We are a 4-person dev team in France building custom warehouse management software for small logistics firms. Our app has been live for two years, and around 30 active clients handle critical inventory data on it. Last week, one of our clients requested a security audit report on our source code as part of a corporate insurance requirement.
There are countless code analysis tools on the market; some are open-source, free CLI tools, while others are enterprise cloud platforms charging thousands of euros in annual licensing. As a team of four, our budget is tight, but we don't want to drop the ball in front of the client either.
Are free and open-source static analysis tools actually good enough to catch real vulnerabilities, or is the gap between them and pricey paid tools night and day? Also, does simply running these tools count as an actual security audit?