Skip to content

A code audit that tells you what your software is really worth.

Your supplier says it needs a rewrite. Your developers say it just needs time. The board wants a date. A code audit settles it on the facts: engineers read the code, run it, check its security and its data, and talk with the people who maintain it. You get a written report and a plan you can act on, with us or with anyone else.

What you receive
A written report, the risks ranked, and a recommendation for each part of the software.
Scope and price
Set before we start, from the size of the code and the questions you need answered.
What comes next
Your decision. The plan works with your team, with us or with another supplier.

What you get at each step of the audit.

  1. Before we start

    Agree on the questions

    Rewrite or not, take over a supplier’s code, buy a company, pass a security review: the audit is shaped around the decision you have to make. You get a written scope and a fixed price.

  2. Review

    Read, run and measure

    Read-only access to the code and the servers, automated analysis, then a line-by-line reading of the parts that matter. The software is built and deployed the way your team does it.

  3. Interviews

    Talk with the people who know

    Developers, users and whoever deploys the software. Much of what an audit finds was never written into the repository: it lives in people’s heads.

  4. Report

    Decide on the facts

    A written report, the risks ranked by impact, and for each part of the software a recommendation: keep, fix, refactor or rebuild, with the effort each option takes.

Read our full delivery method, deliverable by deliverable

What is a code audit?

A code audit is an independent review of an application’s source code, architecture, dependencies, security, tests and deployment. It tells the owner what state the software is really in, which risks it carries and what each option would take: keep it, fix it or rebuild it. A useful audit ends with a ranked plan that a manager can act on, backed by evidence an engineer can check.

Most audits are asked for at a turning point. A supplier leaves, a rewrite is on the table, a company is being bought, an incident has shaken confidence. In each case someone has to decide with money at stake, and the people closest to the code are rarely neutral about it.

A software project rescue starts the same way. When a project has stalled, the audit separates what is wrong with the code from what is wrong around it: priorities, process, knowledge held by one person. Sometimes the code is the smaller problem, and the report says so.

When a code audit changes the decision.

The first is a real project; the client name stays private and the facts are the ones published at delivery. The other two are the moments we are most often called in.

  • Real project: a B2B lead generation company where the problem sat around the code

    BeforeThe product team had stopped delivering. Sprints looked like planning meetings that decided nothing, and management no longer knew what to ask of its developers.

    AfterBefore touching the code, the frame was reset: a backlog prioritized on business value, blockers raised within 24 hours, public demos. The JavaScript stack was kept as it was, and the team delivered again under an internal product owner.

  • Before taking over a supplier’s code

    BeforeThe agency that built the software is leaving, and nobody knows what is being handed over.

    AfterA clear list of what works, what is fragile and what is missing, before you sign with the next team.

  • Before a rewrite decision

    BeforeA rewrite estimate on the table, and no independent view of whether it is needed.

    AfterEach part of the software assessed on its own, so only what must be rebuilt is rebuilt.

What the price of a code audit depends on.

Reviewing one application in a single language and auditing a portfolio of services built by three suppliers are different jobs. The scope and the price are set in writing before we start, from these factors.

Read the custom software cost guide, with market ranges
  1. 01The size of the code, and the number of applications or services.
  2. 02The number of languages, frameworks and databases involved.
  3. 03How deep the security review must go.
  4. 04Whether the servers, the deployment and the data are in scope.
  5. 05The access we get to the people who know the software.

What a code audit checks, and why it matters to you.

Seven areas, each tied to a business risk. The report rates every one of them and says which to handle first.

The areas reviewed in a code audit
CriterionWhat we look atThe risk if it is weak
ArchitectureHow the software is split, what depends on whatEvery change touches everything, and costs more each year
Code qualityReadability, duplication, complexity of the critical partsOnly the original authors can change it safely
Dependencies and versionsFrameworks, libraries and runtimes, and their support statusSecurity flaws nobody patches, and forced upgrades
SecurityAuthentication, access rights, secrets, input handling, known flawsA data breach, and the GDPR duties that follow
Tests and deploymentAutomated tests, build and release process, rollbackFear of releasing, and incidents in production
DataDatabase structure, integrity, backups, personal dataWrong figures, lost history, a migration that fails
KnowledgeDocumentation, and who knows whatThe software stops the day one person leaves

Code audit: the questions buyers ask us

How long does a code audit take?

It depends on the size of the code and on the questions you need answered. We set the scope and the price with you in writing before we start. A focused audit on one application is much shorter than a review of several services built by different suppliers.

What do you need from us?

Read-only access to the code repository and, if in scope, to the servers and a copy of the database. Then a few hours with the people who build, deploy and use the software. We work under a confidentiality agreement, and you revoke our access when the audit ends.

Is a code audit the same as a penetration test?

No. The audit reads the code and its configuration to find security weaknesses, among other risks. A penetration test attacks the running software from outside, like an intruder would. They complement each other, and the audit can tell you whether a penetration test is worth ordering next.

Can you audit code written by another agency?

Yes, that is the most common case. The report stays factual about the code and the process, so it can be shared with the supplier concerned. The goal is a decision for you, and a fair view of the work.

What happens if the audit recommends a rewrite?

The report says which parts need it, and why, with the effort each option takes. Often only part of the software needs rebuilding. You are free to carry out the plan with your team, with us or with another supplier.

Do we have to continue with you after the audit?

No. The report is yours and is written to be used by anyone. If you want us to carry out the next step, whether maintenance or modernization, its scope and price are fixed in writing before it starts.

An audit you can show your board, and your supplier.

Security and data
  • Evidence behind every finding.

    Each risk points to the file, the dependency or the measurement it comes from, so your engineers can check it.

  • Read-only access, under confidentiality.

    We never change your code during an audit, and access ends with the mission.

  • Written for two readers.

    A summary a manager can decide on, and the technical detail a developer can act on.

  • No rewrite to sell.

    The recommendation is made part by part, and keeping the software as it is remains an option on the table.

What would you decide if you knew the real state of your code?

Tell us about the software and the decision in front of you. We reply within one business day to set up a free 30-minute call, and you leave it with the questions the audit should answer.

We reply within one business day and only use your message for that. Privacy