Case study · Legal technology

Security, audit readiness and AI inside the development process

An independent engagement with anita.legal, a German AI legal-research platform for law firms: security best practices and a comprehensive tech-stack review, audit, pentest, due-diligence and certification preparation with the CTO, an optimised AWS setup, a modernised architecture, and AI-accelerated development including a daemon that implements tickets and reviews pull requests.

Independent engagement

Mandate

Security and the practices around it, a comprehensive tech-stack review, a modernised architecture, an optimised AWS setup, preparation for audits, pentests, due diligence and certification alongside the CTO, and AI-accelerated development inside the team.

Key decisions

  1. Start from a comprehensive review of the tech stack, then put the security practices into the pipeline: SAST and SCA scanning, and licence handling.
  2. Prepare audits, pentests, investor technical responses and a probable certification as one body of evidence, alongside the CTO.
  3. Put AI inside the development process itself: agentic teams, automated workflows, and a daemon that plans and implements tickets and reviews pull requests.

Outcome — qualitative

Covered the engagement, from the long-term AWS savings alone
Audit-ready material prepared for audits, pentests, due diligence and a certification review
Autonomous daemon that plans and implements tickets, raises and reviews pull requests
Stakeholders
  • The CTO
  • The engineering team
  • Investors running technical due diligence
  • External auditors and penetration testers
Constraints
  • External review as the bar: audits, pentests, due diligence and a probable certification
Reuse
  • SAST and SCA scanning with licence handling in the pipeline
  • AI-accelerated development practice: agentic teams and automated workflows
  • The on-demand daemon that plans, implements and reviews from the ticket queue

Context

anita.legal is a German AI legal-research platform for law firms. I am engaged directly, under my own name, working alongside the company’s CTO.

Business problem

A startup selling into law firms is asked to prove things early: how the stack is secured, what a pentest would find, what an investor’s technical due diligence would turn up, and what a certification audit would want to see. The CTO carried all of that next to a product the team had to keep building.

My mandate

Work with the CTO on security and the practices around it: review the tech stack, modernise the architecture, optimise the AWS setup, prepare what audits, pentests, due diligence and certification ask for, and change how the team builds.

Decisions

  • Security as a review first. A comprehensive review of the tech stack, then security best practices introduced into the way the team works — including SAST and SCA vulnerability scanners, static application security testing and software composition analysis, and licence best practices.
  • One body of evidence for external review. Audit preparation, pentest preparation, investor technical responses, due diligence and a probable certification prepared together with the CTO, including advice on which certification to go for.
  • AWS as an architecture question, not only a bill. The AWS setup was reviewed and optimised; the long-term savings alone covered the engagement.
  • An architecture that still holds with AI in it. The architecture was modernised, with AI-ready security best practices implemented alongside it.
  • AI inside the development process. AI-accelerated coding best practices taught to the team, with agentic teams and automated workflows.
  • A daemon in the development loop. Interactive and on demand: it plans implementation for developers, takes tickets from their helpdesk platform and implements them autonomously, raises pull requests, and reviews the developers’ pull requests.

Delivery

The work sits inside the team’s existing tooling rather than beside it: the scanners and licence handling run in the pipeline they already use, and the daemon works from the helpdesk queue they already file into. No dates, duration or contract terms are published.

Outcome

The AWS optimisation paid for the engagement: the long-term savings alone covered it. The CTO has the material that audits, pentests, investor due diligence and a certification review ask for. Security scanning and licence handling sit in the pipeline rather than in a report. The team builds with AI-accelerated practices, and a daemon plans and implements tickets from the helpdesk queue, raises pull requests and reviews theirs.

Reuse

The scanner and licence setup, the agentic development practice and the on-demand daemon are ways of working rather than one-off configurations: each transfers to another team with a different stack.

Evidence

The AWS result is stated as a comparison rather than a figure: the long-term savings alone covered the engagement. Everything else here is qualitative, and no metrics from the engagement are published. The link in the facts panel is the company’s own site.

Want the same thing done in your environment?

This case is one of several. If the shape looks like your problem, the fastest route is to send me the constraints you cannot move.

Remote-first, on-site when it matters; NDA on request