The real state of your system

A system health check. In five to ten working days you get a written report: risks ranked by impact, what can be fixed straight away and what needs a project. Groundwork for an audit, and for deciding whether to stay with your current supplier.

Seven questions that are most often met with silence

Each one is a threshold. If nobody in the business can answer one of them, you have most likely crossed that threshold already - and you’ll only find out in production.

Trust

Does it have to work every time, not just in the demo?

The warning sign: ‘it almost works’ keeps coming up when people talk about the product.

Money

Do payments flow through it?

The warning sign: nobody has ever written down how refunds and failed charges work.

Exposure

Does it hold other people’s personal data?

The warning sign: nobody can say who is allowed to see what.

Audit

Will someone want you to prove it?

The warning sign: logs and policies exist, but nobody can put evidence together from them.

Growth

Can it carry more users than it was built for?

The warning sign: quick patches are piling up and nobody is counting them.

Continuity

Could a second person work on it?

The warning sign: the architecture lives only in a chat history, or in one person’s head.

Year two

Will it still be changing a year from now?

The warning sign: delivery is slowing down and the team is getting the blame.

What you get

A written report, not a presentation. It describes the state the system is in, and what that means for the decision in front of you.

Findings are graded by severity on four levels, so you can read the report from the top and stop once you are past the issues that matter to you.

Every finding comes with a fix and a size estimate - whether it is an afternoon, a sprint or a project. Together they make a plan for the next three to twelve months.

The report is yours to keep. It is written so you can take it anywhere - to an auditor, to your current supplier or to another one. Nothing commits you to continuing with us.

What it is not

  • It is not a pitch for a rewrite. A rewrite is the last resort, not the first. Most findings can be solved more cheaply.
  • It is not a certified audit. It is the groundwork that lets you go into an audit prepared, with no surprises.
  • We don’t touch your production systems. We read, measure and ask questions. We deploy nothing and change nothing.
5-10
working days
4
severity levels
for every finding
Fixed
price, agreed
in advance
0
commitment to
continue with us

How it works

1 · Introductory call

Half an hour. You tell us what is hurting and what worries you. From that we work out the scope and a fixed price - and only then do you decide.

2 · Access and interviews

We need the repository, read-only access to production and an hour with the people who know the system: the developers, who know how it is built, and the people who work in it every day, who know where it gets stuck.

3 · Review

Architecture, code, security, integrations, deployment and operations. We read the system from two angles: as an attacker, and as a new team member who will take it over tomorrow.

4 · Handing over the report

We don’t email the report and vanish. We go through it with you, answer your questions and tell you what we would do first in your place.

Do you run a system where nobody can say what shape it is in?

Get in touch. On the introductory call we’ll establish the scope and tell you the price - with no obligation.

Arrange an introductory call