Application security methodology
How LAN10 AppSec Review analyses your application code
LAN10 AppSec Review examines application source code at an exact commit, combines two independent AI security reviews, consolidates overlapping findings deterministically and requires human assessment before the final report is approved.
Agree scope and pin the commit
You provide the repository and a branch, tag or commit. After the scope is agreed, the selected reference is resolved to one exact commit SHA and recorded with the review.
Run two independent reviews
Two AI security reviewers analyse the same source code at the same commit. Neither reviewer receives the other reviewer's prompts, output or conclusions.
Consolidate and assess the findings
Deterministic rules consolidate overlapping candidate findings and retain both reviewers' original material. A human reviewer assesses every candidate, confirms or dismisses it, sets final severity and records the rationale.
Approve and deliver the report
The report is approved only after every candidate finding has a human decision. It records the reviewed commit, confirmed findings, evidence, remediation guidance, provenance, coverage and limitations.
What the review preserves
In the report
- Prioritised findings
- Evidence and source location
- Final severity and rationale
- Remediation guidance
- Finding provenance
- Scope, coverage and limitations
In the process
- Exact-commit scope
- Independent reviewer inputs
- Deterministic consolidation
- Original reviewer findings retained
- Human decision on every candidate
- Recorded coverage and limitations
Technical detail
Current review scope
LAN10 AppSec Review works from application source code at an exact commit. As part of the review, Codex Security may execute code inside the ephemeral run container when validating candidate findings. This execution remains within the review environment and does not deploy to, send traffic to, or test the customer’s running application.
The current independent review streams use OpenAI Codex Security and Anthropic Claude. Read more about provider processing and source handling on the Confidentiality page.