Security, confidentiality, and rigor at the core of every review.
Granting source code access takes trust. Here is concretely how Validra handles your access, your code, and your data.
NDA before any access
Signed before looking at a single line of code. Your trade secrets, API keys, and data models stay confidential.
Strict Read-Only
Never any write, push, or production deployment rights. Your live systems remain under your sole administrative control.
Deleted within 30 days
Code copies, temporary credentials, and test artifacts deleted no later than 30 days after the engagement ends.
Shareable summary
An engagement summary (scope, method, findings, status) to attach to customer security questionnaires. Not a certification.
A method aligned with public security frameworks
Validra relies on public, well-known frameworks so your findings are easy to understand and pass on to a security or compliance team.
OWASP Top 10:2025
The OWASP categories relevant to the scope, with priority on Broken Access Control, Injection, and Security Misconfiguration.
OWASP WSTG v4.2
Web Security Testing Guide applied to modern session management, Server Actions, authentication flows, and API endpoints.
Severity + certainty
Every finding gets two ratings: its severity, based on the real business impact, and its level of certainty (observation, weakness, or demonstrated vulnerability).
Compliance, Vendor Assessments & Access FAQ
How does Validra protect our intellectual property and source code?+
Every engagement starts with a signed Non-Disclosure Agreement (NDA), before any access to your code. Your source code is never published, resold, or shared with third parties beyond what the engagement strictly requires.
What level of access is required to perform the review?+
Read-only access only. We never request push, merge, write, or administrator privileges on production systems. Code review needs read-only repository access; testing of the running app is done against staging or dedicated test accounts.
What is your data retention policy after the audit?+
Access and technical data shared during the engagement (code copies, temporary credentials, test artifacts) are deleted no later than 30 days after the engagement ends, unless you ask otherwise. This is the commitment in our privacy policy.
Can the Validra report be used for a customer security questionnaire?+
It can help. Many vendor questionnaires (VSAQ, CAIQ, SIG) ask whether the application has had a recent security review. The report includes a shareable engagement summary (dates, tested scope, OWASP-aligned method, fix status). It is an external review, independent from your team, but not a certification (like SOC 2 or ISO 27001): each customer decides what they accept as evidence.
Who actually performs the security review?+
Every review is performed personally by Téo Brondel, founder of Validra and a full-stack developer who builds his own SaaS products. Engagements are never outsourced.
Need an NDA or scope confirmation before starting?
Submit your project details with total confidence. A standard bilateral NDA is executed before any code review starts.