Context
anita.legal is a German AI legal-research platform for law firms. I am engaged directly, under my own name, working alongside the company’s CTO.
Business problem
A startup selling into law firms is asked to prove things early: how the stack is secured, what a pentest would find, what an investor’s technical due diligence would turn up, and what a certification audit would want to see. The CTO carried all of that next to a product the team had to keep building.
My mandate
Work with the CTO on security and the practices around it: review the tech stack, modernise the architecture, optimise the AWS setup, prepare what audits, pentests, due diligence and certification ask for, and change how the team builds.
Decisions
- Security as a review first. A comprehensive review of the tech stack, then security best practices introduced into the way the team works — including SAST and SCA vulnerability scanners, static application security testing and software composition analysis, and licence best practices.
- One body of evidence for external review. Audit preparation, pentest preparation, investor technical responses, due diligence and a probable certification prepared together with the CTO, including advice on which certification to go for.
- AWS as an architecture question, not only a bill. The AWS setup was reviewed and optimised; the long-term savings alone covered the engagement.
- An architecture that still holds with AI in it. The architecture was modernised, with AI-ready security best practices implemented alongside it.
- AI inside the development process. AI-accelerated coding best practices taught to the team, with agentic teams and automated workflows.
- A daemon in the development loop. Interactive and on demand: it plans implementation for developers, takes tickets from their helpdesk platform and implements them autonomously, raises pull requests, and reviews the developers’ pull requests.
Delivery
The work sits inside the team’s existing tooling rather than beside it: the scanners and licence handling run in the pipeline they already use, and the daemon works from the helpdesk queue they already file into. No dates, duration or contract terms are published.
Outcome
The AWS optimisation paid for the engagement: the long-term savings alone covered it. The CTO has the material that audits, pentests, investor due diligence and a certification review ask for. Security scanning and licence handling sit in the pipeline rather than in a report. The team builds with AI-accelerated practices, and a daemon plans and implements tickets from the helpdesk queue, raises pull requests and reviews theirs.
Reuse
The scanner and licence setup, the agentic development practice and the on-demand daemon are ways of working rather than one-off configurations: each transfers to another team with a different stack.
Evidence
The AWS result is stated as a comparison rather than a figure: the long-term savings alone covered the engagement. Everything else here is qualitative, and no metrics from the engagement are published. The link in the facts panel is the company’s own site.