Applications fail at the boundaries between code, identity, data, infrastructure, and business process. GDF combines architecture review, source analysis, dependency review, API testing, and controlled dynamic testing. The assignment can support release assurance, M&A diligence, remediation verification, or a focused review after an event.
Architecture sets the test plan
Review begins with data flows, trust boundaries, authentication, authorization, tenancy, administrative functions, secrets, third-party services, queues, storage, logging, and deployment. Threat scenarios are tied to the application's actual users and transactions rather than copied from a generic checklist.
Code and runtime evidence together
Static tools can identify candidates; reviewers trace data and control flow to determine whether the condition is reachable and consequential. Dynamic tests verify behavior in an approved environment. Manual work targets access-control errors, unsafe state changes, injection, insecure deserialization, server-side request forgery, file handling, concurrency, and misuse of privileged workflows.
- Web, API, mobile-backend, and desktop application assessment
- Manual source-code and architecture review
- Authentication, session, authorization, and tenant-isolation testing
- Dependency, secret, configuration, and deployment review
- Developer-ready fixes and targeted retesting
Findings written for the person making the change
Reports include the affected component, prerequisite, reproduction steps, evidence, consequence, code or design context, and recommended correction. Sensitive test evidence is separated from broad executive distribution. Retesting follows the original route and agreed adjacent conditions, records the environment and date, and identifies residual or untested exposure.