Services · The software review
Find out what you actually own.
An independent, fixed-fee review of your software, the developer or agency who built it, and your ability to operate without them — delivered in about 10 business days.
What was promised, delivered, and redone. We line up contracts, tickets, invoices and code, and separate what shipped from what was built twice.
What you can run without the original team. We count the parts only they can reach, so you know what changing teams would actually cost.
Where AI writes the code. We check whether the time saved survives review and testing — or just piles up rework.
You get one recommendation — keep and improve, switch providers, bring it in-house, or outsource less — with evidence you and your board can check together.
Five documents your board can act on.
Written for a non-technical reader, with a full technical appendix for whoever needs it.
Executive brief
Two pages, plain English, one recommendation.
Independence checklist
18 binary checks. Pass or fail. No interpretation required.
Full technical assessment
Every claim traceable to evidence, for your CTO or advisor.
Remediation roadmap
Ranked by risk, with effort estimates. What to fix, in what order.
Transition risk model
What it would actually cost, in time and money, to change teams.
Delivery record
What was promised, billed, and actually delivered — side by side.
Ten things we examine, the same way every time.
Systematic, not one consultant’s impression — so two reviews a year apart are comparable.
How much of the volume is real, maintained work.
Who actually built it, and AI’s share of the work.
How many parts only your vendor can reach.
Keys and passwords left where they shouldn’t be.
What stands between a bad change and your customers.
Whether shortcuts are tracked or quietly piling up.
How many people actually understand each part.
Whether you could get it back after an outage.
Whether it holds as the business grows.
What it would take to move to another team.
Most reviews produce opinions. This one produces counts.
Opinions get argued with. Counts and pass/fail checks don’t. We run them on infrastructure you control — not your vendor’s.
Can you build and run it yourself?
On infrastructure you control, from a clean start — yes or no.
How many parts does one outside party hold?
A single count of what only your vendor can reach.
How well protected are the workflows you get paid through?
The count of automated tests on the paths that make you money.
How long to operate without them?
A number, in money and months, with its assumptions shown.
Clone from your own account, private dependencies resolve, third-party installs run clean.
Backend and frontend build, checks pass, the environment starts healthy.
Migrations run, schema tooling works, seed data applies.
App loads, login works, core views, exports and notifications all function.
The documented deploy runs in a test environment, and a rollback works without the vendor.
See it before you buy it.
One page of a real review, redacted. Evidence — not a severity list.
The only option that’s fast, fixed-fee, and on your side.
| This review | Due-diligence firm | Another dev shop | Internal review | |
|---|---|---|---|---|
| Turnaround | ~10 days | 6–8 weeks | Varies | Ongoing |
| Cost | Fixed fee | Much higher | “Free” | Staff time |
| Independent of the outcome | Yes | Yes | No — wants the work | No |
| Written for a board | Yes | For investors | No | Rarely |
Four steps. Ten business days.
Scoping call
30 minutes. We confirm fit and tell you honestly if you don’t need this.
Access
Read access to the code and a short list of documents. We tell you exactly what’s needed.
Analysis
Automated collection plus expert review. No disruption to your team.
Readout
The brief, the full report, and a 60-minute session with your leadership.
Nothing in the report is an opinion.
You pay the same fixed fee whether we find one problem or forty, and every finding is a count or a pass/fail check you can reproduce. There’s nothing in it we could inflate.
Before you commit.
What access do you need — and what if my vendor controls the repository?
Does my development team have to know?
What if you find that everything is fine?
Do you fix what you find?
How is this different from a security review?
Find out what you actually own.
Send a few nonconfidential lines about the decision you’re weighing — we’ll tell you what we’d want checked first.
No call needed · Fixed fee · We never sell you the fix
