All services

Start Here

Codebase Rescue & Audit

You find out exactly what you own, what it's worth, and what it costs to finish.

Typical engagement2–4 weeks

What this engagement is

A vendor disappeared. A contractor left without documentation. A build ran twice as long as quoted and stopped. In every case the first question is the same and nobody can answer it: what actually works? Before you can decide whether to finish, rebuild, or walk away, you need a factual answer — and the code is the only place it exists.

We get the system building and running in an environment we control, then audit it against a fixed checklist: code quality, dependencies and their known vulnerabilities, security posture, data model, infrastructure, and the gap between what was promised and what exists. We verify claims by running the software, not by reading status decks.

The output is a written assessment a non-technical executive can act on and a technical one can verify: an inventory of what works, what's incomplete, and what's abandoned, plus three priced paths — finish, partial rebuild, replace — with our recommendation stated plainly and the reasoning behind it. If you engage us to continue, the audit converts directly into the scope document; nothing is billed twice.

Who this is for

  • Companies whose development partner has gone quiet or been let go
  • Buyers doing technical diligence on an acquisition
  • Internal teams who inherited a system nobody understands

What you get

  • Written audit covering code quality, security, and architecture
  • Verified inventory of what works, what's incomplete, and what's abandoned
  • Data model and infrastructure review
  • Cost-to-complete estimate against three options
  • Recovered build and deploy process, documented

Scope

Exactly what the quoted price covers

The scope document for this engagement lists both columns below in writing. Nothing moves between them without a conversation.

Included in the engagement

  • Getting the system to build, run, and deploy in a controlled environment
  • Dependency and known-vulnerability review
  • Security posture review: authentication, secrets handling, exposed surfaces
  • Data model and database review, including migration state
  • Three priced completion options with a written recommendation

Not included

  • Fixing what the audit finds — that's a follow-on engagement
  • Penetration testing by a certified security firm (we can refer one)
  • Legal review of vendor contracts or IP assignments

Working together

What we need from you

Fixed dates only hold when both sides show up. These are the commitments we ask for in exchange for ours.

  • 01

    All repositories, credentials, and documentation the previous vendor left behind

  • 02

    Access to hosting, cloud, and domain accounts

  • 03

    An hour with whoever knows what the system was supposed to do

Process

How it runs

  1. 01

    Recover and run

    We get the system building and running in an environment we control. This alone answers a surprising number of questions.

  2. 02

    Audit

    Code, dependencies, security posture, data model, and infrastructure reviewed against a fixed checklist.

  3. 03

    Options and costs

    Three paths priced — finish, partial rebuild, replace — with our recommendation and the reasoning stated plainly.

Also in Start Here

Scope a codebase rescue & audit engagement.

Send us the situation in a few sentences. You'll get a scope, a price, and a date back — or an honest no.