The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
An independent, expert evaluation of a codebase, its infrastructure, and the practices around it. Whether you are acquiring a product, assessing a vendor's work, validating an investment, or deciding whether to support or rebuild, we give you a written, severity-rated view with costed options, so there are no surprises after the decision is made.
Assess the codebase, infrastructure, and engineering practices before you buy a company or a product. Know the remediation cost before it becomes your remediation cost.
An independent quality review of what a contractor or agency has delivered, whether you are mid-project, at sign-off, or deciding whether to renew.
An outside view on mounting technical debt in an in-house system, with a prioritised plan your team can own or hand to us.
Technical validation for investors and boards: is the platform what the deck says it is, and what will it cost to scale?
The same review underpins our development partner transitions, internal systems handovers, and AI-built app rescues. If you go on to work with us, nothing is repeated. If you do not, the report is yours to act on with anyone.
Structure, separation of concerns, naming, duplication, and architectural coherence. Could a competent engineer who has never seen this code maintain it?
Authentication, authorisation, data handling, secret management, dependency vulnerabilities, and OWASP Top 10 exposure, with each finding flagged by severity.
What is tested and what is not, pipeline maturity, deployment procedures, rollback capability, and environment management. See how we run DevOps and CI/CD ourselves.
Hosting setup, database design, caching, growth headroom, cost efficiency, and single points of failure, on Azure or elsewhere.
How much lives only in people's heads. Bus factor, onboarding viability, and the gaps that would hurt most if a key person left tomorrow.
Third-party libraries, framework versions, end-of-life components, and open-source licence compliance that could block a sale, a tender, or a release.
We establish the decision the review has to support, whether that is an acquisition, a vendor check, or a health check, so the assessment answers your actual question.
Senior engineers run a manual and automated review across architecture, security, tests and pipelines, dependencies and licences, and infrastructure configuration.
A detailed written report with every finding rated for severity and business impact, plus a prioritised action list with cost estimates, presented in a session with questions answered.
Hand the plan to your own team, or ask us to remediate as a standalone engagement or as part of managed support.
Written for the decision-maker as much as the engineer. Findings are explained in business terms first, technical detail second, and every recommendation carries an indicative cost.
Every engagement starts from the same foundation: understand the estate, take operational ownership, then improve it. These pages cover the situations we are asked about most.
Independent technical due diligence before you acquire, invest in, or commit to supporting a codebase.
Handing a live system to a new partner means trusting them with source code, credentials, and data. We make that easy to verify: our policies, certifications, and evidence are published openly in our Trust Centre, and the commercial terms we work to are set out in our Client Playbook.
Our complete policy set, certifications including Cyber Essentials, insurance, and company information in one place.
Visit the Trust CentreHow we protect your code, credentials, and data during an engagement: secrets in Key Vault, encrypted transfers, least privilege.
Read the policyHow a security incident would be handled: containment, investigation, and prompt notification of affected customers.
See how we respondWhere your data lives while we support the system, and how UK residency is maintained when your obligations require it.
Check data residencyEngagements are governed by our Master Services Agreement, with a UK GDPR Article 28 Data Processing Agreement wherever personal data is involved. We are happy to sign a mutual NDA before any access is granted. Common due-diligence questions, answered →
Typically three to ten working days of review depending on the size and complexity of the codebase, with the report delivered within days of completion. The scoping call and walkthrough are scheduled around your availability.
Read-only access to the repositories, plus infrastructure and CI/CD pipeline access where possible. Where access is limited, for example before an acquisition completes, we work with what can be shared and say clearly what we could not assess.
Yes, and we expect to for due diligence work. We will sign yours or provide ours. Our security practices are published in the Trust Centre and common due-diligence questions are already answered there.
A detailed written report with every finding rated for severity and business impact, a prioritised action list with cost estimates, and a walkthrough session with questions answered.
Yes. We can propose remediation as a standalone engagement or as part of managed support. Equally, your own team or another supplier can act on the report. We have no stake in the answer.
Reviews are fixed price, scoped on the initial call according to codebase size and the depth required. Our rate card is published if you want to sanity-check the quote.
Both are common. AI-built applications are covered by our vibe coding rescue service and older Microsoft stacks by legacy application support; the review is the same rigorous first step for each.
Tell us what decision the review needs to support and we will scope it on a short call, quote a fixed price, and tell you honestly if you do not need one.
Scope a Review All Managed Support ServicesCyber Essentials certified · UK-based team · Microsoft Partner · Policies and evidence at our Trust Centre