Secure Source Code Review
Static analysis with manual review of security-critical paths: authentication, authorisation, cryptography and payment handling.
Fee & intake
Sign in to see the engagement fee (plus 7.5% VAT), complete the intake form, save a draft if you need to, then pay to submit.
- Standard
- 10 business days
- Express
- 5 business days
Regulatory and standards basis
This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.
- OWASP Code Review Guide
- PCI DSS v4.0.1 Requirement 6.2
- NIST SP 800-218
Who this is for
- Firms handling card data
- Products with complex authorisation logic
What you receive
- 01Source code review report with file and line references
- 02Manual review of authentication, authorisation and cryptographic code
- 03Dependency and secrets analysis
- 04Remediation guidance with example fixes
How the engagement runs
Phase 1
Scope and authorisation
You define targets and sign a Testing Authorisation Form. Every in-scope target must have verified ownership — DNS TXT record, well-known file, cloud role or written attestation — before any traffic is sent.
Phase 2
Preflight
Targets are resolved, shared hosting is detected and flagged, and your emergency contact is notified that testing is beginning. Any gate failure aborts the run.
Phase 3
Automated testing
An industry-standard toolchain is run against the verified scope, mapped to OWASP ASVS, MASVS or PCI DSS 11.4 as applicable. All raw output is retained.
Phase 4
Triage and manual validation
Findings are deduplicated across tools and false positives eliminated with a recorded reason. Every critical and high finding is then reproduced and confirmed by a consultant, who also performs a scoped manual pass on business logic.
Phase 5
Reporting and retest
You receive the report with reproduction steps and evidence, plus one free retest within 90 days.
Questions
Who approves the deliverable?
A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.
Is this a manual or an automated test?
Both, and we are specific about the split. An automated toolchain covers known vulnerability classes — misconfiguration, known CVEs, injection, weak TLS, exposed services, dependency issues and secrets. A consultant then reproduces and confirms every critical and high finding, and performs a scoped manual pass on business logic: authentication flows, authorisation boundaries, insecure direct object references, workflow abuse and race conditions. We do not describe this as a fully manual test, because it is not.
What is explicitly not included?
This is not a load or stress test, not a social engineering assessment, not a physical security assessment, and not a source code review, unless you purchase those separately. Denial-of-service testing is never performed.
What do you need from us before testing starts?
A signed Testing Authorisation Form from someone with authority to give it, and proof of ownership for every in-scope target. We will also give you the static IP addresses our scanners egress from so you can allowlist them.
Where do our documents live?
In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our sub-processors and data residency are published on the trust page.
How do we pay?
By card through Stripe after you complete intake in the portal. You can save a draft without paying; submission happens only after payment succeeds.
Related engagements in Cybersecurity and Assurance
Business Continuity and Disaster Recovery Plan
Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.
CBN Risk-Based Cybersecurity Framework Assessment
An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.
Incident Response Plan and Playbooks
An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.