How It Works

A Defined Process for Every Audit

Each engagement follows the same structured methodology. Consistency means findings are comparable, reports are clear, and nothing falls through the gaps.

01

Initial Scoping Call

We begin with a structured conversation covering your technology stack, codebase size, deployment architecture, and the specific concerns driving the audit request. This call takes approximately 45 to 60 minutes and results in a written scope document that defines what the audit will and will not cover.

45-60 minutes
Scope document produced
02

NDA and Access Setup

Before any code is reviewed, a mutual NDA is signed and read-only repository access is established through your preferred method. We support GitHub, GitLab, Bitbucket, and secure archive transfer. Access is scoped precisely to the repositories relevant to the audit. No write access is ever requested.

NDA executed first
Read-only access only
03

Audit Execution

The review is conducted systematically across the agreed domains. Security review examines authentication, authorisation, input handling, dependency vulnerabilities, and cryptographic usage. Data handling review traces data flows, storage practices, and third-party integrations. Architecture review assesses service design, dependency structure, and failure handling.

Systematic domain coverage
Findings logged continuously
04

Interim Check-In

For full codebase audits, we schedule a mid-point check-in to share early findings, confirm scope alignment, and flag any critical issues that warrant immediate attention before the final report. This prevents surprises at delivery and gives your team time to begin addressing high-severity items.

Early findings shared
Critical issues flagged early
05

Report Delivery and Walkthrough

The final report is delivered as a structured document with an executive summary, domain-by-domain findings, severity ratings, and specific remediation recommendations for each finding. A delivery call walks your team through the report, answers questions, and clarifies any findings that need additional context.

Written report delivered
Walkthrough call included
Scope Detail

What Gets Examined, Domain by Domain

Security Review

  • Authentication and session management
  • Authorisation and access control logic
  • API endpoint exposure and rate limiting
  • Input validation and injection risk surfaces
  • Dependency vulnerability scanning
  • Cryptographic implementation review
  • Secret and credential handling
  • Logging practices and sensitive data exposure

Data Handling

  • Personal data flow mapping
  • Financial data storage and encryption
  • Data retention and deletion logic
  • Third-party data sharing and SDK review
  • Consent and opt-out implementation
  • Cross-border data transfer handling
  • Backup and recovery data exposure

Architecture Review

  • Service boundary and coupling assessment
  • Dependency management practices
  • Scalability assumptions and bottlenecks
  • Failure mode and resilience review
  • Infrastructure configuration review
  • Deployment and release process risk
  • Observability and monitoring gaps
Deliverable

What the Report Contains

The audit report is a structured document designed to be useful to two different audiences simultaneously: the technical team who will act on the findings, and the non-technical stakeholders who need to understand the overall risk picture.

Executive Summary

A plain-language overview of the audit scope, key findings, and overall risk assessment. Written for founders, investors, and board members.

Findings Register

Each finding documented with: description, location in codebase, severity rating (Critical / High / Medium / Low / Informational), and specific remediation steps.

Risk Summary Matrix

Visual overview of findings by domain and severity. Useful for prioritising remediation work and communicating risk status at a glance.

Remediation Roadmap

Suggested sequencing for addressing findings, grouped by effort level and business impact. Not prescriptive, but a practical starting point for planning.

Technical lead reviewing a detailed fintech audit report document at a desk with a laptop and printed findings
Start the Process

The first step is a scoping conversation.

Tell us about your codebase and your timeline. We will outline what an audit would involve and whether the timing makes sense.