SVC—07 · REVIEW

Security source-code review

Architecture and security-critical modules determine the review boundary. Raw line count alone does not define the work.

Start scoping
OWASP ASVS 5.0.0 subsetCWEManual data-flow and control-flow review

TEST BOUNDARY

What sits inside the boundary

Repositories, languages, buildability and generated-code boundaries
Authentication, authorization, cryptography, deserialization and trust boundaries
Architecture documents, tests and dependency context

ACCESS MODES

Knowledge level is scoped

Focused module review
Risk-led repository review
Review plus validation

DELIVERY—LEDGER

Deliverables you can inspect.

OUTPUT

Code-linked findings and data-flow evidence

Root-cause patterns and secure alternatives

Coverage map and explicit list of unreviewed areas

EFFORT—DRIVER

Security-critical modules and languages

Buildability and documentation

Architecture and framework complexity

EXPLICIT—LIMIT

Static tools assist but do not replace human review

Unreviewed and generated code is listed explicitly

POINT—IN—TIME

Precision includes what we do not claim.

A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.

Method and limitations

SCOPE—NEXT

Define the boundary before the fee.

Build a scope draft