Where the target agrees to it, the assessment can include evidence drawn from their repositories: contributors, commit history, dependencies, licenses and known vulnerabilities. In a project it lives under Evidence → Software Analysis, beside the documents and notes the rest of the assessment stands on.
We do not hold the source
This is the part worth understanding before you ask a target for it, because it is usually their first objection.
Analysis runs against an extract, produced in isolation from the platform. The extract contains the measurements — contributor statistics, commit metadata, dependency manifests, license findings, file and language counts — and the key extracted data is then handed into the project. Percomb does not clone the repository, does not need credentials to the target's systems, and does not store their source code.
A target that will not grant a third party live access to their repositories can usually still agree to this, which is why the assessment can reach the code at all.
What it produces
| Area | Evidence |
|---|---|
| Contributors | Who commits, how often, and where knowledge is concentrated |
| Activity | Commit history over time, by area of the codebase |
| Dependencies | What is used, how current it is, and its license |
| Vulnerabilities | Known advisories against those dependencies, with detail |
| Composition | Languages, size, test and documentation presence |
Key person risk
The contributor data is what makes this finding evidenced rather than anecdotal: a component with a single maintainer and no second owner is visible in the commit history. Report it as key person risk and name the component and the dependency — never the developer slang for it, which does not belong in a document an investment committee reads.
Read the extract's date, not today's date
An extract is a snapshot. Every figure it produces is as of the extract date, and the report says so. "No commits in the last quarter" means no commits in the quarter before the extract — which may not be the quarter you are reading in. If the deal timeline has moved, take a fresh extract rather than aging the numbers in your head.
Availability
Source code analysis is part of the plans that include it, and requires the target's cooperation to produce the extract. Without it, the review areas that depend on code evidence rely on documents alone and say so.