What reviewers need
Time-limited, read-only access to your source repository; access to a staging or representative deployment; and any documentation you have about architecture, deployment, and backups. Sparse documentation is common and not disqualifying — reviewers assess what exists and note gaps as findings with clear guidance.