@shv_founder ↗
Services / Source code audit (Code Review Security) Moscow · Worldwide

Code audit: logic holes, not just dependency CVEs

Manual and tool-assisted repo review: auth, SQL, secrets, dangerous patterns — what SAST misses.

Why it matters

Almost everyone patches dependencies. Business logic gets broken more quietly — and more painfully: data leaks, payment bypass, someone else’s access in your admin. Without a code review you learn from users or attack alerts, not from a report.

What we do

In this engagement:

  • Module and threat scope — what is actually exposed: auth, payments, API, admin
  • SAST + manual review — scanner as a baseline, engineer’s eye on logic and edge cases
  • Secrets and configs — keys, tokens, .env, hardcode, leaks in git history
  • Findings with fix examples — file, line, risk, how to close it without a full rewrite
  • PR process checklist — what to catch on every merge so holes don’t come back

How we work

We get repo access and a short product brief: who the user is, where money and data live. We run SAST, then manually cover auth, crypto, SQL/ORM, secrets, and risky patterns. You get a findings list with severity, exploit path, and a fix example; optional call to rank priorities. Timeline and scope are locked after we map the surface.

FAQ

How long does a security code review take?

It depends on repo size and scope: one critical service or the full product. After a short pass over modules and threats, we lock the timeline and report format — no vague ballpark from thin air.

What about pricing, and what do we get?

Price follows scope: language, codebase size, depth (high-risk only or broader). You leave with a report tied to files and lines, severity, fix examples, and a PR checklist so your team keeps catching this in-house.

Next / Your project

Give repo access — findings mapped to files.