Source code analysis: SAST with manual verification
You have already tried SAST tools – but the results were unclear, contradictory or full of false positives? You are required by regulation to carry out a source code analysis but do not know how to set it up correctly? You want to integrate cybersecurity into your development process without jeopardising your time to market?
Source code analysis: finding vulnerabilities in the code, sorting out false positives.
Your situation
You need to provide evidence of a source code analysis or finally want to use SAST with usable results?
The reasons vary. A certification procedure or set of rules requires a source code analysis – such as an evaluation according to Common Criteria, an Accelerated Security Certification (BSZ), BSI TR-03161 for digital health applications or IEC 62443 for industrial systems. Or your team has tried SAST tools, and the results were unclear, contradictory or full of false positives.
If vulnerabilities in the source code are only discovered in production, the result is often expensive hotfixes, release delays, security incidents or problems in the certification procedure. At the same time, security should not jeopardise your time to market.
We combine established SAST tools with the manual validation of all findings. You do not receive tool lists, but verified, prioritised findings with code examples. Your source code stays on our own systems – we do not use cloud services or external servers for this.
As a BSI-recognised evaluation facility, we know the requirements for SAST in evaluations from our own evaluation practice. If your team wants to identify vulnerabilities in code reviews itself, it can learn how in the OWASP Top 10 Advanced workshop.
Services & results
From code analysis to anchoring in the secure development lifecycle
You receive findings from the static analysis (SAST) of your source code, with every automated finding manually checked for relevance. The basic analysis takes around four working days for projects of up to about 50,000 lines of code; your source code stays on systems we operate ourselves. On request, SAST runs continuously in your CI/CD pipeline.
A one-off SAST provides valuable insights but remains a snapshot. That is why we offer three levels: the analysis of a code base, integration into your CI/CD pipeline and governance according to OWASP SAMM. The principles of our penetration tests apply to all of them: confidentiality, disclosed methodology and tools, individually written and quality-assured reports.
01
Defining the depth of analysis: basic or in-depth
In the initial consultation, we clarify objectives, project size and the desired depth. The basic analysis (approx. 4 working days) is a focused analysis for small to medium-sized projects of up to approx. 50,000 lines of code and provides a quick picture of the security situation.
The in-depth analysis comprehensively examines critical code paths manually, assesses vulnerabilities in the context of the overall system and reports positively on the basis of a previously defined test plan. The time budget depends on project size and depth of analysis.
02
Analysing automatically, validating manually
We analyse the source code with our own analysis framework, which combines various SAST tools, without executing the application. In doing so, we assess the structure, logic and data flows in the code – without test data, a special runtime environment or live operation.
Our security experts then validate all findings manually and filter out false positives. The analysis runs on our own systems, not in cloud services or on external servers. We disclose our methodology and the tools used.
03
Report and presentation of results
We write the report individually and in a way that developers and decision-makers can work with. It goes through our quality assurance. In the presentation of results, we answer technical and organisational questions.
Your SAST report
Verified and prioritised vulnerabilities with code examples and specific recommendations – for the in-depth analysis, additionally with positive reporting along the test plan.
04
SAST integration into your CI/CD pipeline
With “SAST Integration”, static code analysis becomes an automated, recurring part of your build and deployment process. We make sure that the results remain manageable and can be prioritised in day-to-day development:
Analysis of your existing CI/CD pipeline
Selection of suitable SAST tools
Integration into build processes and quality gates
Definition of prioritisation rules for findings
Training on interpreting results for development and DevOps teams
Strategies for dealing with false positives
Documentation and knowledge transfer for long-term operation
05
SAST governance: OWASP SAMM assessment
If you want to anchor application security in a structured way for the long term, we follow OWASP SAMM:
Assessment of your SDLC according to OWASP SAMM
Gap analysis between the current state and best practices
Roadmap for SAST integration into your entire development process
Strategy for continuously improving your application security
Our expertise
secuvera has more than two decades of experience in analysing, assessing and certifying software security. As a BSI-recognised evaluation facility, we carry out evaluations in which SAST is a central component: according to Common Criteria, in the Accelerated Security Certification (BSZ), according to BSI TR-03161 for digital health applications and according to IEC 62443 for industrial systems. We are also a BSI-certified IT security service provider for penetration testing.
Our colleague Timo Schäpe described how SAST tools detect security vulnerabilities early in the secure development lifecycle in the iX special “Security Tools” 2025.
For the analysis, we use our own framework with various self-operated tools and support the common programming languages. Our experts know the strengths and limitations of the tools used. They keep their knowledge up to date through training and work in standardisation bodies. secuvera is an OWASP Corporate Member and Silver Sponsor.
Getting started
Assessing your code base and existing SAST results
Choose the right depth of analysis
We offer two analysis approaches – depending on objectives, project size and desired depth. Technology and existing SAST results also inform the choice.
SAST findings assessed, so your team starts in the right places.
Basic analysis or in-depth analysis
Depending on project size and the desired depth of analysis.
01
Basic analysis (approx. 4 working days)
Focused analysis for small to medium-sized projects (up to approx. 50,000 LOC). Quick picture of the security situation (“first impression”). Suitable for an initial assessment or as a basis for further steps.
02
In-depth analysis
Comprehensive manual review of critical code paths. Context-based assessment of vulnerabilities in the overall system. Positive reporting based on a previously defined test plan. Flexible time budgets depending on project size and desired depth of analysis.
Distinguishing source code review from runtime tests
SAST examines the source code without executing the application. Runtime behaviour and third-party components require additional testing methods. The one-off analysis is a snapshot; for recurring tests, we offer support with integration.
Questions about source code analysis and SAST integration
Does our source code leave your systems for the SAST analysis?
According to the secuvera analysis concept, the source code handed over is processed exclusively on our own systems. Cloud services or external servers are not used for this. The source code remains your property; we agree on the method of handover before we start.
How do you deal with false positives from SAST tools?
Automated findings are verified manually and checked for relevance. We present the assessed vulnerabilities with code examples and recommendations. Your team should receive a technically reviewed basis for remediation, not an unfiltered tool list.
Can SAST be integrated permanently into our CI/CD pipeline?
Yes. Integration support covers embedding into build and deployment workflows as well as handling and prioritising the results. For anchoring application security more broadly, we offer an approach based on OWASP SAMM.
Does a source code analysis replace a penetration test?
No. SAST provides one perspective: the static analysis of your own source code. Runtime vulnerabilities are uncovered by DAST (dynamic application security testing), third-party components and open source libraries are checked by SCA (software composition analysis), and manual penetration tests assess real attack possibilities. For production applications, we combine these methods on request.
Do we need SAST for a certification?
In several procedures, source code analysis is a central component, for example in Common Criteria, BSZ, BSI TR-03161 and IEC 62443. For DiGA and DiPA pentests, the guides require code reviews, among other things. We clarify in the initial consultation which requirements apply to your product.