'If the code developer is offering the code security tool, is that like the fox guarding the hen house?'