The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
Independent software assessments for acquisitions, modernisation, operational resilience and technology investment. We help organisations understand what they own, what risks exist, what it will take to maintain or improve their software, and whether the technology can support their future business objectives.
Synthetic example. Every audit is scoped to your question.
A software audit is an independent, evidence-based assessment of an application and everything it depends on: its architecture, source code, technical debt, security controls, infrastructure, deployment processes and the knowledge needed to run it. Technical due diligence is the same assessment carried out to support a specific decision, such as buying a business, investing in one, or changing software supplier.
The output is not a score for its own sake. It is a clear account of the risks that matter to your business, the evidence behind each one, and a prioritised view of what to do next, written so that owners, boards and engineers can all act on it.
Assemblysoft brings practical experience of designing, modernising, integrating, troubleshooting and supporting custom .NET and Microsoft Azure applications. Our recommendations are grounded in delivery realities rather than theoretical architecture alone.
When a business changes software supplier, buys a company or loses its original developer, two questions decide almost everything that follows.
In many cases, yes. Software does not need to be rewritten simply because the original development company is no longer involved. An independent assessment establishes whether another engineering team can maintain, improve or modernise the existing application, and what a structured handover would involve.
Where a replacement is justified, we help identify why, and evaluate the options before substantial expenditure is committed.
Read the full answer → Supplier transition assessment →Ownership and practical control are separate matters. A business can have a working application without controlling its source code, hosting, deployment pipeline or third-party accounts. We establish exactly which repositories, accounts, databases and deployment assets you can access, and which dependencies would complicate a supplier change.
Confirming legal ownership and IP rights requires your legal advisors; our findings tell them which questions to ask.
Read the full answer → Read the article →Scope is agreed with you first. A focused health check may cover three areas; a full due diligence assessment covers all nine.
Structure, coupling and whether the design can support where the business is going. See the .NET code & architecture audit.
Material debt separated from acceptable compromise, and prioritised by business impact, urgency and remediation complexity.
Authentication, authorisation, secrets, dependencies and logging, framed against OWASP ASVS. Not a substitute for penetration testing.
Reliability, security, cost, operations and performance across the Well-Architected pillars. See the Azure assessment.
Build reproducibility, pipelines, test gates, environments and release safety. Can someone else ship a change tomorrow?
Monitoring, incident response, backup, restore and disaster recovery compared with your expectations. See the resilience review.
Frameworks, libraries and platforms mapped to vendor support dates. .NET 8 and .NET 9 both leave support on 10 November 2026.
Repositories, tenants, subscriptions, domains, certificates and service accounts: who holds the keys today.
What is written down, what lives with individuals or suppliers, and the onboarding effort for a new team.
Every engagement is scoped and priced once we understand the systems involved, so you never pay for depth the decision does not need. Our day rates are published on the rate card.
A rapid, targeted view of one application or one concern, when you need direction rather than a full audit.
A full assessment of an application and its estate across all nine areas, for planning the next stage of its life.
Technical due diligence shaped around a transaction or a supplier change, with findings delivered to your timetable.
Commission one on its own, or combine them into a comprehensive audit. Each page explains what is assessed, what you receive and where the boundaries are.
Most of the work uses read-only access, documentation, interviews and existing engineering evidence, so day-to-day operations are not disrupted.
We agree the decision the audit must support, the systems in scope, access arrangements and timescales, under NDA where needed.
Code, configuration, pipelines, cloud estate and documentation, plus short interviews with the people who run the system.
Each finding is checked against evidence, rated for impact and urgency, and marked as verified or uncertain.
Executive assessment, technical report and roadmap, presented to business and technical stakeholders together.
Written for decision-makers first and engineers second. Every material finding carries its evidence, its likely impact, a recommended action and any limitation in what could be verified, so nothing reads as more certain than it is.
View the anonymised sample reportOur audit method draws on established technical and regulatory guidance, so findings use a vocabulary your advisors, insurers and engineers already recognise.
| Area | Supporting authority | How it shapes the audit |
|---|---|---|
| Secure development practices and software acquisition | Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology | Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software. |
| Application security review and verification | Application Security Verification Standard (ASVS)OWASP Foundation | Frames application security findings as verifiable requirements across authentication, access control, input handling and data protection, rather than a superficial vulnerability scan. |
| Cloud reliability, security, cost and operational maturity | Azure Well-Architected FrameworkMicrosoft | Structures Azure workload assessment around its five pillars: reliability, security, cost optimisation, operational excellence and performance efficiency. |
| Data protection during mergers and acquisitions | Data sharing code of practice: due diligence following mergers and acquisitionsUK Information Commissioner's Office | Identifies where personal data, its lawful basis and its security arrangements need attention when systems change hands. Legal conclusions remain with your advisors. |
These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.
We design, modernise, integrate, troubleshoot and support custom .NET and Azure applications every day, including systems we did not build, such as the business-critical legacy applications we supported and migrated for LV=. Our recommendations reflect what change really costs.
The findings are yours to use with your own team or any supplier. There is no obligation to appoint Assemblysoft for remediation, and a recommendation to keep what you have is a perfectly good outcome.
AI tooling helps us map unfamiliar codebases and trace dependencies quickly. Every material finding is verified by a senior engineer before it reaches your report.
A permanent UK team based in Bournemouth, a Microsoft Partner with Cyber Essentials Plus, and policies published openly in our Trust Centre.
If you want help acting on the findings, the same team can turn recommendations into a structured programme: legacy .NET upgrade and migration, Azure modernisation, DevOps and CI/CD and managed application support, including a structured development partner transition. Any implementation work is scoped and agreed separately.
An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.
We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.
Due-diligence questionsRepository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.
Information securityWorking copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.
Data residencyAssemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.
Visit the Trust CentreWhere personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.
One evidence-based method, applied to the decision in front of you. Each specialist assessment can run on its own or as part of a comprehensive audit.
The overview: independent software audits and technical due diligence for acquisitions, supplier changes and investment decisions.
Twenty questions business owners, investors and IT leaders ask before taking on or deciding the future of a software system. Each answer has its own link.
For buyers, investors and organisations inheriting a system from a supplier or developer who is moving on.
In many cases, yes.
Software does not necessarily need to be rewritten simply because the original development company is no longer involved.
An independent technical assessment can establish whether the existing application can be maintained, improved or modernised by another engineering team.
Assemblysoft evaluates the codebase, architecture, dependencies, deployment processes and available documentation to identify potential transition challenges.
The outcome may be a recommendation to retain the existing application, address specific weaknesses and establish a structured handover.
Where a replacement is justified, we can help identify the reasons and evaluate the available options before substantial expenditure is committed. See our software supplier transition assessment.
Link to this answerOwnership and practical control are related but separate matters.
A business may have access to a functioning application without having complete control over its source code, hosting environment, deployment processes or third-party dependencies.
As part of a technical audit, Assemblysoft can establish which repositories, infrastructure accounts, databases, services and deployment assets are accessible to the organisation.
We can also identify technical dependencies that may complicate a supplier transition.
However, confirming legal ownership, intellectual property rights and contractual entitlements requires a review of the relevant agreements by qualified legal advisors.
Our technical findings can help identify which assets and contractual questions need further investigation.
Link to this answerAn independent software audit helps establish whether the technology can support the business objectives behind an acquisition.
Assemblysoft can assess the software's architecture, code quality, technical debt, infrastructure, scalability and operational dependencies. We also identify potential engineering work that may be required after acquisition.
The resulting technical due diligence report helps you understand whether the software is maintainable, what risks could affect future investment and where additional expenditure may be necessary.
Although a software audit does not determine the financial valuation of a business, its findings can provide valuable evidence for commercial negotiations, investment decisions and post-acquisition planning. See acquisition and investment technical due diligence.
Link to this answerYes. Technical due diligence can provide evidence that informs commercial discussions.
For example, an audit may identify unsupported technologies, missing documentation, supplier dependencies, operational weaknesses or significant engineering work that will be necessary after acquisition.
These findings can help buyers and their advisors evaluate future investment requirements, transition obligations and appropriate contractual protections.
Assemblysoft provides the technical evidence and explains its likely operational implications.
Commercial negotiations, transaction valuation and legal terms remain matters for the relevant business and professional advisors.
Link to this answerYes. Pre-acquisition technical due diligence is a common and valuable use of a software audit.
The review can be conducted during the acquisition process, subject to the seller's agreement and appropriate confidentiality and access arrangements.
Assemblysoft can begin with available architecture documentation, technical discussions and supporting evidence, followed by deeper code and infrastructure assessment where access is permitted.
We identify material risks, outstanding questions and technical assumptions that may affect the buyer's decision.
Where access is restricted, our report distinguishes verified findings from areas that remain uncertain.
Link to this answerA maintainable application should be understandable, buildable, testable and deployable by suitably qualified engineers without unreasonable dependence on its original authors.
Assemblysoft evaluates the code structure, development tooling, documentation, automated tests, dependencies and deployment processes.
We also consider how easily a new team could establish a development environment, reproduce existing builds and understand important business workflows.
Where appropriate and authorised, practical build or deployment validation can provide stronger evidence than documentation alone.
The findings help organisations understand the likely onboarding effort and any barriers to transferring technical responsibility.
Link to this answerWhat a code audit and architecture review can, and cannot, tell you about the technical condition of a system.
Software can function correctly for users while still containing significant technical weaknesses.
A software code audit examines the quality of the underlying implementation, including its architecture, coding practices, dependencies, error handling, testing and maintainability.
Assemblysoft looks for evidence of established engineering practices and identifies areas where changes may be unusually expensive, risky or difficult.
The assessment helps distinguish between software that simply works today and software that is reasonably structured to support future development.
No review can guarantee defect-free software, but an evidence-based assessment can substantially improve your understanding of its technical condition. See our .NET code and architecture audit.
Link to this answerA technical audit can identify security weaknesses within application architecture, source code, authentication, authorisation, dependencies and infrastructure configuration.
Assemblysoft can examine relevant security controls and assess whether engineering practices support secure development and operation.
Depending on the agreed scope, this may include reviewing access controls, secrets management, dependency vulnerabilities, data protection arrangements and security-related logging.
Findings are documented according to their potential impact and the evidence available.
A general software audit does not guarantee that every vulnerability will be discovered and is not a substitute for specialist penetration testing.
Where deeper security assurance is required, we can recommend additional assessment.
Link to this answerAn application that performs adequately today may encounter difficulties as customer numbers, transaction volumes, data storage or integration requirements increase.
Assemblysoft can assess the architecture, database design, infrastructure configuration and known performance constraints to identify potential scalability concerns.
We consider whether the system is appropriately structured for anticipated business growth and whether its infrastructure can be adapted efficiently.
Where historical performance data, monitoring information or test environments are available, these can provide additional evidence.
A technical review can identify scalability risks and recommend further testing, but reliable capacity predictions may require representative load testing and defined growth assumptions.
Link to this answerBusiness-critical applications should have appropriate arrangements for monitoring, incident response, backup, restoration and disaster recovery.
Assemblysoft can assess whether these arrangements exist, how they are configured and whether the available evidence supports the organisation's recovery expectations.
We review operational dependencies, monitoring, deployment processes, recovery documentation and potential single points of failure.
Where agreed, we can also evaluate evidence from previous recovery tests or recommend controlled restoration exercises.
The assessment helps organisations understand how prepared they are for disruption and which improvements should be prioritised. See our operational resilience and DevOps review.
Link to this answerOlder technology does not automatically mean that an application must be replaced.
However, unsupported frameworks, outdated libraries and ageing infrastructure can introduce security, compatibility, maintenance and recruitment challenges.
Assemblysoft can assess the technologies in use, identify relevant support constraints and evaluate the implications for ongoing operation.
For Microsoft-based applications, this may include reviewing .NET Framework, modern .NET, ASP.NET, SQL Server and Azure-related dependencies.
We can then recommend whether to maintain, upgrade, refactor, migrate or replace particular components.
The objective is to establish a proportionate modernisation strategy rather than assume that a complete rewrite is necessary. See our legacy software modernisation review.
Link to this answerHow an audit informs budgets, how long it takes, and what it means for the decision in front of you.
A software audit can provide a stronger technical basis for estimating future development, maintenance and modernisation expenditure.
By examining the architecture, codebase, infrastructure and dependencies, Assemblysoft can identify areas likely to require corrective work or additional investment.
Where sufficient evidence exists, we can provide indicative effort ranges, technical dependencies and implementation priorities.
However, a code review alone cannot establish a reliable fixed price for every future requirement.
Detailed estimates may require additional discovery, business requirements analysis, prototyping or investigation of particularly complex components.
Our objective is to reduce uncertainty and make future budgeting more informed.
Link to this answerA cloud infrastructure assessment can identify opportunities to improve cost efficiency.
For Microsoft Azure environments, Assemblysoft can review resource configuration, utilisation, hosting architecture, monitoring and relevant expenditure data.
We look for potentially unnecessary resources, inappropriate service tiers, inefficient architecture and opportunities to simplify infrastructure.
Recommendations consider reliability, performance, security and operational requirements alongside cost.
Actual savings depend on usage patterns, contractual arrangements and the changes ultimately implemented. See our Azure infrastructure assessment.
Link to this answerThe duration depends on the complexity of the application, the number of systems involved, the depth of assessment and the availability of technical information.
A focused technical health check may take several working days, while a comprehensive review of interconnected business-critical systems may require several weeks.
Most initial review activities can be conducted using read-only access, documentation, interviews and existing engineering evidence.
Where testing or configuration changes could affect a live environment, these should be separately agreed and appropriately controlled.
Assemblysoft establishes the assessment scope, access arrangements and expected timescales before work begins.
Link to this answerYes. Where this is the agreed objective, the assessment can provide a reasoned recommendation based on the available technical evidence and business requirements.
Assemblysoft considers the application's condition, technical debt, architecture, dependencies, operational risks and suitability for future development.
Possible recommendations include retaining the existing system, targeted remediation, phased modernisation, platform migration or replacement.
We explain the advantages, disadvantages, dependencies and uncertainties associated with the principal options.
The aim is to support a proportionate business decision rather than recommend redevelopment unnecessarily.
Link to this answerWhat you receive, what happens if information is missing, and what comes after the report.
Yes. Incomplete documentation is a common reason for commissioning a software audit.
Where source code, infrastructure access and relevant technical stakeholders are available, it may be possible to reconstruct a useful understanding of the application's architecture and operating requirements.
Assemblysoft can examine code repositories, configuration, databases, integrations, deployment pipelines and other technical evidence.
We identify missing documentation and areas where knowledge appears concentrated within individuals or suppliers.
Any conclusions that cannot be adequately verified are clearly identified in the report.
Link to this answerThe agreed deliverables typically include an executive assessment, detailed technical findings and prioritised recommendations.
The executive assessment explains the principal risks and their potential implications for business continuity, investment and future development.
The technical report documents material findings, supporting evidence, potential impact, recommended action and any limitations in the assessment.
A prioritised roadmap identifies immediate concerns, planned improvements and areas requiring additional investigation.
Assemblysoft can also present the findings in a stakeholder workshop, allowing business owners and technical teams to discuss the results and agree appropriate next steps. See an anonymised sample report built from synthetic findings.
Link to this answerYes. Assemblysoft can provide further technical consultancy, remediation, modernisation, development and application support services where required.
Following the audit, we can help turn the recommendations into a structured programme of work, including technical priorities, dependencies, implementation phases and delivery estimates.
This may involve improving code quality, modernising .NET applications, optimising Azure infrastructure, strengthening DevOps processes or preparing software for transition to a new support provider through managed application support.
Any subsequent implementation engagement is separately scoped and agreed.
The audit findings remain available for your own engineering team or another supplier to use. There is no obligation to appoint Assemblysoft to perform the recommended work.
Link to this answerWhether you're acquiring a software business, replacing a development supplier or planning the future of an existing application, Assemblysoft can help you understand the technical risks before making a significant commitment.
Discuss Your Software Audit Requirements See a Sample ReportCyber Essentials Plus certified · NDA as standard · UK-based team · Microsoft Partner · No obligation to appoint us for remediation