Back to code security
Code security · Free analysis

The free code analysis. What happens on day 0 and what the first findings contain.

No obligation, no sales call as a precondition. We connect your repositories, scan the existing code and tell you which findings are real and critical, which can wait, and what needs to happen first.

A workstation with two monitors and a keyboard in a dimmed office, the screens glowing softly out of focus.

A report full of findings that nobody works through is not protection. That is why the first findings are not a raw list but an assessment: a person checks every finding before it reaches you and removes what is not exploitable in your specific case.

The process

Three steps, one set of findings.

Step 1 · Day 0

Connection

It starts with a contract, not an upload: we agree which repositories are checked, what the access is for and that it stays that way. Only then do we connect. If the code must not leave your premises, we set the scan up inside your environment.

Step 2

Inventory scan

The entire existing code is checked at three depths: secrets and known unsafe patterns, every change in the context of the codebase, and the whole codebase with dependencies, repository history and configuration.

Step 3 · 48 hours

Prioritised findings

You get a clear report: which findings are real and critical, which can wait, and what needs to happen first. Sorted by real risk, not by volume.

What is checked

Three things where most attacks on software begin.

01

Hardcoded credentials

Passwords, API keys and tokens in the code, including in the repository history. A key that was once checked in stays dangerous until it is rotated.

02

Vulnerable dependencies

Open-source packages with known flaws. The scan matches every dependency against known vulnerabilities and finds outdated libraries.

03

Unsafe code patterns

Unvalidated input, dangerous system calls, missing access checks and insecure defaults in the configuration.

What the findings contain

An assessment, not a hit list.

Every scanner also reports findings that are not exploitable in the specific case. That is why a person sorts them before you see the report.

  • Real and critical

    What must be fixed immediately

    Findings that are actually exploitable in the context of your codebase. With the reasoning why they are critical and the action that goes with them.

  • Can wait

    What is scheduled but not urgent

    Findings with low risk or no current attack path. They are in the report so they are not lost, but they block nothing.

  • First

    The order for week 1

    A clear priority instead of an endless list: which steps have to happen first and what they depend on.

  • Removed

    What is not a real risk

    False positives never reach you. They are removed before the report so the list stays short and every entry counts.

Access and data protection

Your code stays your code.

Governed by contract

The access has a single purpose, the search for vulnerabilities, and that is what the data processing agreement says. No passing on, no second use.

Processed in the EU

The analysis runs in the EU. The code is processed exclusively for the vulnerability check.

On request inside your environment

If the code must not leave the building, the scan runs on your side. The result is the same, only the location differs.

And afterwards

The findings are the end of the analysis. Everything else is your decision.

Option

Work through it yourselves

The report is written so that your team can act on it without us. Priority, action and reasoning sit next to every finding.

Option · Week 1

Have it cleaned up

Rotate critical secrets, update vulnerable libraries, defuse dangerous patterns. We carry out the fix and document it with a date.

Option · Ongoing

Keep checking on every commit

From then on every change is checked before the code moves on. New critical findings are handled straight away and we report what is already done.

FAQ

Questions about the code analysis

  • What does the code analysis cost?

    Nothing. Connection, inventory scan and the prioritised findings are free and without obligation. Whether anything follows is your decision after the report.

  • What do we need for it?

    A contact who names the repositories, and the signed data processing agreement. We set up everything else, inside your environment if required.

  • How long until the findings?

    The first findings are ready after 48 hours: which findings are real and critical, which can wait, and what needs to happen first.

  • What exactly is scanned?

    The three classes of finding at the top of this page: credentials that someone checked in, even years ago; libraries with a known flaw; and places in your own code where input, system calls or permissions are not secured. Plus the configuration and its defaults.

  • Does the analysis find every flaw?

    No, and no other tool does either. Anything that looks like a fixed pattern is found. Anything that is only wrong in its business context, such as who may see which data, remains the job of a test or a review. The findings name that limit instead of hiding it.

  • We do not develop software ourselves. Is it worth it for us?

    It depends on what you operate. An application you bought and host yourselves still consists of packages that age and settings nobody checks any more. The scan sees both. If you only have software that others run for you, there is nothing to connect, and the better starting point is our dark web monitoring.

What is in your code that should not be there?

Free code analysis, a clear result, no obligation.