Scoping & threat model
2–4 days
We read the documentation and the code before we quote. Together we fix the boundary: which contracts are in scope, which are trusted, and which are explicitly out. Then we enumerate the actors and their privileges, the external dependencies, and the assets at risk — and we write it down. That document is what the review is measured against, and it is the artefact most teams tell us they did not know they needed.
Output
- Scope document at a fixed commit
- Trust-boundary map and actor list
- Assumptions register
- Fixed quote and review plan