The challenge behind the engagement.
A secure code review checks whether the code that handles money, identity, and customer data does what the design says. We agree the paths first: sign-in and sessions, who is allowed to do what, where untrusted input reaches a database, a command, or a file, how secrets and encryption are handled, and business logic where ordering or replay matters. Proven analysis tools tuned to your stack steer the manual work, and a person judges every result; scanner output is never the deliverable. We follow each entry point to where it lands, check how the application is configured, and prove exploitability in a safe test build. You receive findings with exact locations, a trace, and a fix for the owning developer, plus a coverage statement, reusable rules, and a retest. The review covers the agreed paths, not the whole codebase.
For engineering leads and product security owners before a major release, after acquiring a codebase, or after licensing vendor code. Also for teams whose customer or PCI DSS assessor asks for evidence that critical modules were reviewed by a person rather than a scanner.
What we do.
What you can use.
Fix the commit and the paths
You grant read-only repository access or an export at a fixed commit, with build instructions, a runnable test build, dependency manifests and lock files, and language and framework versions. We take your threat model or spend an hour building one, then agree the modules in scope, typically payments, authentication, admin APIs, and file handling. Third-party code is reviewed under your NDA or escrow terms.
Trace by hand, steer with tools
Proven analysis tools with rules tuned to your frameworks, plus dependency and secrets scanning, produce a baseline we triage by hand. We follow untrusted input from every entry point through to where it could do harm, and we check every action for a missing permission check, one of the most common serious flaws in live code. We prove exploitability in your safe test build.
Deliver developer fixes and verify changes
Each finding names severity, the exact location, a trace or reproduction, and a fix written for the developer who owns the file. You also receive a coverage statement, the triaged tool baseline with false positives explained, and reusable detection rules for the patterns we found, so your pipeline catches them next time. We retest later, then delete our copy of your source.
Who it’s for.
When you need it.
- Engineering teams shipping code that handles money, credentials, or regulated customer data
- Organizations that recently acquired a codebase or licensed software they did not write
- Product security owners needing proof a person, not only a scanner, reviewed critical modules
- Teams whose scanners surface noise yet miss authorization and business-logic flaws
- A major release or refactor of a payment, authentication, or admin component is approaching
- An acquisition or vendor code drop needs review before it reaches production
- A customer questionnaire or PCI DSS assessor asks for manual code-review evidence
- An incident traced a breach to logic an automated scanner could not catch
What the scope can include.
- 01
Authentication, session handling, password reset, and token issuance traced end to end
- 02
Permission checks at every level, confirming who is allowed to do what across every route and handler
- 03
Every place untrusted input reaches a database, a system command, a file path, or stored data
- 04
Encryption, secrets handling, and how the application and its framework are configured
- 05
Business logic, race conditions, and multi-step transactions where ordering or replay changes the result
- 06
A tool-assisted baseline with rules tuned to your stack, every result triaged by hand and false positives explained
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
One application under about 20,000 lines, focused on sign-in, payments, and customer data
About 32–60 hoursOne business application of 20,000 to 100,000 lines
About 80–140 hoursA large application of over 100,000 lines, or several languages
About 160–280 hours- Size of the code that handles money, identity, and customer data
- Number of programming languages and frameworks
- Complexity of the business logic and permission checks
- Whether a retest of the fixes is included
1–2 weeks for a small application; 3–6 weeks for a large codebase, plus a retest of fixes
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Findings with severity, exact location, a trace or reproduction, and a code-level fix
- Coverage statement naming which paths were reviewed by hand and which only by tooling
- Reusable detection rules for the patterns found, so your pipeline catches recurrences
- Retest evidence at a later point confirming that each remediated finding is closed
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
We already run automated scanners; what does a manual review add?
Automated scanners match known patterns. They are good at obvious injection points and known-bad calls, and weak at permission logic, business rules, timing bugs, and misconfiguration. That is why missing permission checks remain one of the most common serious flaws despite years of scanning. We start from your scanner output rather than ignoring it and check every result. Then we read the flows a tool cannot judge: who is allowed to call this, what happens when two requests race, whether the token is checked on every route. Patterns we find become reusable rules so your pipeline catches them next time.
Do you need the whole repository, or can we scope to payments and authentication?
Scoping to specific modules is normal and usually the best use of the time. We still need enough surrounding code to follow a request: shared libraries, middleware, configuration, and the routes that call into the modules. A targeted review of a few critical modules is usually one to two weeks; a baseline review of a mid-sized application runs three to six weeks. Effort is driven by lines of code, number of languages, whether the code builds, and whether a threat model exists. Licensed vendor code can be reviewed under escrow or NDA terms.
- Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
- Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD Pipelines
- SLSA specification
- 2026 Minimum Elements for a Software Bill of Materials (SBOM)
- OWASP Top 10 CI/CD Security Risks
- Threat Modeling - OWASP Cheat Sheet Series
- 2025 CWE Top 25 Most Dangerous Software Weaknesses
