The free code analysis. What happens on day 0 and what the first findings contain.
No obligation, no sales call as a precondition. We connect your repositories, scan the existing code and tell you which findings are real and critical, which can wait, and what needs to happen first.

A report full of findings that nobody works through is not protection. That is why the first findings are not a raw list but an assessment: a person checks every finding before it reaches you and removes what is not exploitable in your specific case.
Three steps, one set of findings.
Connection
It starts with a contract, not an upload: we agree which repositories are checked, what the access is for and that it stays that way. Only then do we connect. If the code must not leave your premises, we set the scan up inside your environment.
Inventory scan
The entire existing code is checked at three depths: secrets and known unsafe patterns, every change in the context of the codebase, and the whole codebase with dependencies, repository history and configuration.
Prioritised findings
You get a clear report: which findings are real and critical, which can wait, and what needs to happen first. Sorted by real risk, not by volume.
Three things where most attacks on software begin.
Hardcoded credentials
Passwords, API keys and tokens in the code, including in the repository history. A key that was once checked in stays dangerous until it is rotated.
Vulnerable dependencies
Open-source packages with known flaws. The scan matches every dependency against known vulnerabilities and finds outdated libraries.
Unsafe code patterns
Unvalidated input, dangerous system calls, missing access checks and insecure defaults in the configuration.
An assessment, not a hit list.
Every scanner also reports findings that are not exploitable in the specific case. That is why a person sorts them before you see the report.
- Real and critical
What must be fixed immediately
Findings that are actually exploitable in the context of your codebase. With the reasoning why they are critical and the action that goes with them.
- Can wait
What is scheduled but not urgent
Findings with low risk or no current attack path. They are in the report so they are not lost, but they block nothing.
- First
The order for week 1
A clear priority instead of an endless list: which steps have to happen first and what they depend on.
- Removed
What is not a real risk
False positives never reach you. They are removed before the report so the list stays short and every entry counts.
Your code stays your code.
Governed by contract
The access has a single purpose, the search for vulnerabilities, and that is what the data processing agreement says. No passing on, no second use.
Processed in the EU
The analysis runs in the EU. The code is processed exclusively for the vulnerability check.
On request inside your environment
If the code must not leave the building, the scan runs on your side. The result is the same, only the location differs.
The findings are the end of the analysis. Everything else is your decision.
Work through it yourselves
The report is written so that your team can act on it without us. Priority, action and reasoning sit next to every finding.
Have it cleaned up
Rotate critical secrets, update vulnerable libraries, defuse dangerous patterns. We carry out the fix and document it with a date.
Keep checking on every commit
From then on every change is checked before the code moves on. New critical findings are handled straight away and we report what is already done.
Questions about the code analysis
What does the code analysis cost?
Nothing. Connection, inventory scan and the prioritised findings are free and without obligation. Whether anything follows is your decision after the report.
What do we need for it?
A contact who names the repositories, and the signed data processing agreement. We set up everything else, inside your environment if required.
How long until the findings?
The first findings are ready after 48 hours: which findings are real and critical, which can wait, and what needs to happen first.
What exactly is scanned?
The three classes of finding at the top of this page: credentials that someone checked in, even years ago; libraries with a known flaw; and places in your own code where input, system calls or permissions are not secured. Plus the configuration and its defaults.
Does the analysis find every flaw?
No, and no other tool does either. Anything that looks like a fixed pattern is found. Anything that is only wrong in its business context, such as who may see which data, remains the job of a test or a review. The findings name that limit instead of hiding it.
We do not develop software ourselves. Is it worth it for us?
It depends on what you operate. An application you bought and host yourselves still consists of packages that age and settings nobody checks any more. The scan sees both. If you only have software that others run for you, there is nothing to connect, and the better starting point is our dark web monitoring.
What is in your code that should not be there?
Free code analysis, a clear result, no obligation.