Skip to content
LENDAGO

Audit

Code and security audit

A written assessment of your application: what risks exist, what remediation takes, and where it is worth starting.

When an audit is worth doing

An audit is useful at the moments when an expensive decision is coming and you need an objective basis for it.

  • You are taking an application over from another team and want to know what you are buying
  • A large investment into an existing platform is about to start
  • You have had a security incident or suspect unauthorised access
  • You are acquiring a company and want a technical assessment of its product
  • You want to know why development has become slower and slower

What we examine

The audit covers both the security side and the side that determines what development will cost you from here on.

  • Authentication, sessions, permissions and data separation between users
  • Common vulnerabilities: database injection, code execution from user input, file uploads, form protection
  • How passwords and sensitive data are stored
  • Dependencies on vulnerable or unsupported versions
  • The structure of the code and the areas where any change becomes risky
  • The database: consistency, indexes, queries that will become problems at volume
  • Backups, and whether they can actually be restored

What you receive at the end

A document a non-technical person in management can read, with a detailed technical section for whoever will carry out the repairs.

The findings are ordered by real risk rather than by how dramatic they sound, and each one carries an effort estimate. The document is yours and you can take it to any team, including one other than ours.

Frequently asked questions

What people ask us about code audit

If your question is not here, write to us — we answer just as directly.

Ask us a question
Does the audit include penetration testing?

A standard audit is an analysis of the code, the configuration and the database. Active penetration testing is a separate engagement, carried out only with the owner's written consent and within an agreed window.

Do I have to give you the source code?

Yes, otherwise the assessment stays superficial. We sign a confidentiality agreement first and work on a copy, without access to your customers' real data.

Do you fix what you find?

We can, but it is not required. Many companies use the audit to direct their own team. The document is written to be useful no matter who does the repairs.

From practice

A project where we did this

The situation it started from, the decisions taken along the way, and how the work looks now.

See all case studies

Tell us what you need built or fixed

We answer with the right questions and a concrete first step, not with a generic pitch.