What we would examine
Authentication, authorization, tenant boundaries, unsafe data flows, secret exposure, dependency risk, infrastructure definitions, deserialization, file handling, and business rules.
- Repository and branch agreed in scope
- Generated files and vendored code handled intentionally
- Framework-specific reasoning
What you would receive
A structured set of candidate and validated code findings with affected locations, preconditions, impact reasoning, evidence, and prioritized remediation guidance.
- Root cause and reachable path
- Confidence and unresolved assumptions
- Executive and engineering views
Important limit
Source review cannot prove runtime exploitability by itself. Environment configuration, deployed versions, gateways, and external services can change the actual risk. Runtime validation requires a separately authorized target.