Qantid
Class BTechnical testing

Secure Source Code Review

Static analysis with manual review of security-critical paths: authentication, authorisation, cryptography and payment handling.

Fee & intake

Sign in to see the engagement fee (plus 7.5% VAT), complete the intake form, save a draft if you need to, then pay to submit.

Standard
10 business days
Express
5 business days

Regulatory and standards basis

This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.

  • OWASP Code Review Guide
  • PCI DSS v4.0.1 Requirement 6.2
  • NIST SP 800-218

Who this is for

  • Firms handling card data
  • Products with complex authorisation logic

What you receive

  1. 01Source code review report with file and line references
  2. 02Manual review of authentication, authorisation and cryptographic code
  3. 03Dependency and secrets analysis
  4. 04Remediation guidance with example fixes

How the engagement runs

  1. Phase 1

    Scope and authorisation

    You define targets and sign a Testing Authorisation Form. Every in-scope target must have verified ownership — DNS TXT record, well-known file, cloud role or written attestation — before any traffic is sent.

  2. Phase 2

    Preflight

    Targets are resolved, shared hosting is detected and flagged, and your emergency contact is notified that testing is beginning. Any gate failure aborts the run.

  3. Phase 3

    Automated testing

    An industry-standard toolchain is run against the verified scope, mapped to OWASP ASVS, MASVS or PCI DSS 11.4 as applicable. All raw output is retained.

  4. Phase 4

    Triage and manual validation

    Findings are deduplicated across tools and false positives eliminated with a recorded reason. Every critical and high finding is then reproduced and confirmed by a consultant, who also performs a scoped manual pass on business logic.

  5. Phase 5

    Reporting and retest

    You receive the report with reproduction steps and evidence, plus one free retest within 90 days.

Questions

Who approves the deliverable?

A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.

Is this a manual or an automated test?

Both, and we are specific about the split. An automated toolchain covers known vulnerability classes — misconfiguration, known CVEs, injection, weak TLS, exposed services, dependency issues and secrets. A consultant then reproduces and confirms every critical and high finding, and performs a scoped manual pass on business logic: authentication flows, authorisation boundaries, insecure direct object references, workflow abuse and race conditions. We do not describe this as a fully manual test, because it is not.

What is explicitly not included?

This is not a load or stress test, not a social engineering assessment, not a physical security assessment, and not a source code review, unless you purchase those separately. Denial-of-service testing is never performed.

What do you need from us before testing starts?

A signed Testing Authorisation Form from someone with authority to give it, and proof of ownership for every in-scope target. We will also give you the static IP addresses our scanners egress from so you can allowlist them.

Where do our documents live?

In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our sub-processors and data residency are published on the trust page.

How do we pay?

By card through Stripe after you complete intake in the portal. You can save a draft without paying; submission happens only after payment succeeds.

Related engagements in Cybersecurity and Assurance

Business Continuity and Disaster Recovery Plan

Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.

CBN Risk-Based Cybersecurity Framework Assessment

An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.

Incident Response Plan and Playbooks

An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.