SVC—07 · REVIEW
Security source-code review
Architecture and security-critical modules determine the review boundary. Raw line count alone does not define the work.
Start scopingTEST BOUNDARY
What sits inside the boundary
ACCESS MODES
Knowledge level is scoped
DELIVERY—LEDGER
Deliverables you can inspect.
Code-linked findings and data-flow evidence
Root-cause patterns and secure alternatives
Coverage map and explicit list of unreviewed areas
Security-critical modules and languages
Buildability and documentation
Architecture and framework complexity
Static tools assist but do not replace human review
Unreviewed and generated code is listed explicitly
POINT—IN—TIME
Precision includes what we do not claim.
A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.
Method and limitations