Each engagement follows the same structured methodology. Consistency means findings are comparable, reports are clear, and nothing falls through the gaps.
We begin with a structured conversation covering your technology stack, codebase size, deployment architecture, and the specific concerns driving the audit request. This call takes approximately 45 to 60 minutes and results in a written scope document that defines what the audit will and will not cover.
Before any code is reviewed, a mutual NDA is signed and read-only repository access is established through your preferred method. We support GitHub, GitLab, Bitbucket, and secure archive transfer. Access is scoped precisely to the repositories relevant to the audit. No write access is ever requested.
The review is conducted systematically across the agreed domains. Security review examines authentication, authorisation, input handling, dependency vulnerabilities, and cryptographic usage. Data handling review traces data flows, storage practices, and third-party integrations. Architecture review assesses service design, dependency structure, and failure handling.
For full codebase audits, we schedule a mid-point check-in to share early findings, confirm scope alignment, and flag any critical issues that warrant immediate attention before the final report. This prevents surprises at delivery and gives your team time to begin addressing high-severity items.
The final report is delivered as a structured document with an executive summary, domain-by-domain findings, severity ratings, and specific remediation recommendations for each finding. A delivery call walks your team through the report, answers questions, and clarifies any findings that need additional context.
The audit report is a structured document designed to be useful to two different audiences simultaneously: the technical team who will act on the findings, and the non-technical stakeholders who need to understand the overall risk picture.
A plain-language overview of the audit scope, key findings, and overall risk assessment. Written for founders, investors, and board members.
Each finding documented with: description, location in codebase, severity rating (Critical / High / Medium / Low / Informational), and specific remediation steps.
Visual overview of findings by domain and severity. Useful for prioritising remediation work and communicating risk status at a glance.
Suggested sequencing for addressing findings, grouped by effort level and business impact. Not prescriptive, but a practical starting point for planning.
Tell us about your codebase and your timeline. We will outline what an audit would involve and whether the timing makes sense.