Skip to content
Free Code Guard scan

Find the payment flaws fraudsters look for.

Code Guard runs twenty checks on your repository, built for M-Pesa, NIP, Paystack and wallet code. Each finding comes with the fix.

  • Free, with no commitment
  • GitHub or GitHub Enterprise
  • Each finding ranked, with a fix and a test
  • A prompt for your coding agent

Ask for a free scan

* Required

We use these details to send what you asked for and to follow up. See our privacy notice.

How it works
  1. 01

    Tell us about the repo

    Which repository, which language, and where it is hosted.

  2. 02

    We set up the scan

    We agree access with your team before anything runs.

  3. 03

    Code Guard runs 20 checks

    Callbacks, races, idempotency, step-up, OTPs, secrets and more.

  4. 04

    You get the findings

    Ranked by severity, each with the exploit, the fix and a test.

What you get

Plain answers, not a sales deck.

How each flaw is exploited

In plain words, with a KES or NGN example.

The fix, for your code

Specific to your language and your payment provider.

A test that proves it

Ready to add to your CI, so it stays fixed.

A prompt for your coding agent

Paste it in and let the agent make the change.

The twenty checks
  • CriticalPayment callbacks credited without checking they came from the provider
  • CriticalBalance updates that can race (double spend)
  • CriticalPayment or API secrets in source code
  • CriticalSQL built from user input on money tables
  • HighThe amount to charge taken from the client
  • HighAmounts not checked to be positive
  • HighPayouts without an idempotency key
  • HighAccounts fetched by ID without an owner check
  • HighMass assignment of balance, role or KYC fields
  • HighPhone or payout details changed without re-authentication
  • HighPayouts without a PIN or OTP
  • HighOTP and login endpoints without a rate limit
  • HighOTPs from weak randomness, or too short
  • HighJWTs accepted without verification
  • HighKYC checks the client can bypass
  • HighTest or debug backdoors in authentication
  • MediumOTPs that never expire or can be reused
  • MediumMoney stored as floating point
  • MediumPayouts with no amount or daily limit
  • MediumCallback or redirect URLs taken from the request
Book a demo

See Sieve catch fraud in your business.

Book a demo and get a private workspace set up for how your customers pay.