Skip to main content

Application security methodology

How LAN10 AppSec Review analyses your application code

LAN10 AppSec Review examines application source code at an exact commit, combines two independent AI security reviews, consolidates overlapping findings deterministically and requires human assessment before the final report is approved.

  1. Agree scope and pin the commit

    You provide the repository and a branch, tag or commit. After the scope is agreed, the selected reference is resolved to one exact commit SHA and recorded with the review.

  2. Run two independent reviews

    Two AI security reviewers analyse the same source code at the same commit. Neither reviewer receives the other reviewer's prompts, output or conclusions.

  3. Consolidate and assess the findings

    Deterministic rules consolidate overlapping candidate findings and retain both reviewers' original material. A human reviewer assesses every candidate, confirms or dismisses it, sets final severity and records the rationale.

  4. Approve and deliver the report

    The report is approved only after every candidate finding has a human decision. It records the reviewed commit, confirmed findings, evidence, remediation guidance, provenance, coverage and limitations.

What the review preserves

In the report

  • Prioritised findings
  • Evidence and source location
  • Final severity and rationale
  • Remediation guidance
  • Finding provenance
  • Scope, coverage and limitations

In the process

  • Exact-commit scope
  • Independent reviewer inputs
  • Deterministic consolidation
  • Original reviewer findings retained
  • Human decision on every candidate
  • Recorded coverage and limitations

Technical detail

Current review scope

LAN10 AppSec Review works from application source code at an exact commit. As part of the review, Codex Security may execute code inside the ephemeral run container when validating candidate findings. This execution remains within the review environment and does not deploy to, send traffic to, or test the customer’s running application.

The current independent review streams use OpenAI Codex Security and Anthropic Claude. Read more about provider processing and source handling on the Confidentiality page.