Get a source code review
Have your source code examined before launch, during an acquisition or to support an audit. DongIT combines static analysis (SAST) with manual review by OSCP- and OSWE-certified ethical hackers.

Findings are mapped to OWASP ASVS, CWE and the compliance frameworks relevant to your sector: the applicable DigiD framework, ISO 27001:2022 Annex A.8.28 (secure coding), NIS2 article 21(2)(e) and PCI DSS Requirement 6. Reporting via our self-developed Security Reporter platform with CVSS scoring and concrete remediation guidance per finding.
CCV Keurmerk-accredited. Data stays in Europe. DongIT is ISO 27001:2022-certified and works under the four-eyes principle.
Our three services for codebase assessment
Depending on your goal we offer three complementary services, individually or combined. Each delivers its own insights for secure development, compliance evidence and risk management.
Static code analysis (SAST)
Automated analysis of your full codebase with commercial SAST tools (for example Semgrep, SonarQube, Snyk Code, Checkmarx). We configure the tooling to your stack and manually filter out false positives.
- Full codebase in scope
- OWASP Top 10 and CWE mapping
- Dependency scanning and SBOM
- Suitable for CI/CD integration
Security code review (manual)
In-depth manual review by OSCP and OSWE-certified ethical hackers. Focus on issues that scanners systematically miss: business logic flaws, authentication and authorization flows, cryptographic implementation and risky patterns.
- Critical modules in scope
- Business logic and authentication
- Cryptography and key management
- Four-eyes principle with peer review
Code inspection (quality assessment)
Independent judgment when taking over a codebase from an external vendor or legacy application. Beyond security we assess maintainability, architectural choices and technical debt.
- General code quality
- Maintainability and readability
- Architecture and technical debt
- Basic security scan included
For DigiD applicants and TPM engagements we typically recommend the combination of SAST + manual security code review. This delivers the most complete audit evidence.
Our approach: five phases from intake to remediation
Every source code review follows the same structured approach, regardless of which of the three services (SAST, manual review or code inspection) you engage.
Scope definition and access
We jointly determine which modules, repositories and languages are in scope. Access to your Git repository (GitHub, GitLab, Bitbucket, Azure DevOps) or shared codebase is arranged. For sensitive codebases we work within your own environment.
Tooling configuration and baseline
For SAST we configure the tooling to your stack and frameworks. For manual review we first read architecture documentation, threat models and API specifications. Baseline configuration is tailored to minimize noise.
Analysis and verification
Static analysis and/or manual review by OSCP and OSWE-certified ethical hackers. Every finding is manually verified. False positives are filtered out before reporting takes place.
Reporting via Security Reporter
Delivery via Security Reporter. Every finding gets CVSS scoring, CWE mapping, concrete remediation guidance and code reference (file and line). Executive summary for management, technical details for developers.
Remediation support and retest
Direct contact with the reviewer via the Security Reporter portal for developer questions. Optional retest of resolved findings. For large engagements we recommend a remediation review after 4 to 6 weeks.
Duration: typically 2 to 4 weeks for medium-sized codebases, 4 to 8 weeks for enterprise scopes.
AI-assisted code review within our own environment
By default, we analyze your source code within our own infrastructure in Europe, including when we use AI. We only share your source code with external AI or analysis services with your prior permission. We agree with you which service we will use and which data will be shared.
AI does not replace our OSCP and OSWE-certified reviewers, it accelerates them. Where SAST rules match regex-based patterns, a semantic model understands context: business logic flaws, subtle authentication issues and risky patterns that no traditional scanner detects. Every AI finding is manually validated by an ethical hacker before it appears in your Security Reporter report.
Sharing only with your permission
Without your prior permission, we do not share your source code with external AI or analysis services. If you give permission, we document the agreed service and the data to be shared. All other confidentiality and data protection arrangements continue to apply.
Human-in-the-loop
AI signals, humans decide. Every finding is verified by an OSCP or OSWE-certified ethical hacker before reporting takes place. The four-eyes principle remains leading. AI is a force multiplier, not an autonomous authority.
Semantic reasoning
Where SAST only matches patterns, AI understands context. Detects business logic flaws, authentication bypass patterns and cryptography misuse that scanners systematically miss. Complement to SAST, not a replacement.
Important: AI support is included with all three of our code review services at no additional cost. For organizations that want to exclude AI analysis entirely for compliance reasons, we can disable this component. This is discussed during intake.
Who is source code review suitable for?
Codebase assessment is valuable for four concrete target groups. Each with their own priorities and compliance triggers.
Software vendors and SaaS builders
At release of new major versions, for certification statements toward enterprise clients, or as a condition for TPM issuance by your accountant. Often part of a DigiD assessment or ISO 27001 audit with secure development scope.
Government organizations with DigiD connection
For a DigiD assessment, we agree the technical evidence needed with your auditor upfront. A source code review can provide additional insight into security logic but is not automatically mandatory for every DigiD connection.
Organizations acquiring code
At mergers and acquisitions, when taking over from an external vendor or migrating legacy applications. Code inspection provides independent insight into quality, security status and technical debt before you sign.
Enterprise organizations with in-house development
For secure SDLC implementation, shift-left security and CI/CD integration. Our SAST configuration can be structurally incorporated into your development workflow. Manual reviews periodically on critical changes.
Compliance context for source code review
For four compliance frameworks, source code review is either a concrete obligation or a strong recommendation:
DigiD normenkader
We align the code review with the applicable DigiD framework, NOREA assessment guidance and arrangements with your auditor. This establishes which components will be assessed and how the results contribute to the assessment.
ISO 27001:2022
Annex A.8.28 "Secure coding" requires secure coding principles with tooling and process anchoring. SAST integration and manual review cycles deliver demonstrable evidence for your ISMS.
NIS2 and Dutch Cybersecurity Act
Article 21(2)(e) requires "security in acquisition, development and maintenance of network and information systems". Code review is the most concrete implementation for internally developed applications.
PCI DSS Requirement 6
Requirements 6.2 and 6.3 mandate secure coding training and code review before production release. We deliver reporting that is directly usable for your PCI audit.
What does a source code review cost?
The price depends on codebase size (lines of code, number of modules), programming languages and frameworks, desired depth (SAST-only versus SAST + manual review) and whether certification evidence (TPM, DigiD) is required. Indicative budget ranges:
- SAST-only, indicative from €3,500 excl. VAT
- Manual review (compact), indicative €7,500 to €12,500 excl. VAT
- SAST + manual review, indicative €15,000 to €25,000 excl. VAT
- Enterprise and TPM engagements, tailored quotation
For recurring reviews on release basis or periodic SAST cycles, more favorable rates apply on multi-year agreements.
Scoping conversation as start
For every source code review engagement we start with a complimentary scoping conversation covering your codebase, languages, goal and compliance requirements. Concrete quotation within three business days.
Frequently asked questions about source code review
Below are the most frequently asked questions about source code review. For a complete overview please visit our FAQ page.
Which programming languages and frameworks do you cover?
Our reviewers have experience with the most common stacks: PHP (Laravel, Symfony), Java (Spring), .NET (ASP.NET, ASP.NET Core), JavaScript and TypeScript (Node.js, React, Vue, Angular), Python (Django, Flask, FastAPI), Ruby (Rails), Go, Kotlin, Swift. For specialized stacks (Rust, Elixir, embedded C/C++) we discuss upfront whether our expertise fits your codebase.
What is the difference between source code review and a pentest?
A pentest investigates how vulnerabilities in your application could be exploited. Our pentesters can also use source code and documentation: this is a white box pentest. We generally recommend this approach to use the available testing time effectively.
A source code review focuses on the code itself, for example security logic, data processing and cryptography. A full code review is a separate service; providing source code for a pentest does not automatically mean the entire codebase will be reviewed. The assessments can complement each other depending on your objectives and risk profile.
Does my source code really stay within your own environment?
Yes. By default, all analysis, including AI support, takes place within our own infrastructure in Europe. We only share source code with an external AI or analysis service with your prior permission. We agree with you which service we will use and which data will be shared. All other confidentiality and data protection arrangements continue to apply. If you want to disable AI analysis entirely, we discuss this during intake.
Do I need to give you full repository access?
Preferably yes for the duration of the review, with read-only rights. For sensitive codebases we work within your own environment (for example via VDI, jump host or dedicated review server). We sign a non-disclosure agreement upfront and process all code under GDPR-compliant terms.
Which SAST tools do you use?
For static application security testing (SAST), we use tools such as Semgrep, SonarQube, Snyk Code and Checkmarx. The tools we use depend on your technology and the available licenses. No single tool finds every vulnerability. Our pentesters therefore combine automated analysis with manual testing. They validate findings and remove false positives before including the results in your report.
Can you issue a Third Party Memorandum (TPM)?
We are not an accountant and do not issue TPMs ourselves. We do deliver the technical evidence your accountant or NOREA-certified IT auditor needs to issue a TPM. Our reporting is deliberately structured for this purpose and we regularly cooperate with the major accounting firms on TPM engagements.
How long does a source code review take?
Duration 2 to 4 weeks for medium-sized codebases (50,000 to 200,000 lines), 4 to 8 weeks for enterprise scopes. Active review time depends on complexity: SAST configuration 1 to 3 days, manual review 3 to 15 days per module, reporting 3 to 5 days.
What do I provide as input?
Access to Git repository or code export, architecture diagrams, API specifications (OpenAPI/Swagger), threat models if available and a brief technical description of your stack. For DigiD engagements also your DigiD normenkader mapping and compliance scope.
Can you integrate SAST into our CI/CD pipeline?
Yes. We can deliver SAST configuration that you can integrate yourself into GitHub Actions, GitLab CI, Azure Pipelines or Jenkins. For structural shift-left security we also provide advice on quality gates, break-build criteria and developer training on SAST output. This is typically a one-off implementation engagement of 2 to 4 weeks.
Does a code review combine well with a pentest?
Yes. For high-assurance engagements (DigiD, financial services, healthcare) the combination is standard. We offer combined engagements with double-mapping of findings to both pentest and code review scope. This delivers efficiency in reporting and more complete audit evidence than either alone.
Ready for certainty about your source code?
Preparing for a DigiD assessment or TPM engagement? Taking over a codebase and want an independent judgment? Want to integrate SAST structurally into your CI/CD pipeline? We start with a complimentary scoping conversation covering your codebase, goal and compliance context. Response within one business day. Quotation within three business days.
Nederlands