# An LLM-assisted security review of GlobaLeaks: 41 findings for –$3,140

> Source: <https://www.isgroup.biz/en/cyber-security/llm-based-code-security-review-costs-findings-methodology.html>
> Published: 2026-07-30 18:16:01+00:00

We spent approximately $3,140 on API calls to conduct a security review of [GlobaLeaks](https://www.globaleaks.org/), a software platform that had already undergone six independent professional audits over the past thirteen years.

The review identified 29 vulnerabilities, 12 denial-of-service issues, and 42 hardening recommendations. The average cost was approximately $77 per confirmed finding, before human validation.

The total spend is one of the most relevant figures. Reviewing an entire codebase, line by line and against the main known classes of software weakness, has traditionally required weeks of work, specialised expertise, and substantial budgets. This type of analysis is now far more accessible.

The distribution of costs was also notable. The model with the most advanced reasoning capabilities accounted for 62% of the budget while processing only 7% of the tokens. Standard models handled most of the volume at a significantly lower cost.

Deep analysis remains more expensive than broad coverage, but the difference is no longer large enough to represent a significant barrier.

For organisations developing critical software, the implication is clear: systematically reviewing an entire codebase in depth is now within reach of many more people and organisations.

The full report, including the methodology and a breakdown of costs by model, is available here: **What Can an Attacker Find With an LLM?**

#CyberSecurity #ApplicationSecurity #LLM #SecureCodeReview #ISGroup
