The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
An independent .NET code audit and software architecture review examines how a C# application is really built: its structure, dependencies, error handling, tests and engineering practices. You get evidence-based findings, ranked by business impact, from engineers who build and support .NET systems for a living.
Synthetic example. Your audit is scoped to your question.
A .NET code audit is a structured, evidence-based review of a C# codebase and the architecture around it. It answers a practical question: could a competent engineering team maintain, extend and secure this application at a reasonable cost? It covers ASP.NET, ASP.NET Core, Blazor, Web API, WinForms, WPF, worker services and the SQL Server or Azure data stores behind them.
It is part of Assemblysoft's software audit and technical due diligence practice and can run on its own or as part of a comprehensive audit.
Every release breaks something else, estimates keep growing, and nobody can explain why simple features take weeks.
An independent view of what an agency or contractor has delivered, at a milestone, at sign-off, or before a renewal.
Establish whether another team can realistically understand, build and extend the code before you change supplier.
Code produced quickly, by AI tools or under deadline pressure, that now carries real users and real data.
Layering, separation of concerns, coupling, domain boundaries and whether the design matches what the business now needs.
Duplication, complexity hot-spots, dead code, naming and consistency, with material debt separated from cosmetic issues.
NuGet and npm packages, framework versions, end-of-support components and known vulnerable libraries.
What is tested and what is not, whether the solution builds cleanly from source, and how reliable the tests are.
Exception handling, logging, telemetry and whether failures are visible before users report them.
Authentication, authorisation, input validation, secrets handling and data access patterns, framed against OWASP ASVS requirements.
Scope, access and timescales are agreed before work begins. Anything that could affect a live environment is agreed separately and controlled.
We agree the question the audit must answer, the repositories in scope and read-only access arrangements.
Static analysis, dependency and vulnerability scanning, then senior engineers read the code that matters most to the business.
We attempt a clean build and test run from source, the strongest evidence of whether a new team could take over.
Findings ranked by impact and effort, with recommendations and a walkthrough for technical and non-technical stakeholders.
See how findings are presented in our anonymised sample report.
| Area | Supporting authority | How it shapes the audit |
|---|---|---|
| Application security review and verification | Application Security Verification Standard (ASVS)OWASP Foundation | Frames application security findings as verifiable requirements across authentication, access control, input handling and data protection, rather than a superficial vulnerability scan. |
| Secure development practices and software acquisition | Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology | Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software. |
These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.
An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.
We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.
Due-diligence questionsRepository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.
Information securityWorking copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.
Data residencyAssemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.
Visit the Trust CentreWhere personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.
.NET Framework 2.0 to 4.8.1 and modern .NET up to .NET 10, including ASP.NET Web Forms, MVC, ASP.NET Core, Blazor, Web API, WCF, WinForms, WPF, .NET MAUI, worker services and Azure Functions, together with SQL Server and Azure data stores.
Automated analysis is used to cover breadth quickly: static analysis, dependency and vulnerability scanning, complexity metrics. AI-assisted tools help us map unfamiliar code faster. Every material finding is verified by a senior engineer before it reaches the report, because tools produce false positives and miss context.
No. The audit uses read-only access. Where a build or test run is useful as evidence, it happens in an isolated environment and is agreed in advance.
Yes. AI-generated code is assessed in exactly the same way as hand-written code, with particular attention to security, validation, duplicated logic and missing tests. If it needs stabilising, see our vibe coding rescue service.
It depends on the size of the codebase, the number of systems and the depth required, so we scope it first and confirm the price before work starts. Our day rates are published on the rate card.
One evidence-based method, applied to the decision in front of you. Each specialist assessment can run on its own or as part of a comprehensive audit.
An independent review of C# and .NET code quality, architecture, dependencies, tests and maintainability.
Tell us which application, what decision is riding on it and how much access you can provide. We will scope a proportionate audit and confirm timescales before any work begins.
Discuss Your Requirements All Software Audit ServicesCyber Essentials Plus certified · NDA as standard · UK-based team · Microsoft Partner · No obligation to appoint us for remediation