A senior review of your code, in plain English.
We run Locrin, our open-source checker, across your repository. Then a senior engineer reads every finding and the code that carries the most risk. You get a short report that says what matters, what is noise, and what to fix first.
- Fixed scope and price agreed before we start
- NDA before access, read-only
- Built on Locrin, free and open source
Safe to ship after three fixes.
- High1
- Medium2
- Low4
Your database admin key is reachable from the browser
The Supabase service-role key is read in a file that ends up in the code sent to users' browsers. It ignores every row-level security rule, so anyone who loads that page could read or change any row, including other customers' data. Rotate the key today and move these queries to a server-only route.
- createClient(url, SERVICE_ROLE_KEY)+ createClient(url, ANON_KEY)
Checked by Locrin · Read by RAS
Illustrative example, not from a client's code
- 21 rules, 10 of them for security
- No AI model in the engine
- Free and MIT licensed
- We run it on FastLift
01 / What you get
Your database admin key is reachable from the browser
The Supabase service-role key is read in a file that ends up in the code sent to users' browsers. It ignores every row-level security rule, so anyone who loads that page could read or change any row, including other customers' data. Rotate the key today and move these queries to a server-only route.
- createClient(url, SERVICE_ROLE_KEY)+ createClient(url, ANON_KEY)
Illustrative example, not from a client's code
Found by Locrin
Every file in scope goes through the same engine checks, the same way every time.
Read by a senior engineer
An engineer confirms or rejects each finding, removes the noise, and says what it means for your business.
The fix
What to do, where, and roughly how long it takes, in priority order.
Verified by the re-check
After you fix, we run the engine checks again. Full review and above also get a senior re-read.
Not a penetration test · No live systems touched · No certification
02 / What we check
Every file in scope goes through the same engine checks. A senior engineer then reads the parts no rule can judge.
Leaked keys and passwords
Credentials committed to source, private keys, and database admin keys reachable from browser code.
Known vulnerable packages
Dependencies with published security advisories, with the version that fixes each one.
Risky patterns
Weak cryptography and unsanitised HTML reaching the page.
Access gaps in common stacks
Supabase tables without row-level security, Express routes without authentication, wildcard CORS on signed-in routes, and cookies missing secure flags.
Code that rots
Debug lines, blocks of commented-out code, leftover TODO markers, unused imports, unreachable code, and exports nothing uses.
Tests that do not test
Test cases with no assertions, and tests a recent change switched off.
These engine checks cover TypeScript and JavaScript in depth. PHP and Python get a lighter pass: five of the 21 rules run on PHP and four on Python, and the senior review reads the rest.
The human read
Sign-in and permissions, payments, data access, error handling and configuration, time-boxed to the areas that carry the most risk.
What we do not check
Live websites, servers or cloud accounts; penetration testing; performance and load; accessibility (a separate review, coming later); secrets in your git history, because the engine reads the working tree; languages outside the agreed scope. The report lists exactly what was covered.
Not the right fit
Not the right fit if you need a CREST penetration test, a Cyber Essentials certificate or a test of live systems, or if your code is mainly Java, C#, Go, Swift or Kotlin. We will tell you if that is the case.
03 / How it works
Tell us about the code
Stack, rough size, deadline and what prompted the review. We reply within one working day with a fixed scope and price.
Paperwork first
We sign an NDA, you confirm in writing that we may review the code, and you give us read-only access to one repository.
Engine pass
Locrin checks every file in scope and your dependency lockfiles, the same way every time.
Senior review
An engineer confirms or rejects each finding, removes noise, and reads the high-risk areas by hand.
Report and walkthrough
A plain-English report and a call to go through it. After you fix, we run the engine checks again.
Then we delete your code
Our copy is deleted within 14 days of delivery and we confirm it in writing.
04 / Code or running site?
Your code
- Locrin plus a senior engineer
- Read-only access to one repository
- No live systems touched
- Fixed scope and price agreed before we start
Not a penetration test
Your running staging site
- autoSecurity, our invite-only scanner for staging sites
- Authorised, staging-only, never production
- A different service with a different scope
- Or a CREST penetration testing firm if you need one
05 / Packages
Pick a starting point.
Snapshot
A fast, honest first look.
£395 + VAT
3 working days
- Engine run on your repository and lockfiles
- Up to half a day of senior triage
- Your top 10 findings in plain English
- Dependency advisories and a coverage statement
- A 30-minute call
- An engine re-run after you fix
Full review
Everything in Snapshot, plus a senior read of the risky areas.
£1,750 + VAT
7 to 10 working days
- Every finding triaged, and the noise removed
- Sign-in, permissions, payments and data access read by hand
- An owner summary and a prioritised fix list
- Your Locrin setup, tuned to your repository
- A 60-minute walkthrough and a re-run after you fix
Review plus fix support
We review it, then help fix it.
From £3,000 + VAT
agreed per repository
- Everything in Full review
- Fixes as pull requests you review and merge
- Locrin wired into your pull requests
- A re-run and an updated report
- Fix days billed at £600 per fix day
If you upgrade from a Snapshot within 30 days, we credit the Snapshot fee.
Monthly re-check
Code changes every week, and new security advisories keep appearing for packages you already use, even when your code has not changed. Each month we run the same checks on your main branch with fresh advisory data, compare the results with the baseline we agreed, and send a short note: what is new, what matters, what to do.
If something blocking appears, we tell you within 2 working days. Cancel any month.
The checks can run inside your own GitHub, so your code does not have to leave it.
£99 a month + VAT
Add the monthly re-check- Oct · Review7 open
- Nov · Re-check2 open1 new
- Dec · Re-check0 open
06 / Why trust the review
- The engine is Locrin: free, open source and MIT licensed. You can run what we run, and you keep it afterwards, set up for your repository.
- Rules are checked against real repositories before a rule ships, and a rule that misses our precision bar ships switched off.
- No AI model in the engine, so the same change gets the same verdict every time.
- We use it ourselves: our FastLift app runs Locrin on its pull requests.
Rahat Ali Shah
Senior engineer, signs every report
Senior engineer at Raxbi. Builds and reviews the studio's own products, including FastLift on iOS and Android, and reads every finding in every review himself.
07 / Questions
Good to know
The honest answers first: what this is, what it is not, and how your code is handled.
Ask a question firstIs this a penetration test?
No. We review source code. We do not test running systems, websites, networks or cloud accounts, and we never try to break in. If a customer contract asks for a penetration test, we will say so and suggest an accredited testing firm.
Can you guarantee our code is secure?
No one honestly can. A review lowers risk by finding problems visible in the code in scope, at the commit we reviewed. The report says exactly what we covered and what we did not.
Which languages and stacks do you cover?
Our engine covers TypeScript and JavaScript in depth, including projects built with React, Next.js, Node, Express, React Native and Supabase. PHP and Python get a lighter engine pass (leaked keys, leftover debug calls, TODO markers, commented-out code on PHP, and known vulnerable packages), and the senior review reads the rest. For anything else, ask us first.
Locrin is free. What am I paying for?
A senior engineer's time and judgement. Locrin tells you what matched a rule. We tell you which findings are real, what they mean for your business and what to fix first, and we read what no rule can judge, such as how sign-in and permissions really work. You keep the free tool afterwards, set up for your repository.
How do you handle our code?
NDA before access, read-only access to one repository, work on an encrypted machine Raxbi controls, never shared, and deleted within 14 days of delivery with written confirmation. Locrin sends only package names and versions to the public OSV advisory database, never your code.
Do you put our code into AI tools?
Locrin has no AI model in it. We do not upload your code to AI services.
How long does it take, and what do you need from us?
A Snapshot takes 3 working days and a Full review 7 to 10 working days, counted from when we have access. We need read-only repository access, a signed NDA, written confirmation that we may review the code, and a 30-minute kickoff call.
Can you fix what you find?
Yes. Choose Review plus fix support, or book fix days after any review. Fixes arrive as pull requests on a branch, so your team reviews and merges them and stays in control of what ships.
Know what to fix first.
Tell us your stack, rough size and deadline. We reply within one working day with a fixed scope and price.
NDA before access. Read-only. Deleted after delivery.
Or ask a question first: [email protected]