Acqualytics

Services · The software review

The software review

Find out what you actually own.

An independent, fixed-fee review of your software, the developer or agency who built it, and your ability to operate without them — delivered in about 10 business days.

What was promised, delivered, and redone. We line up contracts, tickets, invoices and code, and separate what shipped from what was built twice.

What you can run without the original team. We count the parts only they can reach, so you know what changing teams would actually cost.

Where AI writes the code. We check whether the time saved survives review and testing — or just piles up rework.

You get one recommendation — keep and improve, switch providers, bring it in-house, or outsource less — with evidence you and your board can check together.

What you get

Five documents your board can act on.

Written for a non-technical reader, with a full technical appendix for whoever needs it.

Executive brief

Two pages, plain English, one recommendation.

Independence checklist

18 binary checks. Pass or fail. No interpretation required.

Full technical assessment

Every claim traceable to evidence, for your CTO or advisor.

Remediation roadmap

Ranked by risk, with effort estimates. What to fix, in what order.

Transition risk model

What it would actually cost, in time and money, to change teams.

Delivery record

What was promised, billed, and actually delivered — side by side.

The method

Ten things we examine, the same way every time.

Systematic, not one consultant’s impression — so two reviews a year apart are comparable.

01
Scale & composition

How much of the volume is real, maintained work.

02
How the code was produced

Who actually built it, and AI’s share of the work.

03
Dependency & lock-in

How many parts only your vendor can reach.

04
Exposed secrets

Keys and passwords left where they shouldn’t be.

05
Testing & release control

What stands between a bad change and your customers.

06
Technical debt

Whether shortcuts are tracked or quietly piling up.

07
Key-person risk

How many people actually understand each part.

08
Infrastructure & recovery

Whether you could get it back after an outage.

09
Scalability & resilience

Whether it holds as the business grows.

10
Transition risk

What it would take to move to another team.

The signature test

Most reviews produce opinions. This one produces counts.

Opinions get argued with. Counts and pass/fail checks don’t. We run them on infrastructure you control — not your vendor’s.

Can you build and run it yourself?

On infrastructure you control, from a clean start — yes or no.

How many parts does one outside party hold?

A single count of what only your vendor can reach.

How well protected are the workflows you get paid through?

The count of automated tests on the paths that make you money.

How long to operate without them?

A number, in money and months, with its assumptions shown.

Access · 3

Clone from your own account, private dependencies resolve, third-party installs run clean.

Build · 4

Backend and frontend build, checks pass, the environment starts healthy.

Data · 3

Migrations run, schema tooling works, seed data applies.

Run · 6

App loads, login works, core views, exports and notifications all function.

Release · 2

The documented deploy runs in a test environment, and a rollback works without the vendor.

18binary checks, scored N of 18
The deliverable

See it before you buy it.

One page of a real review, redacted. Evidence — not a severity list.

Review · executive page Engagement 0412 · redacted
What you can run without the original team
8 you control 63 outside your control
What the last two years bought
$28KCost per feature shipped
41%Effort spent on rework
19/31Delivered vs promised
Risk by domain · tap any row
Why not the alternatives

The only option that’s fast, fixed-fee, and on your side.

This reviewDue-diligence firmAnother dev shopInternal review
Turnaround~10 days6–8 weeksVariesOngoing
CostFixed feeMuch higher“Free”Staff time
Independent of the outcomeYesYesNo — wants the workNo
Written for a boardYesFor investorsNoRarely
How it works

Four steps. Ten business days.

Step 01

Scoping call

30 minutes. We confirm fit and tell you honestly if you don’t need this.

Days 1–2

Access

Read access to the code and a short list of documents. We tell you exactly what’s needed.

Days 3–8

Analysis

Automated collection plus expert review. No disruption to your team.

Day 10

Readout

The brief, the full report, and a 60-minute session with your leadership.

Why you can trust it

Nothing in the report is an opinion.

You pay the same fixed fee whether we find one problem or forty, and every finding is a count or a pass/fail check you can reproduce. There’s nothing in it we could inflate.

Questions owners ask

Before you commit.

What access do you need — and what if my vendor controls the repository?
Read access to the code and a short list of documents. If your vendor won’t grant it, that refusal is itself a finding — and we write it up as one.
Does my development team have to know?
No. The review runs without disrupting them, though we usually recommend transparency.
What if you find that everything is fine?
Then you get an independent document saying so — worth having the next time your board asks.
Do you fix what you find?
Only if you ask, as a separate, optional engagement. The recommendation never depends on it, and you’re free to use anyone.
How is this different from a security review?
A security review asks whether attackers can get in. This asks whether you could build, run, and recover your software without the people who built it.

Find out what you actually own.

Send a few nonconfidential lines about the decision you’re weighing — we’ll tell you what we’d want checked first.

No call needed · Fixed fee · We never sell you the fix