Secure code review & application security
Secure code review is an application-security assessment where senior engineers read your source — authentication, input handling, access control, secrets and dependencies — to find the flaws that put your product and your customers' data at risk. NorthSight Technologies reviews the code and builds the remediation. This is product security, not network scanning: we complement your MSSP, we don't replace it. Start with a free introductory call.
- We review the code — auth/authz, injection, secrets, dependencies, access control, data residency — and build the fix.
- Application security, not network security: we read the source and write the remediation plan, we don't run firewall or perimeter scans.
- Built for Canadian SaaS vendors that must pass HECVAT, SOC 2, PIPEDA/PHIPA and Quebec Law 25 reviews to sell into regulated buyers.
- You get a findings report with severity, a remediation plan, and a retest — start with a free 20-minute call.
What a secure code review covers
"Security" is a broad word. Ours is a hands-on review of the application you built, across six concrete lenses:
- Authentication & authorization. How you prove who a user is and what they're allowed to do: session handling, token validation, password and MFA flows, and privilege checks that actually run on the server rather than just hiding a button in the UI.
- Input handling & injection. Where untrusted input meets your database, shell, templates or downstream APIs — SQL and command injection, cross-site scripting, SSRF and unsafe deserialization.
- Secrets & data handling. Where credentials, keys and personal data live and travel: hard-coded secrets, over-broad logging, unencrypted storage, and data that leaks through caches or error messages.
- Dependencies & supply chain. The third-party packages you ship: known-vulnerable versions, unmaintained libraries, and build-pipeline weak points that let bad code in.
- Access control. Broken object-level and function-level authorization — the most common way one tenant or user reaches another's data. We trace real request paths, not just the happy path.
- Data residency. Where your data physically sits and crosses borders, so a Canadian buyer's residency requirement is something you can answer with evidence, not a guess.
Application security vs network security
These get lumped together, and they shouldn't be. Network security protects the perimeter and infrastructure — firewalls, endpoint protection, intrusion detection, a managed SOC watching traffic. That is the domain of a network provider or MSSP, and it matters. Application security is a different question: is the software you wrote safe? A firewall can't fix a broken permission check or a SQL-injection hole in your own code.
NorthSight lives entirely on the application side. We read the code and write the remediation plan — we do not run network scans, tune firewalls, sell antivirus, or operate a managed SOC. If you already have an MSSP, we slot in alongside them: they secure the environment your product runs in, we secure the product. If you don't, a code review is still the right place to start, because most breaches that hurt SaaS vendors come from application flaws, not an unpatched router.
Compliance & selling to regulated buyers
This is where a code review earns its keep. Canadian SaaS vendors that sell into higher education, healthcare and government keep hitting the same wall: the buyer's security team sends a HECVAT questionnaire or runs a SOC 2 vendor assessment, and the deal stalls until the answers are credible. We help you get there:
- HECVAT & SOC 2 vendor assessments. We review the application against what these questionnaires actually probe, close the real gaps, and help you answer honestly instead of aspirationally. We are not the auditor who issues your SOC 2 report — we are the engineers who make the answers true.
- PIPEDA, PHIPA & Quebec Law 25. How personal and health information is collected, stored, logged and shared, mapped to the Canadian privacy rules your buyers are bound by.
- Protected-B handling. For public-sector buyers, the data-handling and residency posture that Canadian government work expects.
- AODA. Accessibility obligations that increasingly show up in the same procurement checklist.
A recent example of the shape of this work: a health-and-education SaaS vendor selling to Canadian colleges needed to complete a HECVAT and pass a code review before their contract could close. That is exactly the situation we're built for — senior engineers who both find the issues and fix them, so the assessment stops being a blocker.
What you receive
- A findings report — each issue with a severity rating, a plain-language explanation of the risk, and the specific location in the code, readable by both engineers and leadership.
- A remediation plan — ordered by severity and effort, each item scoped so you can act on it with us or with your own team.
- A retest — once fixes land, we verify the issues are actually closed, so you can stand behind your answers to a buyer's security team.
Most clients have us build the remediation too: the same senior engineers who found the issue write the fix. But the report stands on its own if you'd rather remediate in-house.
Why NorthSight
Principal-led delivery by co-founders Kamran Khalil and Muhammad Irfan — not a report handed off to juniors. Between us, 28+ years of combined engineering across government, enterprise and consumer software, 9M+ downloads shipped, a Macworld "Best of Show", and a 5.0-star client rating. We're a Canadian firm, so your data stays in Canada. Start with a free 20-minute call — a low-risk way for both sides to see whether a deeper engagement makes sense.
Frequently asked questions
Secure code review vs penetration testing — what's the difference?
A penetration test probes a running system from the outside to find exploitable holes. A secure code review reads the source — auth logic, input handling, access control, secrets and dependencies — to find the flaws that cause those holes, including ones a black-box test would miss. The two are complementary; a code review tells you why something is exploitable and exactly where to fix it. We review the code and can build the remediation with you.
Can you help us pass a HECVAT or SOC 2 vendor security review?
Yes — this is a core reason clients come to us. We help Canadian SaaS vendors selling into regulated buyers (higher-ed, healthcare, government) get their application in shape for a HECVAT questionnaire or SOC 2 vendor assessment: reviewing the code, closing the findings a buyer's security team will ask about, and documenting data handling and residency. We are not an auditor issuing the SOC 2 report; we are the engineers who make the answers true.
Do you fix the issues or just report them?
Both, and the fix is the point. Every engagement produces a findings report with severity and a prioritized remediation plan. From there most clients have us build the remediation — the same senior engineers who found the issue write the fix and re-test it — rather than hand a report to a team that has to decode it. The report stands on its own if you prefer to remediate in-house.
Is this network security, firewalls or managed SOC/MSSP work?
No. We do application and product security: we read your code and build the fix. We do not run network scans, manage firewalls, sell antivirus, or operate a managed SOC. That work belongs to a network security provider or MSSP, and we complement them rather than compete — they secure the perimeter and infrastructure; we secure the software you built.
How much does a secure code review cost?
Reviews are scoped as paid engagements based on codebase size, language and access requirements. Your first 20-minute call is free — we use it to understand what triggered the review (often a buyer's security questionnaire) and outline how we'd approach it. Email hello@northsight.ca to start.