Consultation

Secure Code Review

Our flagship consultation: deep reading of authentication, authorization, session handling, input boundaries, and sensitive data paths — written for the people who will fix the code.

Who it is for

Product and platform teams preparing a public launch, a regulated integration, or a major refactor who want an independent reading of the code that handles identity, money, personal data, or privileged actions.

Result you leave with

A written findings report with severity, location (file or route), evidence of the issue, and suggested remediation. We close with a live walkthrough so leads can ask about edge cases and sequencing.

What is included

  • Intake briefing to lock repositories, environments, and out-of-scope areas
  • Manual review of agreed surfaces (typically auth, sessions, access control, data exposure, and critical business flows)
  • Dependency and configuration notes where they affect the reviewed surfaces
  • Severity-ranked findings with remediation guidance
  • One findings workshop (video or in-person in Taipei)

What is excluded

  • Full-network penetration testing or physical security
  • Guaranteed discovery of every defect
  • Hands-on patch implementation (available separately as hardening advisory follow-on)
  • Legal attestation or certification stamps

Process

  1. Brief — You share architecture notes, threat concerns, and access constraints.
  2. Access — We receive read access to repositories and, where useful, a staging environment.
  3. Review — Reviewers work the agreed window and log findings as they go.
  4. Report — You receive the written report at least one day before the workshop.
  5. Workshop — We walk findings, answer questions, and help prioritize.

Duration and delivery

Most focused reviews complete in five to ten working days after access is ready. Larger monorepos or multi-service estates are quoted as multi-week engagements. Delivery is primarily remote; Taipei-based workshops can be scheduled at our office or yours.

Preparation

Please prepare: repository list and branch freeze plan, architecture overview, identity/provider details, known prior issues, and a technical contact available for clarifying questions within one business day.

Pricing basis

Quoted per engagement. Drivers include number of services, language mix, whether staging access is available, and whether the review is first-time or a re-review after remediation. See Rates for starting ranges.

Next step

Send an inquiry with your release date and the surfaces you most want examined. We reply with scope questions and a proposed window.