A code audit that tells you what your software is really worth.
Your supplier says it needs a rewrite. Your developers say it just needs time. The board wants a date. A code audit settles it on the facts: engineers read the code, run it, check its security and its data, and talk with the people who maintain it. You get a written report and a plan you can act on, with us or with anyone else.
- What you receive
- A written report, the risks ranked, and a recommendation for each part of the software.
- Scope and price
- Set before we start, from the size of the code and the questions you need answered.
- What comes next
- Your decision. The plan works with your team, with us or with another supplier.
What you get at each step of the audit.
Before we start
Agree on the questions
Rewrite or not, take over a supplier’s code, buy a company, pass a security review: the audit is shaped around the decision you have to make. You get a written scope and a fixed price.
Review
Read, run and measure
Read-only access to the code and the servers, automated analysis, then a line-by-line reading of the parts that matter. The software is built and deployed the way your team does it.
Interviews
Talk with the people who know
Developers, users and whoever deploys the software. Much of what an audit finds was never written into the repository: it lives in people’s heads.
Report
Decide on the facts
A written report, the risks ranked by impact, and for each part of the software a recommendation: keep, fix, refactor or rebuild, with the effort each option takes.
What is a code audit?
A code audit is an independent review of an application’s source code, architecture, dependencies, security, tests and deployment. It tells the owner what state the software is really in, which risks it carries and what each option would take: keep it, fix it or rebuild it. A useful audit ends with a ranked plan that a manager can act on, backed by evidence an engineer can check.
Most audits are asked for at a turning point. A supplier leaves, a rewrite is on the table, a company is being bought, an incident has shaken confidence. In each case someone has to decide with money at stake, and the people closest to the code are rarely neutral about it.
A software project rescue starts the same way. When a project has stalled, the audit separates what is wrong with the code from what is wrong around it: priorities, process, knowledge held by one person. Sometimes the code is the smaller problem, and the report says so.
When a code audit changes the decision.
The first is a real project; the client name stays private and the facts are the ones published at delivery. The other two are the moments we are most often called in.
Real project: a B2B lead generation company where the problem sat around the code
BeforeThe product team had stopped delivering. Sprints looked like planning meetings that decided nothing, and management no longer knew what to ask of its developers.
AfterBefore touching the code, the frame was reset: a backlog prioritized on business value, blockers raised within 24 hours, public demos. The JavaScript stack was kept as it was, and the team delivered again under an internal product owner.
Before taking over a supplier’s code
BeforeThe agency that built the software is leaving, and nobody knows what is being handed over.
AfterA clear list of what works, what is fragile and what is missing, before you sign with the next team.
Before a rewrite decision
BeforeA rewrite estimate on the table, and no independent view of whether it is needed.
AfterEach part of the software assessed on its own, so only what must be rebuilt is rebuilt.
What the price of a code audit depends on.
Reviewing one application in a single language and auditing a portfolio of services built by three suppliers are different jobs. The scope and the price are set in writing before we start, from these factors.
Read the custom software cost guide, with market ranges- 01The size of the code, and the number of applications or services.
- 02The number of languages, frameworks and databases involved.
- 03How deep the security review must go.
- 04Whether the servers, the deployment and the data are in scope.
- 05The access we get to the people who know the software.
What a code audit checks, and why it matters to you.
Seven areas, each tied to a business risk. The report rates every one of them and says which to handle first.
| Criterion | What we look at | The risk if it is weak |
|---|---|---|
| Architecture | How the software is split, what depends on what | Every change touches everything, and costs more each year |
| Code quality | Readability, duplication, complexity of the critical parts | Only the original authors can change it safely |
| Dependencies and versions | Frameworks, libraries and runtimes, and their support status | Security flaws nobody patches, and forced upgrades |
| Security | Authentication, access rights, secrets, input handling, known flaws | A data breach, and the GDPR duties that follow |
| Tests and deployment | Automated tests, build and release process, rollback | Fear of releasing, and incidents in production |
| Data | Database structure, integrity, backups, personal data | Wrong figures, lost history, a migration that fails |
| Knowledge | Documentation, and who knows what | The software stops the day one person leaves |
Code audit: the questions buyers ask us
How long does a code audit take?
It depends on the size of the code and on the questions you need answered. We set the scope and the price with you in writing before we start. A focused audit on one application is much shorter than a review of several services built by different suppliers.
What do you need from us?
Read-only access to the code repository and, if in scope, to the servers and a copy of the database. Then a few hours with the people who build, deploy and use the software. We work under a confidentiality agreement, and you revoke our access when the audit ends.
Is a code audit the same as a penetration test?
No. The audit reads the code and its configuration to find security weaknesses, among other risks. A penetration test attacks the running software from outside, like an intruder would. They complement each other, and the audit can tell you whether a penetration test is worth ordering next.
Can you audit code written by another agency?
Yes, that is the most common case. The report stays factual about the code and the process, so it can be shared with the supplier concerned. The goal is a decision for you, and a fair view of the work.
What happens if the audit recommends a rewrite?
The report says which parts need it, and why, with the effort each option takes. Often only part of the software needs rebuilding. You are free to carry out the plan with your team, with us or with another supplier.
Do we have to continue with you after the audit?
No. The report is yours and is written to be used by anyone. If you want us to carry out the next step, whether maintenance or modernization, its scope and price are fixed in writing before it starts.
An audit you can show your board, and your supplier.
Security and dataEvidence behind every finding.
Each risk points to the file, the dependency or the measurement it comes from, so your engineers can check it.
Read-only access, under confidentiality.
We never change your code during an audit, and access ends with the mission.
Written for two readers.
A summary a manager can decide on, and the technical detail a developer can act on.
No rewrite to sell.
The recommendation is made part by part, and keeping the software as it is remains an option on the table.
In the same family
After the audit
- Application modernization When the audit shows the software must move.
- Application maintenance When the audit shows it needs looking after.
- Custom software development When a part has to be built anew.
- Business applications The internal tools we build and audit.
- AI readiness assessment When your question is where AI pays off.
- Custom software cost guide Market price ranges, with their sources.
- Technical debt, explained How it is measured, and what an audit adds to the tools.
What would you decide if you knew the real state of your code?
Tell us about the software and the decision in front of you. We reply within one business day to set up a free 30-minute call, and you leave it with the questions the audit should answer.