Code Security Analysis
Static and manual review of source code, integrated into your pipeline so findings arrive as pull-request comments rather than as a PDF at quarter end.
What you receive
- SAST tuned to your stack — signal, not noise
- Manual review of authentication and crypto paths
- Pipeline integration with developer-facing output
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
The scanner output has gone untriaged
A queue nobody reads is the same as no scanner at all. The work is deciding which rules to switch off, which findings are reachable from an entry point and which are true but unimportant — after which the queue is small enough to be someone's job.
You wrote your own authentication
Automated analysis can spot a weak cipher constant. It cannot tell that a token is verified with the wrong key, or that a password-reset flow trusts an identifier supplied by the caller — those paths are read by a person, line by line.
An auditor wants evidence of code review
Several regimes require that code is reviewed before release, by someone other than its author, with the outcome recorded. The evidence falls out of doing the review properly. Worth knowing before you buy it: a record in which every review passed tells an auditor very little, so a real review will sometimes hold a release.
How it runs
Scoping call
Thirty minutes with an engineer, not a sales development rep. We establish what you actually need and tell you plainly if it is not us.
Written proposal
Fixed scope, fixed price, named delivery team, and the rules of engagement in writing before anyone touches a system.
Delivery
Weekly written status and a direct channel to the delivery lead. Critical findings are escalated the moment they are confirmed, never held back for the report.
Readout and retest
A working session with your team, an executive summary for your board, and a remediation retest included in the original scope rather than quoted separately.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
Review is bounded by the source you give us — a dependency you consume as a binary is read as a black box, not as code.
We do not commit to your repositories. Every finding names a fix, and the decision to take it stays with the team that owns the file.
Runtime behaviour is out of scope; a flaw that only appears in the deployed configuration is found by Application Security testing.
- PCI DSS 4.0.1 Req. 6.2.3
- Bespoke and custom software must be reviewed before release; a manual review must be done by someone other than the author and approved by management.
- ISO/IEC 27001:2022 Annex A 8.28
- Requires secure coding principles to be applied to software development; the supporting guidance covers what happens before, during and after coding, including review.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Do you need write access to our repositories?
Read access is enough to review, and pipeline comments need a token that can write comments, not code. If your legal position forbids either, we can work from an exported snapshot, at the cost of losing the commit history.
Will SAST findings map to real exploitability?
Not on their own — a static tool reasons about code paths and knows nothing about what sits in front of the application. Deciding whether a path is reachable in your deployment is a judgement call, which is why triage is part of the work.
Is one review enough, or does this have to be continuous?
A review is true on the day it is finished and ages at the speed you commit. It is a reasonable baseline before a release or an audit, but holding it true across every branch is a pipeline problem rather than a review problem.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.