Service Details

Working software is not always secure software

An application can function as expected while still containing weaknesses within its source code. These vulnerabilities may remain hidden until they are discovered during a security review, customer procurement exercise or, in the worst case, after they have been exploited. 
 
The challenge becomes greater when an organisation depends on software developed or maintained by a third-party supplier. Buyers and beneficiaries may have limited visibility into the security of the underlying code, while software vendors must increasingly demonstrate that application security is taken seriously. 
 
The Escrow Company’s Static Application Security Testing service analyses source code from web and mobile applications to identify and report potential security vulnerabilities. This gives depositors and beneficiaries a clearer picture and enables the relevant development team to investigate and remedy identified issues. 
 

Service Details

What are the benefits of conducting a SAST

Find potential weaknesses before they become bigger problems.
 
Static Application Security Testing provides greater visibility into security issues contained within source code, supporting better-informed conversations between software vendors and buyers. 

  • Support Earlier Remediation: Give developers clear findings they can investigate and address before vulnerabilities create greater security, operational or commercial exposure.
  • Strengthen Software Escrow Assurance: Go beyond confirming that source code has been deposited by gaining additional insight into potential security issues contained within it.
  • Improve Supplier Transparency: Provide beneficiaries and software buyers with greater visibility into the security of important third-party applications.
  • Demonstrate Security Commitment: Help software vendors show customers, procurement teams and other stakeholders that source-code security is being independently assessed.
  • Scale with Your Software Estate: Assess up to 10 code repositories as standard, with the flexibility to extend coverage in additional blocks of 10. 
     
smiling software developer looking into the camera, bright blue background, concept: Skilled workers, shortage of skilled workers, recruiting

Independent security analysis for application source code

icon

Web Applications

Analyse the source code underpinning browser-based software and online services.

icon

Mobile Applications

Assess source code used within mobile applications for potential security vulnerabilities.

icon

Detailed Findings

Developers receive a detailed report documenting the potential vulnerabilities identified during the assessment.

icon

Shared Assurance

The final report is provided to both the software depositor and the escrow beneficiary, supporting transparency and collaborative remediation.

casual business woman working on desktop computer
Service Details

When to Use SAST

Add security insight at the moments it matters most. 
 
Static Application Security Testing can support organisations whenever greater assurance is required around the security of application source code, including: 

  • As part of a Software Escrow or SaaS Escrow arrangement
  • When reviewing a new or business-critical software supplier
  • During technology procurement and supplier due diligence
  • When enterprise customers request additional security assurance
  • Before a major application release or significant software update
  • When software has been developed by an external or subcontracted team
  • During technology M&A or investment due diligence 

SAST provides evidence that potential source-code vulnerabilities have been independently assessed, helping stakeholders make decisions with greater visibility. 

Service Details

SASTs Give development teams clearer findings to act upon

Identifying a potential vulnerability is the first step towards addressing it. Following the assessment, The Escrow Company produces a detailed report covering the findings identified within the analysed source code. 
 
The report is shared with both the depositor and beneficiary. This creates a common evidence base for discussing the findings and enabling the relevant software-development team to investigate and remedy potential vulnerabilities. 
 
The Escrow Company identifies and reports the findings; remediation remains the responsibility of the software owner or its appointed development team. 

Smiling business people, colleagues, executives in suits at meeting. Teamwork, partnership, discussion, using laptop in modern office. Happy, positive atmosphere, corporate environment, success.
Get a Quote

Yes! I want a free SAST quote

  • Support organisations whenever greater assurance is required around the security of application source code
  • Provides evidence that potential source-code vulnerabilities have been independently assessed
  • Global service with offices in London (HQ) UK, Atlanta, USA, and Sydney, Australia.​
Name
Needs to be in international format, please include + country code