I do this routinely, including literature-grounded audits of my own systems that surfaced numerical, concurrency, and cache-invalidation bugs across thousands of lines. I have also worked inside a SOC 2 fintech environment, so I treat security review as a discipline, not a checkbox.