We're a UK based startup, with several corporate clients.
We just launched our product on one of these clients sites, and in our contract is the requirement for us to have a 3rd party carry out a review of our code.
The reasoning is that a portion of our code is embedded in a number of pages in their site and they do not have visibility of its functionality.
We haven't come across this issue with any other clients yet, and searching for 3rd party code reviewing services hasn't turned up anything suitable for this purpose - the focus seems to be on clean code/standards compliance as opposed to security.
Does anyone have any advice, experience or recommendations of services that carry out this function?