IT consulting

We review the code, architecture and security settings of your existing software or infrastructure, give the findings in writing and produce a prioritized improvement plan. The review can be a one-time job; if you want, we also take on carrying out the plan separately.

Scope

What is included

Every project has a different scope; the quote lists each included item one by one.

Last updated:

  • Code and architecture review with a written list of findings
  • A check of security settings and access limits
  • An assessment of dependencies, backups and monitoring
  • A prioritized improvement plan
  • A review meeting to present the report and answer your questions

Preparation

What we ask from you

  • Read access to the code and environment to be reviewed
  • A description of the problem that bothers you most
  • A few short conversations with someone who knows the system

Process

With your approval at every step.

  1. 01

    Scope and access

    We settle in writing what will be reviewed and which access is needed.

  2. 02

    Review

    We read the code, architecture, settings and operations; we make no changes to the live system.

  3. 03

    Findings report

    We give the findings in writing in order of importance, with evidence.

  4. 04

    Improvement plan

    We present a plan with what to do first, rough effort and risk, and answer your questions.

Details

About the service

When consulting helps

Sometimes the problem is not clear: the system has slowed down but nobody knows why, the team that wrote the old software has left, preparation is needed before a security audit, or you want to know whether the existing code is sound before starting new development. In such cases, reviewing first is cheaper than starting to write directly. The output of this service is not code but a written report that explains what should be done and why. When we hand over the report, we read the findings with you and answer your questions.

What we look at

  • Code and architecture: Structure, dependencies, test status, repeated and fragile parts.
  • Security settings: Access permissions, password and key management, dependencies with known vulnerabilities, services exposed to the outside.
  • Operations: Whether a backup exists and can be restored, whether monitoring and logging are sufficient, whether there is an update routine.
  • Maintainability: How quickly a newcomer can understand the code and whether documentation exists.

How we work

We start with read access; we make no changes to the live system. We write each finding with a severity and with evidence showing why it is so: which file, which setting, the output of which command. That way you can also hand the report to another team and verify the findings. We then produce an improvement plan in order of severity and write rough effort and risk for each item.

The limit of the report

This is not a penetration test or a formal security audit, and it does not produce a compliance certificate. The review is limited by the access given and the time set aside, and the report states clearly what we looked at and what we did not. We do not say any system is flawless; the report is meant to bring you closer to an informed decision. Sometimes the findings reassure you: the system may turn out sounder than you thought, and we write that too. Sometimes they show early a risk that can still be closed cheaply; both make deciding easier.

Afterwards

Your own team can carry out the plan, another company can do it or, if you wish, we can take it on; whichever it is, the report is yours. If we are to make the fixes, the scope is written again and every change that touches the live system is released with your approval.

What determines time and price

Price and time depend on the size of the code base, the number of technologies in use, the number of environments to review, the state of documentation and tests, the need for meetings and how detailed the report will be. We first write the scope after a short meeting and prepare the quote from it; the quote does not commit you.

If the software needs to be reworked after the review, custom software development comes in; if regular server-side maintenance is needed, see hosting and maintenance.

Pricing

The price is settled in a written quote

Because it depends on the scope, we do not write this service's price on the page. Tell us what you want; we will send the scope and price line by line in writing. A quote does not commit you.

FAQ

Frequently asked questions

Is this a security audit?

No. We review security settings; this is not a penetration test or a formal audit. In the report we write what we looked at and what we did not.

Do you touch the live system?

Not during the review; we work with read access. If fixes are to be made, a separate scope is written and applied with your approval.

Who owns the report?

You do. You can share the report with another team and have the plan carried out by whoever you like.

How is the confidentiality of our code protected?

We use access only with the people who need it and for as long as needed. Confidentiality terms are settled in writing before work begins.

Can you do a one-time review?

Yes. The review and report can be quoted as a job on its own.

Let us send you the scope in writing.

A quote does not commit you; we settle the scope together and price it line by line.

Get a quote