Skip to content

Services/Code Review

Security Code Review

White-box review that finds what a yearly black-box test keeps missing.

Enquire about this service
C source under review

A false sense of security

After years of neglecting information security, many organisations now hire external consultants to test their applications. These consultants typically come in for a few days every year, test the web applications, produce a report — which is then acted upon, or not — and the matter is considered closed until the next year.

That typical black-box penetration test gives a false sense of security. Yes, it simulates a real attacker. It does not go deep enough. Why do consultants keep finding new issues in applications that have barely evolved? Why do some consultants find a lot more than others?

Our difference

We specialise in white-box application testing and code review. We couple the typical hacker simulation with an in-depth review of your code using automated tools and manual checks. If there is a vulnerability in your application, we will find it — as we have in dozens of proprietary and commercial applications.

A typical security code review combined with a penetration test finds at least 50% more vulnerabilities than a penetration test alone.

Full confidence

Any confidential data given to us, including source code, is kept encrypted with current industry-standard algorithms and handled accordingly. After the engagement we wipe the data within 30 days. Our non-disclosure agreements are honoured in perpetuity.

Contact us today to find out how we can help you.

Short engagements, senior consultants, and work we actually sign our names to.