1. Home
  2. Services
  3. Managed Support
  4. Maintainability Review
Maintainability Review & Due Diligence

Know exactly what you're getting before you commit.

An independent, expert evaluation of a codebase, its infrastructure, and the practices around it. Whether you are acquiring a product, assessing a vendor's work, validating an investment, or deciding whether to support or rebuild, we give you a written, severity-rated view with costed options, so there are no surprises after the decision is made.

Fixed price 3–10 working days NDA as standard Read-only access
When a review pays for itself

Four decisions that deserve independent eyes

Pre-acquisition due diligence

Assess the codebase, infrastructure, and engineering practices before you buy a company or a product. Know the remediation cost before it becomes your remediation cost.

Vendor assessment

An independent quality review of what a contractor or agency has delivered, whether you are mid-project, at sign-off, or deciding whether to renew.

Internal health check

An outside view on mounting technical debt in an in-house system, with a prioritised plan your team can own or hand to us.

Pre-investment review

Technical validation for investors and boards: is the platform what the deck says it is, and what will it cost to scale?

  It is also the first step of every takeover

The same review underpins our development partner transitions, internal systems handovers, and AI-built app rescues. If you go on to work with us, nothing is repeated. If you do not, the report is yours to act on with anyone.

What we assess

Six areas, each rated for severity and business impact

Code quality & architecture

Structure, separation of concerns, naming, duplication, and architectural coherence. Could a competent engineer who has never seen this code maintain it?

Security posture

Authentication, authorisation, data handling, secret management, dependency vulnerabilities, and OWASP Top 10 exposure, with each finding flagged by severity.

Test coverage & CI/CD

What is tested and what is not, pipeline maturity, deployment procedures, rollback capability, and environment management. See how we run DevOps and CI/CD ourselves.

Infrastructure & scalability

Hosting setup, database design, caching, growth headroom, cost efficiency, and single points of failure, on Azure or elsewhere.

Documentation & knowledge risk

How much lives only in people's heads. Bus factor, onboarding viability, and the gaps that would hurt most if a key person left tomorrow.

Dependency & licence risk

Third-party libraries, framework versions, end-of-life components, and open-source licence compliance that could block a sale, a tender, or a release.

How it works

Four stages from scoping call to action

1
30 minutes

Scoping call

We establish the decision the review has to support, whether that is an acquisition, a vendor check, or a health check, so the assessment answers your actual question.

Output: fixed-price quote and access checklist
2
3 to 10 days

Codebase review

Senior engineers run a manual and automated review across architecture, security, tests and pipelines, dependencies and licences, and infrastructure configuration.

Method: AI-assisted analysis, engineer-verified
3
Within days

Report & walkthrough

A detailed written report with every finding rated for severity and business impact, plus a prioritised action list with cost estimates, presented in a session with questions answered.

Deliverable: report, risk ratings, costed plan
4
Optional

Remediation

Hand the plan to your own team, or ask us to remediate as a standalone engagement or as part of managed support.

Your choice: no obligation either way
What's delivered

A report you can put in front of a board

Written for the decision-maker as much as the engineer. Findings are explained in business terms first, technical detail second, and every recommendation carries an indicative cost.

  • Executive summary with an overall maintainability rating
  • Findings by area, each rated for severity and business impact
  • Security findings aligned to OWASP Top 10, with proof where relevant
  • Dependency and licence inventory with end-of-life flags
  • Knowledge-risk assessment and documentation gaps
  • Prioritised action list with indicative cost estimates
  • Support-versus-rebuild recommendation where that is the question
  • Walkthrough session with questions answered
Trust & Compliance

Due diligence, already answered

Handing a live system to a new partner means trusting them with source code, credentials, and data. We make that easy to verify: our policies, certifications, and evidence are published openly in our Trust Centre, and the commercial terms we work to are set out in our Client Playbook.

Trust Centre

Our complete policy set, certifications including Cyber Essentials, insurance, and company information in one place.

Visit the Trust Centre

Information Security

How we protect your code, credentials, and data during an engagement: secrets in Key Vault, encrypted transfers, least privilege.

Read the policy

Incident Response

How a security incident would be handled: containment, investigation, and prompt notification of affected customers.

See how we respond

Hosting & Data Residency

Where your data lives while we support the system, and how UK residency is maintained when your obligations require it.

Check data residency

Engagements are governed by our Master Services Agreement, with a UK GDPR Article 28 Data Processing Agreement wherever personal data is involved. We are happy to sign a mutual NDA before any access is granted. Common due-diligence questions, answered →

Frequently asked questions

Maintainability reviews, answered

How long does a review take?

Typically three to ten working days of review depending on the size and complexity of the codebase, with the report delivered within days of completion. The scoping call and walkthrough are scheduled around your availability.

What access do you need?

Read-only access to the repositories, plus infrastructure and CI/CD pipeline access where possible. Where access is limited, for example before an acquisition completes, we work with what can be shared and say clearly what we could not assess.

Can you sign an NDA?

Yes, and we expect to for due diligence work. We will sign yours or provide ours. Our security practices are published in the Trust Centre and common due-diligence questions are already answered there.

What is delivered?

A detailed written report with every finding rated for severity and business impact, a prioritised action list with cost estimates, and a walkthrough session with questions answered.

Can you fix the issues you find?

Yes. We can propose remediation as a standalone engagement or as part of managed support. Equally, your own team or another supplier can act on the report. We have no stake in the answer.

What does a review cost?

Reviews are fixed price, scoped on the initial call according to codebase size and the depth required. Our rate card is published if you want to sanity-check the quote.

Can you review AI-generated or legacy code?

Both are common. AI-built applications are covered by our vibe coding rescue service and older Microsoft stacks by legacy application support; the review is the same rigorous first step for each.

Make informed decisions about software you depend on

Tell us what decision the review needs to support and we will scope it on a short call, quote a fixed price, and tell you honestly if you do not need one.

Scope a Review All Managed Support Services

Cyber Essentials certified  ·  UK-based team  ·  Microsoft Partner  ·  Policies and evidence at our Trust Centre

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor