Code Security Review
Code Security Review sodiumcyber@gmail.com February 6, 2020

Sodium Cyber is able to undertake full spectrum code security reviews against all major recognised languages.

"Comprehensive Code Security Review – Strengthening Your Software from the Inside Out."

Our Approach

 

Our code review process provides your business with a comprehensive understanding of your product’s security posture.  This in-depth analysis is conducted by senior security consultants with extensive programming and secure development expertise, ensuring that vulnerabilities are identified and remediated effectively.

Our Methodology

1
Input/Output Data Interfaces

We employ a combination of manual code tracing and automated testing to meticulously analyse application interfaces and scrutinise the sanitisation of input and output data. This approach allows us to identify potential injection vulnerabilities, safeguarding your application from malicious input.

2
Secure Coding Techniques

Our experts delve deeper into your codebase to pinpoint areas susceptible to a wide array of security issues, including format string errors, race conditions, memory leaks, buffer overflows, integer overflows, and command injection points.

3
Transport Security

We conduct a thorough examination of network traffic protection mechanisms, focusing on the proper implementation of PKI and SSL/TLS validation to ensure robust transport security.

4
Cryptography

Our analysis extends to cryptographic implementations, verifying the strength of password generation systems, random number generators, and the correct usage of high-level cryptographic primitives. This helps maintain the confidentiality and integrity of your data.

5
Data Storage

We assess the protection measures in place for sensitive data storage, ensuring compliance with data protection regulations and the appropriate use of operating system or platform storage mechanisms. This includes scrutinising the storage of personally identifiable information (PII) and application-sensitive security tokens or keys.

6
Access Control

Our review encompasses a thorough evaluation of permissions for interfaces, including IPC interfaces, network interfaces requiring authorisation/authentication, and filesystems, ensuring that access control is properly managed.

By partnering with us for your code review needs, you can proactively address security risks, enhance your product’s resilience, and instill confidence in your customers. Our commitment to technical excellence and thoroughness ensures that your codebase is fortified against the ever-evolving threat landscape.

Our Reporting

Upon completion of the code review, we provide you with a comprehensive report that includes:

1
Management Summary

A high-level overview of the findings, highlighting key risks and recommendations.

2
Technical Overview

A detailed technical analysis of the codebase and identified vulnerabilities.

3
Detailed Technical Findings

Specific vulnerabilities, their potential impact, and actionable recommendations for remediation, along with estimated remediation effort.

Services_Main Pages

Our Services

Scroll to Top