All services

Code Audit & Technical Due Diligence

You paid a freelancer or an agency and you have no way to judge what you received. Or you are about to acquire a product and the seller's technical claims are unverified. We review the codebase as a neutral third party and give you a plain-English verdict backed by specific evidence: what is real, what is missing, what it will cost to fix, and whether you should accept the handover.

This is you if

  • A final invoice is due and you have no way to judge whether the work is finished
  • The developer says it is done; the product says otherwise
  • You are acquiring a product and the seller's technical claims are unverified
  • Your team inherited a codebase and cannot estimate anything in it
  • An investor has asked for technical due diligence and you have nothing to show them
  • You suspect corners were cut but cannot point at where

If none of these describe your situation, this is probably the wrong service. The other service lines may fit better, and a consulting session is the cheapest way to find out.

What's included

  • Independent review: we are not the team that wrote it and have no stake in the verdict
  • Security review of authentication, authorization, secret handling, dependencies and data exposure
  • Verification that the delivered code matches what was actually contracted and demoed
  • Assessment of test coverage, deployment, backups and whether anyone else could maintain it
  • Remediation estimate in hours and money, split into must-fix, should-fix and cosmetic
  • Plain-English report you can put in front of a developer, a lawyer or an investor

Typical stack

Static analysisDependency scanningArchitecture reviewManual review

What you get

  • A defensible answer to whether you got what you paid for
  • Negotiating leverage grounded in evidence rather than suspicion
  • A prioritised fix list your existing developer can start on Monday

How the engagement runs

  1. Access and scope, day 1

    Read access to the repository, the contract or specification it was built against, and a short call on what you actually need answered.

  2. Review, days 2–7

    Static analysis and dependency scanning to find the mechanical problems, then manual review of the parts that decide whether the thing is sound.

  3. Report and walkthrough, days 8–10

    The written report, then a call where we walk you through it in language you can repeat to someone else without us in the room.

What you walk away with

  • A plain-English verdict you can put in front of a lawyer, an investor or the developer themselves
  • Findings ranked must-fix, should-fix and cosmetic, each with the file and the evidence
  • A remediation estimate in hours and money, so the number is negotiable rather than emotional
  • A security assessment covering authentication, authorization, secrets, dependencies and data exposure
  • An answer to the maintainability question: could a competent stranger take this over, and at what cost

What this does not cover

  • Fixing what we find — the audit stays independent, and we quote remediation separately if you want it
  • Legal opinion on your contract; we establish the technical facts your lawyer then argues from
  • Penetration testing of live infrastructure, which is a separate engagement with its own authorisations

Naming the exclusions up front is cheaper for both of us than discovering them in week six.

How to start

Reviewed 2026-09-09. Figures in USD, excluding tax.

Code audit & technical due diligence

From $6,500

5–10 working days, scoped before it starts

A final invoice is due and you cannot judge whether the work is finished, or you are about to acquire a product whose technical claims nobody has verified.

If it goes wrong

Independent by design. We did not write the code and we quote any remediation separately and afterwards, so the verdict is never an advertisement for our own next engagement.

Why not next quarter: Leverage disappears the moment you pay the final invoice. An audit costs a fraction of the invoice and is the only thing that turns a suspicion into a position you can argue from.

Every offer, side by side

Before you ask

How do I know whether the developer I already hired did a good job?
Commission an independent code audit from someone who did not write the code. We review the repository as a neutral third party and give you a plain-English verdict: whether the delivered work matches what was contracted, what security and maintenance risks exist, and what remediation would cost in hours and money. Clients most often order this before paying a final invoice or before an acquisition.
Can you review the work of my current agency without replacing them?
Yes, and this is the point of the fractional CTO retainer. We sit on your side of the table as your technical counterpart: reviewing what your existing team ships, joining planning calls, setting written engineering standards, and reporting monthly on delivery health and risk. You keep the team you have. You stop having to take their word for it.
Read every answer

Two ways to start, both of them cheap.

Book a call and talk it through, or write the problem down and send it — whichever you would actually do today. Either way you get a reply from an engineer within one business day, and an honest answer about whether we are a fit.

Not ready for either? A $600 consulting session buys one straight answer with no obligation to hire us.

Rev. 01Book a call