forumNew topic

The agency said they ran a source code analysis for handover, what does that mean and is it necessary?

MMehmet Y***Member
Job title
IT manager
Sector
Packaging
Organization type
40-person manufacturing company
Joined
Oct 2024
Message
4
#1

We agreed with a software agency on a 420.000 TL budget and a 5-month delivery timeline for our B2B ordering portal where we sell industrial spare parts. The process got delayed by about two months and last week we finally reached the go-live stage. During the final sign-off meeting, while justifying part of the delay, the agency manager claimed they ran a comprehensive source code analysis prior to delivery, which supposedly ensured a much more secure and bug-free project handover.

When I checked our contract, I saw no standalone clause for this, only general testing procedures were listed. They didn't ask for any extra charge on the invoice, but I don't really understand what this analysis is what exactly it audits, or how technically valid it is for the agency that wrote the software to analyze its own code.

To anyone who has taken delivery of similar projects before: What exactly is source code analysis? Is it enough for an agency to analyze its own code, or should I have an independent specialist look at it as well?

RRıdvan Y***Expert
Job title
Software team lead
Joined
Sep 2023
Message
196

Doki · Interface design · 2023

Most Helpful#2

Short answer: Source code analysis is the process of scanning software's raw, uncompiled text for security vulnerabilities, architectural flaws, and performance bottlenecks. This analysis is critical for software quality, but a dev firm auditing its own code is merely an internal check; it does not count as an independent audit.

Agencies using this term usually mean one of two things. First, running automated tools in the dev environment to clean up syntax issues and known common library vulnerabilities. This is already a baseline step that any competent software team should include in routine delivery. Second, a line-by-line architectural review and logical flaw scan performed by an independent security team, which is called an in-depth source code audit.

If there's no separate clause in your contract and no extra invoice was issued, the agency most likely just ran standard automated static scanning tools. Grading their own code is like a student grading their own exam paper. If you want genuine assurance, put these three conditions in the handover report: 1) Specify which software tools were used in the analysis, 2) Share the raw security and bug report with you, 3) Document that all critical-severity findings were resolved prior to delivery.

If your portal involves high-value financial transactions, sensitive customer data, or ERP integration APIs, requesting an external audit from an independent cybersecurity firm after going live will minimize your risk.

VVildan Ş***Member
Job title
Quality control inspector
Sector
Textile
Organization type
medium-sized business
Joined
Aug 2024
Message
162
#3

Static code analysis inspects the app's source code without running it, usually catching known security vulnerabilities, memory leaks, or non-standard code blocks. The agency should be able to provide the raw PDF report showing which tool was used to scan and the severity levels of the findings.

Correction: I misremembered the figure, it was a bit lower.

RRabia Ç***Member
Job title
IT manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jun 2025
Message
354
#4

Did they deliver a written technical report following this analysis? Did they specify which standards they scanned against, like OWASP rules or was it just verbal?

VVildan Ş***MemberCommunity member
Joined
Nov 2023
Message
17
#5

Analyzing your own code and finding zero issues is a classic delivery defense. It's very likely they ran a free plugin and claimed they "analyzed" it just to justify the two-month delay. Ask for the report, they usually end up empty-handed.

ÖÖmer Ö***Member
Job title
Social media manager
Sector
Printing
Organization type
chain store
Joined
Feb 2023
Message
64
#6

You have 3 clear demands to send the agency right now: 1) Ask for the analysis output report in its raw form, 2) Get written confirmation that critical and high-severity vulnerabilities have been patched, 3) Add an agency liability annotation to the handover report for any unresolved medium-severity risks.

ÖÖzgür B***MemberCommunity member
Joined
Feb 2023
Message
34
#7

Last year, on our 350.000 TL budget B2B project, the agency claimed everything was clean. It didn't sit right with us, so we paid 35.000 TL for an independent third-party audit; 3 critical authorization vulnerabilities turned up. The agency had to patch them for free under the contract.

EEfe K***Member
Job title
Intern
Sector
Consulting
Organization type
early-stage startup
Joined
Nov 2023
Message
107
#8

Send an email without wasting time. Ask for the dates of the tests run, the name of the scanning tool used, and the bug list generated if any. If it was part of their routine development, they already have the output on hand and can send it over today.

SSena M***MemberCommunity member
Joined
Dec 2024
Message
142
#9

they told us the exact same thing when our delivery was delayed, and when we asked for a report they sent a generic two-page write-up. I mean make sure to demand detailed logs and scan output, dont let them brush it off.

GGizem A***MemberCommunity member
Joined
Oct 2025
Message
341
#10

On our own portal, the system locked up three months after delivery due to a database query error. Turns out when the agency said they "ran source code analysis", they just ran basic syntax checks and never touched architectural load tests. Ever since, I refuse to officially accept delivery of any software without seeing an independent external report.

ZZehra U***ExpertCommunity member
Joined
Aug 2023
Message
19
#11

My questions are cleared up, thanks. The biggest time-waster for us was not knowing who had the final say.

Hope this helps.

SSinan Y***Member
Job title
Graphic Designer
Sector
IT services
Organization type
early-stage startup
Joined
Dec 2023
Message
25
#12

Saved. If you get three different answers on a topic, the question was asked wrong.

I'm also curious if anyone does it differently.

İİbrahim Y***MemberCommunity member
Joined
Feb 2026
Message
3
#13

correct.

TTuğçe M***Member
Job title
Software team lead
Sector
Education
Organization type
early-stage startup
Joined
Jul 2024
Message
217
#14

We've heard this a lot, but it never happened like that for us. Mistakes made on the meaning of source code analysis side are usually reversible but expensive.

This is my opinion I'm not claiming it's absolute truth.

ZZerrin Ö***MemberCommunity member
Joined
Feb 2026
Message
106
#15

There's a common mistake people make when doing this. Taking notes for two weeks yields better results than a six-month estimate.

If I were you, I'd go this route.

ÖÖmer O***Member
Job title
Field sales representative
Sector
Software
Organization type
sole proprietorship
Joined
Feb 2023
Message
135
#16

Let me summarize the topic, since several different answers were given. If code ownership isn't in the contract, you have no bargaining power when leaving.

JJale T***ExpertCommunity member
Joined
Mar 2022
Message
393
#17

If you're going this route, sort this out first. Solutions that work at a small scale collapse when you grow; I learned this late.

If you post the result here, it will help others too.

HHüseyin T***MemberCommunity member
Joined
Nov 2023
Message
42
#18

My question might sound amateurish, sorry about that. The biggest time-waster for us was not knowing who had the final say.

If I were you, I'd go this route.

MMetin C***MemberCommunity member
Joined
Feb 2024
Message
170
#19

I'm curious too.

ÖÖzge U***Member
Job title
Marketing manager
Sector
Real estate
Organization type
120-person company
Joined
Apr 2023
Message
18
#20

Thanks a lot, I'll try it today.

Reply