Black Shard

Secure code review for Australian software teams.

Line-level review of source, configuration and dependencies, with a fix documented for each finding and a re-review once the fixes land.

Black Shard conducts secure code review of application source, configuration and dependency manifests. The review covers the authentication flow, the authorisation checks on routes that touch data, the query layer, secrets handling, the dependency tree and the deployment configuration. Findings are documented with severity, impact, reproduction steps and a fix, and a re-review of the fixes is included.

Black Shard is an Australian software engineering and cybersecurity firm, headquartered in Brisbane. Code review is delivered remotely against the repositories in scope, with read access and nothing further.

What the review covers

The review reads the source in scope, with attention on the classes of flaw that produce incidents: injection, broken authentication and session handling, authorisation gaps and tenancy boundaries in multi-tenant systems, secrets in code or configuration, and vulnerable or abandoned dependencies.

Tooling informs where to look. A finding is reported once a reviewer has read and confirmed it, and issues with no practical exploit path are left out. Each finding is written with severity, impact and reproduction steps, and carries its fix with the steps to apply it.

  • A defined scope and timeframe in writing before the review starts
  • A findings report with severity, impact and reproduction steps for each issue
  • A fix documented for each finding, with the steps to apply it
  • A re-review of the fixes once they land

Code review and penetration testing

A penetration test exercises the running system and reports what is reachable and exploitable within the engagement window. A code review reads the source and reports what is wrong at the origin, including code behind feature flags, paths a black-box test does not reach, and the deployment pipeline. Authorisation and business-logic flaws are found by reading the code with knowledge of what the software is for.

Where a review finding warrants proof against a live system, that is scoped separately as penetration testing. Both are delivered by Black Shard.

Design-stage review

Review can start before code exists. A design-stage engagement delivers a threat model of the system or feature, an attack-surface and trust-boundary analysis, and specific design changes: a tenancy model enforced in the database, an integration holding only the privilege its job requires, a queue that authenticates its producers.

This is the process applied to Black Shard's own products: threat modelling before implementation, least-privilege architecture, and security review gates through delivery.

When to commission a review

Before launch, while findings are engineering work and no change windows, migration risk or disclosure decisions attach to them.

After an incident, to establish where else the same class of flaw exists and what the attacker had the opportunity to reach.

During due diligence, when acquiring, investing in or selling a software business. The review reports what ships with the codebase: secrets in the commit history, abandoned dependencies, and an authorisation model held together by convention.

Systems we operate

Black Shard builds and operates software in regulated Australian industries. Aurii, clinical software for private-hospital specialists that Black Shard built and operates, runs on Azure with tenant data isolated by PostgreSQL row-level security. GRM LAW, a Brisbane law firm, runs on an operations and compliance portal with an append-only audit ledger enforced on every state change. Stone Leaf Capital operates a staff portal Black Shard built, with a sealed compliance audit log structured around the firm's AFSL perimeter.

Black Shard works against OWASP and ASD guidance and holds SMB1001:2026 Gold, verifiable on the public CyberCert registry. During an engagement we take read access to the repositories in scope and nothing more.

What does a secure code review cost?

Each engagement is scoped and quoted individually. Cost is driven by the size and shape of the codebase, the number of services and repositories in scope, the languages and frameworks in use, and whether design-stage threat modelling is included. The quote comes back with a defined scope and timeframe before any work starts.

The engagement runs one of two ways: a standalone review with a re-review of the fixes included, or an embedded arrangement where review runs continuously across a build.

Questions, answered

How long does a secure code review take?
It depends on the size of the codebase and the number of services in scope. A review of a single service is a shorter exercise than a whole-platform review. The timeframe is set at scoping and is in writing before work starts.
Do you need access to our production environment?
No. A code review runs against the source, its configuration and its dependency manifests. We ask for read access to the repositories in scope and nothing beyond that. If a finding warrants proof against a running system, that is scoped separately as penetration testing.
What stacks do you review?
The ones we ship: web applications and APIs, native iOS and Android, and Azure infrastructure and deployment pipelines, across the languages those stacks are built in. If your stack sits outside that, name it in the brief and we will tell you whether we are the right reviewers.
Is this just a static analysis scan with a report attached?
No. Tooling informs where we look. Every finding in the report has been read and confirmed by a reviewer, and a finding without a fix attached is not reported.
What happens after we fix the findings?
A re-review is part of the engagement. Once your team has applied the fixes, we read them and confirm each closes the issue it was written for without introducing another.
What does the report look like?
Each finding is ranked by severity and written with impact, reproduction steps, and a fix with the steps to apply it. It is a document engineers can work from directly.
Are you only in Brisbane?
No. Black Shard is an Australian firm headquartered in Brisbane, and code review is delivered remotely. The artefact under review is the repository, and the findings carry reproduction steps your engineers can act on wherever they sit.

Scope a secure code review with Black Shard.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au