Service
Code audit: an independent review of your software
A code audit is an independent review of your codebase and the way it is built. I read the code, the architecture and the setup around it, then give you a plain-English report: what is solid, what is risky, and what to fix first, with a 90-day plan.
When you need a code audit
- You're about to raise money and investors will run technical due diligence.
- You're taking over code from an agency or freelancer, or about to switch.
- Releases keep slipping, bugs keep coming back, and you can't tell why.
- Someone is telling you the product needs a rewrite.
- You're hiring your first in-house developers and want to know what they inherit.
- Your app was built with an AI tool and is about to get real users.
What gets checked
- Code quality
- Can another developer pick this up, or does it only work while the current team stays?
- Architecture
- Will it hold up as users, data and features grow? What will be expensive to change later?
- Security basics
- Are passwords, payments, personal data and access keys handled the way they should be?
- Infrastructure
- Who controls the servers, domains and accounts? What happens if something goes down?
- Tests and releases
- How does a change get from a developer to your users, and what stops it breaking things?
- Team and process
- Is your agency or team set up to deliver what you are paying for? Who knows what?
What you get
- A written report in plain English. Every finding is ranked: fix now, fix soon, or leave alone. Technical details sit in an appendix for your developers.
- A 90-day plan: what to do first, what it roughly costs in effort, and what can safely wait.
- A call to walk through it, so you can ask everything you need to before you act on it.
How it works
- Free 20-minute call. What you're building, who builds it, and what worries you. I'll tell you if an audit is the right tool.
- Fixed scope and price. Agreed in writing before I start, along with the delivery date.
- Review. Read-only access to the code and setup, plus a conversation with your lead developer or agency if useful.
- Report and walkthrough. You get the report, then we go through it together.
Why independent matters
I don't sell development. An agency that audits your code has a reason to find a rewrite; I don't. If the code is fine, the report will say so, and you'll have paid for peace of mind rather than a sales pitch.
After the audit, some founders want ongoing help to act on the plan. That's what the fractional CTO engagement is for. You may not need it.
Questions founders ask
- Is a code audit the same as technical due diligence?
- They overlap. Technical due diligence is what an investor or buyer runs on your company before a deal. A code audit is the same kind of review done for you, before anyone else looks, so you can fix the worst problems and explain the rest on your own terms.
- Will my developers or agency be offended?
- Good developers expect their work to be reviewed; it's how engineering teams work anyway. I review the code, not the people, and the report says what is done well as clearly as what isn't. If a team refuses any outside review, that is useful information too.
- Does the audit include penetration testing?
- No. I review security the way a senior engineer would when reading the code and the setup: obvious holes, risky practices, exposed secrets. If your product handles sensitive data and needs a formal penetration test, the report will say so.
- What access do you need?
- Read-only access to the code repositories, a look at how hosting and deployment are set up, and ideally a short conversation with whoever leads development. I'm happy to sign an NDA before seeing anything.
- What technologies do you review?
- Tell me your stack in your first message. If it's outside what I know well, I'll say so before we start rather than after.
- How much does a code audit cost?
- It's a fixed price, agreed before I start. It depends on the size of the codebase, how many separate services or apps there are, and whether team interviews are included. I quote after a free 20-minute call.
Want to know what's really in your codebase?
Tell me what you're building and who builds it. I'll tell you whether an audit is worth it for you, and if not, what to do instead.
Ask for a free 20-minute call