Code audit: an independent view of your software
We review an application's code, database, hosting and release process and give you a written report in plain English: what state it is in, where the risks are and what we would do about them.
At a glance
- Price
- £1,950 fixed
- Typical duration
- 1 to 2 weeks
- VAT
- Prices exclude VAT
Why commission an audit
Most people responsible for a business system cannot see inside it. They know whether it works today. They do not know whether the code can still be built, whether last night’s backup would restore, or whether the database it runs on stopped receiving security fixes two years ago.
An audit answers those questions. It is most useful at a decision point: before changing supplier, after a key developer leaves, when weighing further investment against replacement, or when someone outside the business needs assurance.
What makes it useful
The report is written to be acted on. Each finding states what we observed, why it matters to the business, and what we recommend, with a sense of size. Findings are ordered by priority, so the three things that need attention this quarter are not buried among thirty that do not.
You can read a sample audit report, written for a fictional company, to see the format before you commission one.
We also say what is good. A system that is sound and merely unfashionable should be kept, and a report that says so can save a costly and unnecessary replacement.
After the audit
Some clients take the report to their existing team. Others ask us to deal with the priority items, take the system over or plan a staged modernisation. If you do go on to work with us, the audit fee is credited against the first piece of follow-on work.
Talk to us
Describe the system and what you need. You will hear back from someone who can answer technical questions.
Discuss this project 0800 433 7990What the report covers
- Can it be built and released?
- Whether the application can be built from the source code you hold, and how a change reaches production.
- Support status of everything it depends on
- Each framework, database, server and library, with its vendor support date.
- Security
- Known vulnerabilities in dependencies, how credentials are stored, how users are authenticated and how data is protected.
- Code quality and structure
- How hard the code is to change safely, where the complexity is concentrated, and whether there are tests.
- Database
- Design, size, growth and the queries most likely to cause performance problems.
- Backups and recovery
- What is backed up, whether a restore has been tested, and how long recovery would take.
- Ownership and access
- Who controls the code, servers, domains and accounts, and what is in an individual's name.
- Options and priorities
- What we would fix first, what can wait, and whether the system should be maintained, modernised or replaced.
How the audit runs
A short call
You tell us what the system does and what prompted the audit, so the report answers your questions.
Access
You give us read access to the source code and, where possible, to the hosting environment and database.
Review
We build the code, run automated analysis and read the parts that matter by hand.
Report
A written report with a summary for decision-makers and the technical detail behind it.
Walk-through
A call to go through the findings and answer questions.
What moves the price
- Size of the codebase and the number of separate applications.
- Whether we can access the hosting environment and database as well as the code.
- Unusual or mixed technology that needs extra investigation.
Not included
- Fixing the issues found. Those are quoted separately once you have decided what to act on.
- Penetration testing.
- Legal advice on contracts or licences.
A good fit when
- You are about to change supplier and want to know what you are handing over.
- You have inherited a system and need to know its condition.
- You are deciding whether to keep investing in a system or replace it.
- A buyer, investor or insurer has asked for an independent technical view.
Probably not for you if
- You need a formal penetration test or a compliance certification; those are specialist services and we can point you to providers.
- You have no access to the source code.
Questions we are asked
Is the audit fee deducted if we go on to work with you?
Yes. If you commission follow-on work from us, the audit fee is credited against the first piece of that work.
Do we have to use CodeFirst for the work afterwards?
No. The report is yours and is written so that any competent team could act on it.
Will the audit disturb the live system?
No. We work from a copy of the code and, where we look at production, with read-only access.
Can we see what the report looks like?
Yes. We publish a sample report written for a fictional company, so you can judge the format and the level of detail before commissioning one.
How technical is the report?
It opens with a summary a non-technical director can act on. The detail behind each finding follows for whoever does the work.
Our current supplier will not be pleased. Can it be done discreetly?
Yes, provided you hold your own copy of the source code. We do not need to contact the supplier.
What happens to our code after the audit?
We work under a confidentiality agreement and delete our copy when the engagement ends, unless you ask us to keep it for follow-on work.
Tell us about your system
Say what it does, what it is built on and what is worrying you. We will reply with what we would look at first and whether we are the right people to help.