Independent tech audit with measurable output
Architecture, code, security and performance review in two weeks. No 80-page PDF at the end — a prioritised backlog with concrete next steps.
When
When an audit pays for itself
Feature delivery is slowing
New features now take six weeks instead of two because there are knots in the codebase. The team can't tell you why.
Security is unclear
No one has reviewed CSP, dependencies or secret rotation. The last pen-test was three years ago.
You're inheriting the code
A new team or partner is coming in and needs the real state — not the marketing version.
Investor or acquirer asks
Due diligence needs an independent tech opinion: concrete findings, not hand-waving.
Process
How we work
Kickoff
One-hour call: scope, access, risks. You get the audit plan back the same day.
Deep dive
Five to eight days of codebase review, infrastructure, monitoring and dependency audit. We work quietly.
Findings
Prioritised backlog: P0 (security), P1 (architecture), P2 (DX), P3 (nice-to-have). Each estimated.
Walkthrough
90-minute handover via Loom or live call. Your team asks questions, we answer.
Output
What you get at audit close
- Architecture review document (15-25 pages) with diagrams
- Prioritised findings backlog in Notion or Jira-export format
- Security report covering OWASP Top 10 and dependency CVE list
- Performance benchmark: Lighthouse, Core Web Vitals, bundle-size analysis
- 30-minute walkthrough recorded on Loom — replay any time
- 30-day follow-up: a one-hour review call one month after delivery
Tooling
Audit stack
Proven, industry-standard tools — no experimental tooling.
- Lighthouse
- Snyk
- SonarQube
- OWASP ZAP
- GitHub CodeQL
- Bundle Analyzer
- k6
- Sentry
- Dependabot
Timeline
Typical audit cycle
Phase 01
Kickoff
1 day
Scope, access, NDA in place.
Phase 02
Deep dive
5-8 days
Active audit work independent from your team.
Phase 03
Walkthrough
1 day
Handover plus a 90-minute live Q&A.
Pricing
Fixed-price audit packages
Every package is fixed-price with a pre-agreed scope. No T&M overrun.
Quick audit
€0,0
2 weeks
One application on one platform. SMB-scale codebase (<50k LoC).
- Architecture review
- Top-10 findings
- 30-minute walkthrough
Full audit
from €0,0
3 weeks
Multiple applications or enterprise scope. Deep security and performance review.
- Architecture + security + perf
- Full findings backlog
- 90-minute walkthrough
- 30-day follow-up
Continuous
on request
monthly retainer
Quarterly audit plus monthly check-in. We watch the codebase with you.
- Quarterly audit
- Two-hour monthly review
- Slack priority queue
FAQ
Frequently asked
30-minute audit call
After a 30-minute call we'll know whether an audit fits your situation and which package makes sense.