The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
An operational resilience and DevOps review tests the arrangements that keep a business-critical application running: monitoring, incident response, backup and restore, disaster recovery and the pipelines that ship changes safely.
Synthetic example. Your audit is scoped to your question.
An operational resilience review establishes whether an application can be monitored, recovered and changed safely. It compares the organisation's recovery expectations with the evidence that exists, including backups, restore tests, runbooks and deployment pipelines, and prioritises the gaps.
It is part of Assemblysoft's software audit and technical due diligence practice and can run on its own or as part of a comprehensive audit.
Something went wrong, recovery took longer than expected and you want to know why.
Questions about RTO, RPO, backups and incident response that you cannot yet answer with evidence.
Releases depend on one person, a checklist and a quiet evening.
A tool that started small now underpins revenue or operations.
Application Insights, Azure Monitor, logs and alerts: would you know about a failure before your users?
Who is called, how severity is judged, how incidents are recorded and how root causes are removed.
What is backed up, where it is stored, how long it is kept and whether restores have ever been tested.
Recovery time and recovery point expectations compared with what the architecture can actually deliver.
Build and release pipelines, test gates, approvals, rollback and environment parity.
People, services, credentials and infrastructure whose loss would stop the application.
Scope, access and timescales are agreed before work begins. Anything that could affect a live environment is agreed separately and controlled.
We record how long the business can tolerate an outage and how much data it can afford to lose.
Monitoring, alerts, backup policies, pipelines, runbooks and incident history examined.
Optionally, a restore to an isolated environment to prove backups can be recovered.
Gaps between expectation and evidence, prioritised by business impact.
See how findings are presented in our anonymised sample report.
| Area | Supporting authority | How it shapes the audit |
|---|---|---|
| Cloud reliability, security, cost and operational maturity | Azure Well-Architected FrameworkMicrosoft | Structures Azure workload assessment around its five pillars: reliability, security, cost optimisation, operational excellence and performance efficiency. |
| Secure development practices and software acquisition | Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology | Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software. |
These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.
An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.
We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.
Due-diligence questionsRepository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.
Information securityWorking copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.
Data residencyAssemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.
Visit the Trust CentreWhere personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.
Recovery time objective (RTO) is how long the business can tolerate the application being unavailable. Recovery point objective (RPO) is how much recent data it can afford to lose. The review compares both with what your backups and architecture can really deliver.
No. Where a restore test is agreed, it is carried out into an isolated environment so production is not affected.
No. We review Azure DevOps, GitHub Actions and other pipeline tooling, as well as manual release processes where no pipeline exists.
Yes, through managed application support, which includes monitoring, incident and problem management and verified backups. There is no obligation to use us.
One evidence-based method, applied to the decision in front of you. Each specialist assessment can run on its own or as part of a comprehensive audit.
Monitoring, backup, disaster recovery, deployment pipelines and incident readiness for business-critical applications.
Tell us which application matters most and how long the business could cope without it. We will scope a review that tests the evidence, not just the paperwork.
Discuss Your Requirements All Software Audit ServicesCyber Essentials Plus certified · NDA as standard · UK-based team · Microsoft Partner · No obligation to appoint us for remediation