Managed Code Review
Most static analysis deployments die at the first scan, when the tool reports ten thousand issues and the development team stops reading. We take the delivery half: wire the scan into the pipeline, tune the rule set to the stack, and triage the output so only findings worth a developer's time arrive — with the fix written next to them.
$1,425USDper repository
List $1,900 — what your customer pays. You keep the difference. · 25% off list
- Priced by
- per repository
- Delivered as
- Your brand, your template
- Client access
- Scoped, granted by your customer
Scoped before you quote, not after you have sold it
Scanning is wired into the pipeline the customer already uses — GitHub Actions, GitLab CI, Azure DevOps or Jenkins — so a merge request gets a verdict instead of a monthly PDF.
Rule sets are tuned per language and framework, and rules the team will never act on are switched off rather than left there to be ignored.
Every reported finding is triaged by an engineer with the exploitability call written down: reachable, not reachable, or needs a decision from you.
Dependency findings and leaked secrets are separated from code findings, because they have different owners, different urgency and different fixes.
Fix guidance is written against the actual code path in the repository, not a link to a CWE definition page.
Runs inside the SonarQube instance or equivalent the customer already licences, so the findings history stays in their tooling and survives us leaving.
You quote it, we operate it, you deliver it
Your price is the published list price minus 25%, on every line in the catalogue. You decide what your customer pays and keep the difference, so your margin is settled before the quotation leaves your office.
Our engineers work it from Bangkok on UTC+7, against a methodology that is written down rather than improvised per customer. A senior engineer reads every finding before it leaves the building, because you are the one who has to defend it.
Findings, reports and escalations reach you in your template with your logo on them. Your customer talks to you, and our name is not on the ticket.
What a partner checks before putting this on their price list
Do we have to give you the customer's source code?
Usually not, because the preferred setup runs the scan inside the customer's own pipeline and we work from the findings and the affected snippets. Where a deeper review genuinely needs repository access, it is granted by you, scoped to specific repositories and time-limited.
Which languages do you cover?
The stacks we work in day to day: Java, C#, JavaScript and TypeScript, Python, PHP, Go, and mobile in Kotlin and Swift. If a customer's stack is outside that, we tell you before you sell it rather than after.
Is this the same as a penetration test?
No — code review finds the flaw in the source before it ships, while a penetration test proves what is exploitable in what already shipped. For a software customer they sit at different points of the release cycle and are usually sold as two lines.
What if the customer has no CI pipeline at all?
The first of the work goes into building enough of a pipeline to run a scan on every merge, scoped openly rather than pretending the tool will slot into nothing. It is the part that decides whether the rest of the engagement is worth anything.
Who owns the SonarQube licence?
Your customer or you — we do not need to own it and we do not resell it as part of this. We work inside whichever instance you point us at, and the finding history stays there.
How is it billed?
Per repository, at the rate on the price list. Wiring the pipeline and tuning the rule set are inside that rate; a customer with several repositories is several units, so count them before you quote.
Pick one customer. We will run it for 60 days.
Choose a customer you already serve. We deliver Managed Exposure on their domain for two months, in your template, at no cost — so you can see exactly what your customer would receive before you sign anything.
Apply as a partner