Offers · Audit

Code and security audit

The value of an audit rests on how verifiable its findings are.
Here, each one cites the file, the line and the scenario that triggers it, then weighs the actual risk.
The reading is done by developers who write and operate production code all year, with analysis tooling in support.

10 to 15 business days from CA$12,500 Verifiable findings
Who it serves

Three common situations

Before a commitment

Acquisition, fundraising, a major contract, taking over an existing codebase: an independent, precise and dated assessment before you sign.

Before going to production

A launch, a scale-up, an API opening to third parties: the audit establishes what will hold, what is likely to break and the order of corrections.

At a third party's request

Enterprise client, cyber insurer, payment provider, security framework: the report constitutes the expected evidence, in the required format.

How it runs

Ten to fifteen business days, four steps

01

Scope

What enters the audit is fixed in writing: repositories, services, infrastructure, dependencies.

02

Architecture

Component boundaries, responsibilities, data flows, points of failure. Most expensive problems live at this level.

03

Code and security

Reading of the critical paths: authentication, access control, sensitive data, external input, secrets handling, dependencies. Tools assist the reading; the conclusions stay human.

04

Remediation plan

Findings are ranked by actual risk and the correction effort is costed. Your teams execute the plan, or ours do.

Deliverables

The deliverables

A report your developers will take seriously, because every finding can be checked by opening the file it cites.

  • Architecture report: structure, boundaries, data flows, points of failure.
  • Detailed findings: file, line, trigger scenario and risk.
  • Dependency review: versions, known vulnerabilities, licences.
  • Remediation plan: ranked by actual risk, costed in effort, ordered.
  • Executive summary: two pages, the decisions to take, in plain language.
  • Walkthrough session: a presentation with your teams, questions included.

Pricing. The audit is quoted in detail, from CA$12,500 depending on the size of the codebase and the security scope. A written preliminary assessment opens the engagement (CA$2,200 (plus taxes), delivered within five business days); its price is credited against the audit.

Have your code examined

The codebase and what is at stake, in a few lines. The preliminary assessment delimits the useful audit scope.

Contact us