Get a source code review
Do you want certainty that your source code is secure before it goes to production? Are you preparing for a DigiD assessment or Third Party Memorandum (TPM) that requires secure coding evidence? Are you taking over a codebase from a third party and do you want an independent judgment? DongIT combines static analysis (SAST) with manual review by OSCP and OSWE-certified ethical hackers.
Findings are mapped to OWASP ASVS, CWE and the compliance frameworks relevant to your sector: DigiD normenkader v4.0, ISO 27001:2022 Annex A.8.28 (secure coding), NIS2 article 21(2)(e) and PCI DSS Requirement 6. Reporting via our self-developed Security Reporter platform with CVSS scoring and concrete remediation guidance per finding.
CCV Keurmerk-accredited. Data stays in Europe. DongIT has been ISO 27001:2022-certified since 2015 and works under the four-eyes principle.

Our three services for codebase assessment
Depending on your goal we offer three complementary services, individually or combined. Each delivers its own insights for secure development, compliance evidence and risk management.
Static code analysis (SAST)
Automated analysis of your full codebase with commercial SAST tools (for example Semgrep, SonarQube, Snyk Code, Checkmarx). We configure the tooling to your stack and manually filter out false positives.
- Full codebase in scope
- OWASP Top 10 and CWE mapping
- Dependency scanning and SBOM
- Suitable for CI/CD integration
Security code review (manual)
In-depth manual review by OSCP and OSWE-certified ethical hackers. Focus on issues that scanners systematically miss: business logic flaws, authentication and authorization flows, cryptographic implementation and risky patterns.
- Critical modules in scope
- Business logic and authentication
- Cryptography and key management
- Four-eyes principle with peer review
Code inspection (quality assessment)
Independent judgment when taking over a codebase from an external vendor or legacy application. Beyond security we assess maintainability, architectural choices and technical debt.
- General code quality
- Maintainability and readability
- Architecture and technical debt
- Basic security scan included
For DigiD applicants and TPM engagements we typically recommend the combination of SAST + manual security code review. This delivers the most complete audit evidence.
Our approach: five phases from intake to remediation
Every source code review follows the same structured approach, regardless of which of the three services (SAST, manual review or code inspection) you engage.
Scope definition and access
We jointly determine which modules, repositories and languages are in scope. Access to your Git repository (GitHub, GitLab, Bitbucket, Azure DevOps) or shared codebase is arranged. For sensitive codebases we work within your own environment.
Tooling configuration and baseline
For SAST we configure the tooling to your stack and frameworks. For manual review we first read architecture documentation, threat models and API specifications. Baseline configuration is tailored to minimize noise.
Analysis and verification
Static analysis and/or manual review by OSCP and OSWE-certified ethical hackers. Every finding is manually verified. False positives are filtered out before reporting takes place.
Reporting via Security Reporter
Delivery via Security Reporter. Every finding gets CVSS scoring, CWE mapping, concrete remediation guidance and code reference (file and line). Executive summary for management, technical details for developers.
Remediation support and retest
Direct contact with the reviewer via the Security Reporter portal for developer questions. Optional retest of resolved findings. For large engagements we recommend a remediation review after 4 to 6 weeks.
Duration: typically 2 to 4 weeks for medium-sized codebases, 4 to 8 weeks for enterprise scopes.
AI-assisted code review within our own environment
Where many security parties analyze source code via cloud-based AI services (OpenAI, GitHub Copilot Security, Snyk AI), we never send your code to third parties. Our AI support runs on local large language models within DongIT's own infrastructure in Europe. For DigiD applicants, financial entities, healthcare organizations and government institutions this is often a hard requirement.
AI does not replace our OSCP and OSWE-certified reviewers, it accelerates them. Where SAST rules match regex-based patterns, a semantic model understands context: business logic flaws, subtle authentication issues and risky patterns that no traditional scanner detects. Every AI finding is manually validated by an ethical hacker before it appears in your Security Reporter report.
Data sovereignty
Your source code never leaves our own environment. No OpenAI, no Anthropic, no Google Gemini, no Microsoft cloud. Local inference on European hardware. Under Schrems II and GDPR a concrete advantage for regulated sectors.
Human-in-the-loop
AI signals, humans decide. Every finding is verified by an OSCP or OSWE-certified ethical hacker before reporting takes place. The four-eyes principle remains leading. AI is a force multiplier, not an autonomous authority.
Semantic reasoning
Where SAST only matches patterns, AI understands context. Detects business logic flaws, authentication bypass patterns and cryptography misuse that scanners systematically miss. Complement to SAST, not a replacement.
Important: AI support is included with all three of our code review services at no additional cost. For organizations that want to exclude AI analysis entirely for compliance reasons, we can disable this component. This is discussed during intake.
Who is source code review suitable for?
Codebase assessment is valuable for four concrete target groups. Each with their own priorities and compliance triggers.
Software vendors and SaaS builders
At release of new major versions, for certification statements toward enterprise clients, or as a condition for TPM issuance by your accountant. Often part of a DigiD assessment or ISO 27001 audit with secure development scope.
Government organizations with DigiD connection
The DigiD normenkader v4.0 requires secure development (norm B.03.03 and B.03.04). Our source code review delivers the technical evidence your DigiD assessment needs.
Organizations acquiring code
At mergers and acquisitions, when taking over from an external vendor or migrating legacy applications. Code inspection provides independent insight into quality, security status and technical debt before you sign.
Enterprise organizations with in-house development
For secure SDLC implementation, shift-left security and CI/CD integration. Our SAST configuration can be structurally incorporated into your development workflow. Manual reviews periodically on critical changes.
Compliance context for source code review
For four compliance frameworks, source code review is either a concrete obligation or a strong recommendation:
DigiD normenkader
Norm B.03.03 (secure development lifecycle) and B.03.04 (secure coding) require demonstrably secure development. Manual code review is the most concrete implementation for your annual DigiD assessment.
ISO 27001:2022
Annex A.8.28 "Secure coding" requires secure coding principles with tooling and process anchoring. SAST integration and manual review cycles deliver demonstrable evidence for your ISMS.
NIS2 and Dutch Cybersecurity Act
Article 21(2)(e) requires "security in acquisition, development and maintenance of network and information systems". Code review is the most concrete implementation for internally developed applications.
PCI DSS Requirement 6
Requirements 6.2 and 6.3 mandate secure coding training and code review before production release. We deliver reporting that is directly usable for your PCI audit.
What does a source code review cost?
The price depends on codebase size (lines of code, number of modules), programming languages and frameworks, desired depth (SAST-only versus SAST + manual review) and whether certification evidence (TPM, DigiD) is required. Indicative budget ranges:
- SAST-only, indicative from €3,500 excl. VAT
- Manual review (compact), indicative €7,500 to €12,500 excl. VAT
- SAST + manual review, indicative €15,000 to €25,000 excl. VAT
- Enterprise and TPM engagements, tailored quotation
For recurring reviews on release basis or periodic SAST cycles, more favorable rates apply on multi-year agreements.
Scoping conversation as start
For every source code review engagement we start with a complimentary scoping conversation covering your codebase, languages, goal and compliance requirements. Concrete quotation within three business days.
Frequently asked questions about source code review
Below are the most frequently asked questions about source code review. For a complete overview please visit our FAQ page.
Which programming languages and frameworks do you cover?
Our reviewers have experience with the most common stacks: PHP (Laravel, Symfony), Java (Spring), .NET (ASP.NET, ASP.NET Core), JavaScript and TypeScript (Node.js, React, Vue, Angular), Python (Django, Flask, FastAPI), Ruby (Rails), Go, Kotlin, Swift. For specialized stacks (Rust, Elixir, embedded C/C++) we discuss upfront whether our expertise fits your codebase.
What is the difference between source code review and a pentest?
A pentest tests your application from the outside (black-box or grey-box), without access to the code. A source code review analyzes the code itself (white-box). Both complement each other: a pentest finds visible exploit paths, a code review finds vulnerabilities deeply hidden in business logic or cryptography. For DigiD and high-assurance engagements the two are often combined.
Does my source code really stay within your own environment?
Yes. We do not send your code to OpenAI, GitHub Copilot Security, Snyk AI, Anthropic, Google Gemini or any other cloud service. All analysis (including AI support) takes place within our own infrastructure in Europe. Data processing is GDPR-compliant and described in our Data Processing Agreement. For organizations that want to disable AI analysis entirely we discuss that during intake.
Do I need to give you full repository access?
Preferably yes for the duration of the review, with read-only rights. For sensitive codebases we work within your own environment (for example via VDI, jump host or dedicated review server). We sign a non-disclosure agreement upfront and process all code under GDPR-compliant terms.
Which SAST tools do you use?
We work with commercial SAST tools such as Semgrep, SonarQube, Snyk Code and Checkmarx, depending on your stack and licenses. We are not tool-agnostic but tool-realistic: no SAST tool finds everything. That is why we always combine tooling with manual verification and filter out false positives before reporting.
Can you issue a Third Party Memorandum (TPM)?
We are not an accountant and do not issue TPMs ourselves. We do deliver the technical evidence your accountant or NOREA-certified IT auditor needs to issue a TPM. Our reporting is deliberately structured for this purpose and we regularly cooperate with the major accounting firms on TPM engagements.
How long does a source code review take?
Duration 2 to 4 weeks for medium-sized codebases (50,000 to 200,000 lines), 4 to 8 weeks for enterprise scopes. Active review time depends on complexity: SAST configuration 1 to 3 days, manual review 3 to 15 days per module, reporting 3 to 5 days.
What do I provide as input?
Access to Git repository or code export, architecture diagrams, API specifications (OpenAPI/Swagger), threat models if available and a brief technical description of your stack. For DigiD engagements also your DigiD normenkader mapping and compliance scope.
Can you integrate SAST into our CI/CD pipeline?
Yes. We can deliver SAST configuration that you can integrate yourself into GitHub Actions, GitLab CI, Azure Pipelines or Jenkins. For structural shift-left security we also provide advice on quality gates, break-build criteria and developer training on SAST output. This is typically a one-off implementation engagement of 2 to 4 weeks.
Does a code review combine well with a pentest?
Yes. For high-assurance engagements (DigiD, financial services, healthcare) the combination is standard. We offer combined engagements with double-mapping of findings to both pentest and code review scope. This delivers efficiency in reporting and more complete audit evidence than either alone.
Ready for certainty about your source code?
Preparing for a DigiD assessment or TPM engagement? Taking over a codebase and want an independent judgment? Want to integrate SAST structurally into your CI/CD pipeline? We start with a complimentary scoping conversation covering your codebase, goal and compliance context. Response within one business day. Quotation within three business days.
Nederlands