Validra
Trust & Compliance

Security, confidentiality, and rigor at the core of every review.

Granting source code access takes trust. Here is concretely how Validra handles your access, your code, and your data.

NDA before any access

Signed before looking at a single line of code. Your trade secrets, API keys, and data models stay confidential.

Strict Read-Only

Never any write, push, or production deployment rights. Your live systems remain under your sole administrative control.

Deleted within 30 days

Code copies, temporary credentials, and test artifacts deleted no later than 30 days after the engagement ends.

Shareable summary

An engagement summary (scope, method, findings, status) to attach to customer security questionnaires. Not a certification.

Testing Standards & Frameworks

A method aligned with public security frameworks

Validra relies on public, well-known frameworks so your findings are easy to understand and pass on to a security or compliance team.

01 / OWASP Top 10

OWASP Top 10:2025

The OWASP categories relevant to the scope, with priority on Broken Access Control, Injection, and Security Misconfiguration.

02 / WSTG

OWASP WSTG v4.2

Web Security Testing Guide applied to modern session management, Server Actions, authentication flows, and API endpoints.

03 / Rating

Severity + certainty

Every finding gets two ratings: its severity, based on the real business impact, and its level of certainty (observation, weakness, or demonstrated vulnerability).

Procurement & Trust FAQ

Compliance, Vendor Assessments & Access FAQ

How does Validra protect our intellectual property and source code?+

Every engagement starts with a signed Non-Disclosure Agreement (NDA), before any access to your code. Your source code is never published, resold, or shared with third parties beyond what the engagement strictly requires.

What level of access is required to perform the review?+

Read-only access only. We never request push, merge, write, or administrator privileges on production systems. Code review needs read-only repository access; testing of the running app is done against staging or dedicated test accounts.

What is your data retention policy after the audit?+

Access and technical data shared during the engagement (code copies, temporary credentials, test artifacts) are deleted no later than 30 days after the engagement ends, unless you ask otherwise. This is the commitment in our privacy policy.

Can the Validra report be used for a customer security questionnaire?+

It can help. Many vendor questionnaires (VSAQ, CAIQ, SIG) ask whether the application has had a recent security review. The report includes a shareable engagement summary (dates, tested scope, OWASP-aligned method, fix status). It is an external review, independent from your team, but not a certification (like SOC 2 or ISO 27001): each customer decides what they accept as evidence.

Who actually performs the security review?+

Every review is performed personally by Téo Brondel, founder of Validra and a full-stack developer who builds his own SaaS products. Engagements are never outsourced.

Need an NDA or scope confirmation before starting?

Submit your project details with total confidence. A standard bilateral NDA is executed before any code review starts.