Review an authorized source tree, pull request, or selected paths for security defects using threat modeling, targeted SAST, manual source-to-sink validation, remediation design, and regression testing, without treating scanner output as proof or attacking production systems.