auditamia
Ref. AM-SAMPLE
Indicative review
Hatchpad Ltd. (fictional)
AI spend, privacy, and control
Contents
Prepared for the directors
September 2026
Delivery
5 October 2026 · v1.2
Not a statutory audit, a penetration test, or a legal opinion.
auditamia
AI spend report
Hatchpad Ltd. (fictional)
September 2026
Ref. AM-SAMPLE
Opinion
Indicative opinion on AI spend and customer-data control for this period.
Control
Control: Low
Cross-account data access, AI chat without notice, and duplicate unused tools.
Scope. B2B webapp launched in weeks: dashboard, customer login, AI chat. They asked for AI spend review; the report also covers privacy and database risk before a fine or claim.
Figures for the period
| Figures for the period | Monthly | Annual (×12) |
|---|---|---|
| Spend in the period | €412 | €4,944 |
| Indicative savings | €71–€125/mo | €852–€1,500 (estimate) |
Matters this week
- 1
Close cross-account access between customers
Legal priority: until this is fixed and tested, do not onboard more customers with sensitive data.
€0
- 2
Bring the AI chat into compliance (notice + vendor contract)
Make clear what is sent to OpenAI and update the privacy page before promoting the assistant further.
€0
- 3
Cancel GitHub Copilot (duplicate of Cursor)
Direct license savings; the team already works only in Cursor.
€28
auditamia
AI spend report
Hatchpad Ltd. (fictional)
September 2026
Ref. AM-SAMPLE
Expenditure
Tools included in the period analysis.
| Tool | Type | Cost/mo | Usage | Verdict |
|---|---|---|---|---|
| OpenAI (web assistant) | Usage (tokens/API) | €124 | Product chat; the review showed it receives the user's email and name | Watch |
| Supabase (database) | Other | €48 | Customer data and files; incomplete access rules (see findings) | Watch |
| Cursor | Seats | €40 | Daily product development | Keep |
| Vercel (hosting) | Other | €34 | Production website | Keep |
| Anthropic (internal tests) | Usage (tokens/API) | €72 | Occasional experiments; overlaps with Cursor | Reduce |
| GitHub Copilot | Seats | €28 | No use in 30 days | Cancel |
| Make (automations) | Agents | €66 | Onboarding and emails; runs overnight with no need | Reduce |
| Total | €412 | |||
Composition
Monthly spend split by tool type
- Seats€68 · 17%
- Usage (tokens/API)€196 · 48%
- Agents€66 · 16%
- Other€82 · 20%
auditamia
AI spend report
Hatchpad Ltd. (fictional)
September 2026
Ref. AM-SAMPLE
Findings
Ordered by exposure, then by monthly savings.
F-01
Customers can see data that is not theirs
Indicative exposure €15,000–€80,000
- Observation
- The production site does not separate accounts properly: a user logs in and sees another company's projects and names. This is a serious database failure, common when the app was assembled quickly from templates.
- Implication
- This is not a monthly saving: it is exposure to claims, stopping sales, notifying the Spanish Data Protection Agency if a leak is confirmed, and GDPR fines (for SMEs, reputational and legal damage usually far exceeds savings on AI licenses).
- Recommendation
- Fix database access rules, test with two trial accounts, and keep a screenshot showing it no longer happens.
F-02
The AI chat processes personal data without saying so
Indicative exposure €5,000–€35,000
- Observation
- The assistant sends email and name to OpenAI. The privacy page does not explain this, and there is no data processing agreement (DPA) with the vendor.
- Implication
- Risk of GDPR non-compliance (information and legal basis) and of a customer or employee filing a complaint before you fix it.
- Recommendation
- Clear text in the chat and in the privacy policy, minimize what is sent to the model, and put a DPA in place with OpenAI.
F-03
Personal data kept in logs for too long
Indicative exposure €3,000–€25,000
- Observation
- Server logs store emails and paths with customer names and have no defined deletion period.
- Implication
- If those logs leak or an auditor requests them, it is the same problem as an app breach; fines for excessive retention.
- Recommendation
- Stop logging sensitive data, set a retention period (for example 30 days), and record it in the record of processing activities.
F-04
Copilot paid for with nobody using it
Savings €28/mo
- Observation
- Two licenses active on the invoice; the team develops in Cursor.
- Cost
- €28 a month wasted.
- Recommendation
- Cancel on GitHub and review licenses every quarter.
auditamia
AI spend report
Hatchpad Ltd. (fictional)
September 2026
Ref. AM-SAMPLE
Work programme
This week
- 1Fix cross-customer data access and document the test.
- 2Update privacy and the AI chat notice; start a DPA with OpenAI.
- 3Cancel Copilot and shorten log retention.
This month
- 1Bring the record of processing activities (GDPR) up to date with what the app actually does.
- 2Review database backups (encryption and who can export).
- 3Set an OpenAI spend cap and cut the Anthropic API if it is spare.
Next conversation
A 45-minute review to prioritize legal risk and AI spend for teams that launched the app very quickly.
Notes
- 1Legal exposure figures are indicative orders of magnitude, not fine predictions.
- 2This document is not legal advice; for penalties and notifications, consult a lawyer and your DPO.
- 3Illustrative example with fictional Hatchpad; Strix is a third-party tool cited only as a format reference.
auditamia
AI spend report
Hatchpad Ltd. (fictional)
September 2026
Ref. AM-SAMPLE
Appendix A · Audit sample (Strix format)
Sample security-agent output rewritten for leadership. In a real engagement we cross this with your AI invoices.
Technical reference: github.com/usestrix/strix · Apache-2.0 · usestrix/strix
Scope
Security and privacy review — Hatchpad (production web app)
App published on the internet (customer login, cloud database). Review without access to your admin panel: tests as a third party would run them.
Flow inspired by Strix (open-source agent, Apache-2.0)
01 · Critical
One customer can see another customer's data
A normal account can open files and company names that are not theirs. Typical when the database was left open during rapid development.
What to do: Separate data by customer in the database and test it with two trial accounts before selling further.
If you do not act: Claims from affected people, service shutdown, and a GDPR fine: high exposure for an SME (tens of thousands of euros in the worst case).
02 · High
Personal data in logs with no deletion period
Emails and names stay in server logs longer than needed; there is no clear policy for how long they are kept.
What to do: Stop logging sensitive data, shorten retention, and document it in the record of processing activities (GDPR).
If you do not act: Breach of minimization and storage limitation (GDPR art. 5); a fine and a duty to notify the authority if there is a leak.
03 · High
AI chat with no notice to the user
The product assistant sends the user's name and email to OpenAI without explaining it in the privacy policy or a data processing agreement with the vendor.
What to do: Update the privacy policy, tell users in the chat, and sign a DPA with the AI vendor.
If you do not act: Processing without a clear legal basis; complaints and a marketing freeze until it is regularized.
04 · Medium
Unencrypted database backups
Automatic backups exist, but encryption is not documented and it is unclear who can download them.
What to do: Turn on encryption with the database provider and limit who can export data.
If you do not act: If a backup leaks, it is as serious as a breach of the live app.
Illustrative sample for the auditamia report. Hatchpad is fictional; the format follows agent reports such as Strix (usestrix/strix), rewritten in business language.