SOFTWARE & EXTENSION REVIEWS

Approve code you did not write.

When someone requests an extension, package, repository, or source archive, turn the code into prioritized evidence and a deployment decision your team can explain.

SIMPLIFIED FICTIONAL SOFTWARE REPORT

See how source evidence becomes a decision.

This abbreviated example shows the report structure and omits parts of the complete interactive experience.

Simplified fictional software report

Northstar Extension

Browser extension · Source review · Completed today

AssessmentAcceptableGRADE B
Overall gradeBReview material findings
Risk score12.4out of 100
LicenseAllowedAttribution required
Total findings91 high, 3 medium, 5 low
Findings by severity9 total
Critical0
High1
Medium3
Low5
Top risk driversPrioritized
src/background/messages.jsHIGH

Message origin validation should be restricted before broad deployment.

manifest.jsonMEDIUM

Requested host permissions are broader than the stated business workflow.

01 / ACCEPTED EVIDENCE

Meet the request
where it starts.

Use the source format you actually have. Direct private-repository connections are not currently supported.

PUBLIC SOURCE

Public repositories

Review a public repository and its release, dependency, workflow, licensing, and source context.

PACKAGED SOFTWARE

Extensions and NPM packages

Evaluate permissions, install behavior, provenance, dependencies, and code signals in packaged software.

AUTHORIZED UPLOAD

ZIP source archives

Upload source you are legally authorized to submit when a public repository is not available.

02 / EXACT WORKFLOW

From request to a documented call.

The system organizes code evidence. Your team applies business context and owns the final approval.

01

Submit the software

Provide a public repository, extension, package, or authorized source archive.

02

Analyze the evidence

Review provenance, install behavior, permissions, vulnerabilities, risk patterns, and licensing.

03

Inspect the findings

Use prioritized, evidence-linked findings and explicit uncertainty to focus human review.

04

Record the decision

Share a link to the web report or export it as HTML or PDF, then document why the software was approved, limited, or rejected.

03 / REPORT OUTPUT

A report built for the deployment decision.

Development scanners produce finding feeds for software your team owns. CIRT produces decision support for software someone else wants to introduce into your environment.

Findings remain informational indicators. They can contain false positives, false negatives, incomplete analysis, or misinterpretations and should be reviewed by a qualified person.

DEPLOYMENT DECISION REPORTSHAREABLE
  • Overall grade and risk scorePrioritized
  • Evidence-linked findingsCritical to Low
  • Top risk driversAction focused
  • License statusBusiness use
  • Executive summaryWeb + HTML + PDF
04 / COMMON OBJECTIONS

Know the limits
before you approve.

CIRT states the boundaries of automated analysis and does not ask you to retain source indefinitely.

RETENTION

Source files are discarded

Code files are not retained after processing. Cryptographic file hashes and underlying file-level results are retained indefinitely by default, including after the code review assessment is deleted. For a sensitive codebase, an option available during the initial scan can delete the stored hashes and results created for unique files first seen in that repository after report generation. This option is generally not recommended because it reduces retained analysis history and reuse. Each result is primarily a generated summary of the file's purpose and its associated security findings; rare circumstances may include a small code snippet. It cannot identify or reconstruct the submitted source file.

PRIVATE REPOSITORIES

No direct connection yet

Repository scanning is designed primarily for open source. An authorized ZIP can be used when you have the right to submit the code.

HUMAN REVIEW

The final call stays with you

CIRT is decision support, not a guarantee, certification, professional engagement, or transfer of liability.

05 / RELEVANT PRICING

Start at $50/month.

BYOK Starter includes a seven-day trial, 10 code assessments, 2 vendor reviews, and an observed early-access Anthropic average of less than $2 per code assessment.

MANUAL-REVIEW COMPARISONIf one review takes four staff-hours, $99 Starter breaks even at a loaded rate of $24.75/hour.
Compare every plan

The labor example is illustrative. Actual provider spend, review time, and organizational savings vary.

Review the next request with evidence.

Start with a repository, extension, package, or authorized source archive.

Start your first review