Codebase Audit Report
One-off, per repository snapshot
- Code
- Code review lanes over the whole tree, graded against the repository that contains each finding.
- Architecture
- Dependency cycles, drift and structural metrics judged against the code, not against a diagram somebody drew. Custom rules.
- Security
- Secrets (gitleaks), SAST (Semgrep), IaC misconfiguration (Trivy), GitHub workflow security (zizmor), container and Kubernetes hardening, SBOM and licences.
- Dependencies
- Advisories across eight ecosystems, transitive through lockfiles, with EPSS. Packages we could not assess are named, not counted clean.
- Report
- Exported as PDF.
Optional compliance readiness section. 126 SOC 2 and ISO/IEC 27001:2022 controls, a gap plan, and a score over the controls actually assessed. Readiness, not certification.
Leaves out DAST, pentesting and API testing. Codebase grading is JavaScript and TypeScript only; other languages get the scanners, ungraded.