Your team continues developing with AI tools or its own engineers. WZ-IT regularly reviews technically relevant changes, assesses risks and documents clear priorities. Implementation, hosting and incident response remain separately commissioned services.
Companies worldwide trust WZ-IT
The retainer combines recurring human review with documented prioritisation. Your team retains development speed and product ownership while WZ-IT provides an independent technical view of the agreed application.
Assess not only isolated diffs but also architecture, data paths, permissions and the impact on the existing application.
Assess dependencies, CVEs, authentication, roles, data access and technical findings according to their actual relevance.
Record what should be resolved soon, what matters before a release and what can be consciously scheduled for later.
An AI code audit, ongoing code review and a penetration test serve different purposes. The comparison helps identify the suitable starting point.
The review allowance is defined around the repository, stack, change rate and risk profile. Automated scanners may be included, while assessment and prioritisation are performed by WZ-IT.
Review new or changed logic, critical paths, error handling and conspicuous patterns in the agreed repository.
Assess authentication, authorisation, tenant isolation, RLS, administrative functions and sensitive data paths.
Assess security advisories, package versions and EOL risks for actual exposure and required action.
Review coupling, interfaces, background processes and the data model against maintainability and product requirements.
Consider secrets, environments, builds, tests, rollback, monitoring and backups where they affect release risk.
Document prioritised findings and discuss them with your team within the included clarification allowance.
Clear service boundary
The retainer starts after a Production Readiness Audit or an equivalently documented technical baseline. Access, review allowance, cadence and deliverable format then remain transparent and consistent.
Align repository, architecture, risks and the open backlog with an existing audit or technical onboarding.
Agree the repository, relevant areas, change rate, release windows, communication channel and response target.
Assess risk-relevant changes and advisories on a monthly or continuous cadence.
Document findings, answer questions and prepare remediation by your team or under a separately agreed WZ-IT scope.
Retainer models
Both models cover one clearly scoped repository and an agreed change volume. Multiple repositories, unusually high change rates or intensive launch phases are assessed separately.
Monthly Review Retainer
from EUR 990 / month
excluding VAT, monthly
For early products and internal applications with predictable changes and one monthly technical control point.
Continuous Review Retainer
from EUR 1,950 / month
excluding VAT, monthly
For actively developed applications with regular releases, real users or more sensitive data paths.
The retainer is initially agreed for a minimum of three months. Review and clarification capacity is reserved for the respective month and is not a freely transferable development budget. Scope, access, change allowance and response targets are confirmed in the proposal before work starts.
The review retainer remains separate from implementation and infrastructure. This makes it clear whether WZ-IT is reviewing, implementing changes or operating the production environment.
Establish a one-time baseline for an unknown codebase, go-live risk and operational readiness before starting the retainer.
View the auditfrom EUR 699.90 excl. VAT / monthHave WZ-IT implement prioritised findings, updates, corrections and small features.
View Software CareAdd infrastructure, monitoring, backups and incident response as a separate operating scope.
View operating servicesRequest a retainer
Describe the application, repository, change rate and particularly critical areas. We assess the appropriate review cadence and whether a sufficient baseline already exists.
Baseline, review cadence, implementation, access and service boundaries
The retainer is a recurring technical review of one clearly scoped application. WZ-IT assesses agreed changes, security and dependency advisories and relevant architecture, data and operational risks, then documents prioritised next actions. Your team remains responsible for development unless implementation is added.
The Production Readiness Audit is a one-time baseline before go-live, takeover or a larger investment. The review retainer builds on a confirmed baseline and accompanies ongoing changes monthly or weekly.
Under the review retainer, WZ-IT reviews and prioritises while your team continues development. Under software maintenance, WZ-IT implements agreed updates, technical corrections and releases. Both services can be combined, but are then offered as one coordinated scope.
Yes. The retainer is intended for teams that continue working with AI tools or their own engineers. It requires a traceable repository, an agreed review process and sufficient context about the application, data and deployment.
No. The retainer includes review, prioritisation and technical clarification. Defect remediation, refactoring, tests, releases or feature development are agreed through Software Care, a development retainer or a separate project scope.
Not necessarily. Dependency, secret, static-analysis and other tools can provide valuable signals. WZ-IT assesses those findings alongside the code, architecture, data paths and product context instead of merely forwarding an unfiltered scanner list.
A time-limited and organisationally agreed read-only access to the relevant repository is generally sufficient, together with context about deployment, database, authentication and critical user journeys. Write or production access is not automatically required for review-only work.
The response target describes when WZ-IT picks up technical questions during the agreed business hours. It is not a guaranteed resolution, an incident response time or a 24/7 service level. Critical production operations are agreed separately through Managed Operations.
No. The service is a risk-oriented technical review, not a complete offensive security assessment. It provides neither certification nor a guarantee of defect-free software. A required penetration test is scoped separately.
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Proof for modernization, API extension, architecture, deployment and ongoing operations.
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.