Services / Source code review

Source code review

We read your source code with an attacker’s mindset and find vulnerabilities that stay invisible from the outside.

With access to the source code we see exactly how your application works — and where it breaks. We combine static analysis with manual review of the critical parts: authentication, authorisation, input handling, cryptography and the handling of sensitive data. Your developers get findings with the exact line of code and a suggested fix.

What we look at

Authentication & authorisation

Can user A access user B’s data? Are sessions and tokens handled correctly?

Injection & input handling

SQL injection, XSS, deserialisation, path traversal and similar classics.

Secrets & cryptography

Hardcoded passwords and keys, weak algorithms, misuse of crypto libraries.

Dependencies

Vulnerable open source packages, and whether the vulnerable code is actually reachable.

What you get

  • Findings with file, line number and explanation
  • Concrete fix suggestions in your codebase’s language
  • Walkthrough with your developers
  • Advice on structural improvements and secure coding guidelines

A good fit for

  • Software companies and SaaS vendors
  • Applications that process sensitive or personal data
  • Alongside a pentest, for maximum coverage
  • After taking over code from a third party

Questions

Not sure this is the right service?

Start with the Security Posture Assessment, or book a call.

Where do I start? →
Which programming languages?

Including Java, C#/.NET, Python, JavaScript/TypeScript, Go and PHP. Not sure? Just ask.

Is our code safe with you?

We work under NDA, preferably with read access to your own repository rather than a copy, and delete all data after the engagement.

Curious how an attacker sees your organisation?

Book a no-obligation 30-minute call. We’ll discuss your situation and give honest advice on what makes sense — even if that isn’t work for us.