.

Every engagement is led personally by one of the partners. If there's a fit, you get a personal first read of your case within one business day, not a canned demo.

How we work
  1. 01Tell us which process eats your time
  2. 02Personal reply within one business day
  3. 0320-minute call, no demo, no pitch
Start the conversation →