The real state of your system
A system health check. In five to ten working days you get a written report: risks ranked by impact, what can be fixed straight away and what needs a project. Groundwork for an audit, and for deciding whether to stay with your current supplier.
Seven questions that are most often met with silence
Each one is a threshold. If nobody in the business can answer one of them, you have most likely crossed that threshold already - and you’ll only find out in production.
Trust
Does it have to work every time, not just in the demo?
The warning sign: ‘it almost works’ keeps coming up when people talk about the product.
Money
Do payments flow through it?
The warning sign: nobody has ever written down how refunds and failed charges work.
Exposure
Does it hold other people’s personal data?
The warning sign: nobody can say who is allowed to see what.
Audit
Will someone want you to prove it?
The warning sign: logs and policies exist, but nobody can put evidence together from them.
Growth
Can it carry more users than it was built for?
The warning sign: quick patches are piling up and nobody is counting them.
Continuity
Could a second person work on it?
The warning sign: the architecture lives only in a chat history, or in one person’s head.
Year two
Will it still be changing a year from now?
The warning sign: delivery is slowing down and the team is getting the blame.
What you get
A written report, not a presentation. It describes the state the system is in, and what that means for the decision in front of you.
Findings are graded by severity on four levels, so you can read the report from the top and stop once you are past the issues that matter to you.
Every finding comes with a fix and a size estimate - whether it is an afternoon, a sprint or a project. Together they make a plan for the next three to twelve months.
The report is yours to keep. It is written so you can take it anywhere - to an auditor, to your current supplier or to another one. Nothing commits you to continuing with us.
What it is not
- It is not a pitch for a rewrite. A rewrite is the last resort, not the first. Most findings can be solved more cheaply.
- It is not a certified audit. It is the groundwork that lets you go into an audit prepared, with no surprises.
- We don’t touch your production systems. We read, measure and ask questions. We deploy nothing and change nothing.
for every finding
in advance
continue with us
How it works
1 · Introductory call
Half an hour. You tell us what is hurting and what worries you. From that we work out the scope and a fixed price - and only then do you decide.
2 · Access and interviews
We need the repository, read-only access to production and an hour with the people who know the system: the developers, who know how it is built, and the people who work in it every day, who know where it gets stuck.
3 · Review
Architecture, code, security, integrations, deployment and operations. We read the system from two angles: as an attacker, and as a new team member who will take it over tomorrow.
4 · Handing over the report
We don’t email the report and vanish. We go through it with you, answer your questions and tell you what we would do first in your place.
Do you run a system where nobody can say what shape it is in?
Get in touch. On the introductory call we’ll establish the scope and tell you the price - with no obligation.