Do you really know what state your software is in?
The software works, but every change costs more than the last and nobody can say why. In two weeks we give you an independent snapshot: what's there, what's about to break, what to fix first.
Why you need outside eyes
Whoever wrote the software can't judge it, and whoever uses it lacks the tools to. The result is that decisions get made on trust. The audit replaces trust with a document.
What we analyse
Code and architecture
Quality, duplication, technical debt, outdated dependencies, tests. Where the software holds and where it breaks on the next change.
Infrastructure and costs
Hosting, environments, deployment, backups, monitoring. How much you're paying and for what.
Security
Access management, personal data, secrets in the code, known vulnerabilities in the libraries in use.
Processes and team
How a change is born, who approves it, how long it takes to reach production, where time is lost.
Vendor risk
What happens if whoever wrote the software stops answering tomorrow. Who owns the code, the domains and the accounts.
Priorities and estimates
An ordered list of interventions with impact, effort and indicative cost. Not a list of complaints.
How it works
- 01
Access and kick-off
One hour with you and whoever built the software. We need the repositories, read access and the questions you want answered.
- 02
Two weeks of analysis
We work independently. No disruption to your team beyond a couple of targeted clarifications.
- 03
Report and debrief
A written document plus a 90-minute session to discuss it with you and with whoever will execute it.
Who it's for
It's for you if…
- You're about to invest a significant amount in existing software.
- You want to change vendor and don't know what you're inheriting.
- You're evaluating an acquisition or technical due diligence.
- Development timelines have stretched and nobody explains why.
It's not for you if…
- The software doesn't exist yet: in that case you need setup consulting.
- You only need a formal penetration test for a compliance requirement.
- You want a document that blames someone in particular.
Frequently asked questions
Do we need our current vendor's permission?+
We need read-only access to the code and environments. If the vendor refuses, that's already the audit's first finding.
Is the report understandable to non-technical readers?+
Yes. The first part is for management: risks, costs, priorities. The second is for developers, with the technical detail.
Do you then force us to work with you?+
No. The report is yours and you can give it to anyone, including your current vendor. If you want us to run the execution, we discuss it afterwards.
What if the project is very large?+
€2,900 covers a normally sized system. If it turns out to be bigger after kick-off, we give you an updated quote before starting.
Request the audit
Tell us in two lines what worries you: we'll reply with available dates and the list of access we need.