Support · Code audits

Code audits

You inherited a codebase from a previous vendor, a freelancer who's now unreachable, or a founder-engineer who's left. You don't know whether the security is sound, the architecture is sane, or the cost-to-fix is ₹2 lakh or ₹50 lakh. The vendor pitching the rebuild has a strong opinion. You need an independent one.

We audit the codebase against a written checklist (architecture, security, data handling, deploy pipeline, dependency hygiene, bus factor) and deliver a markdown report you can show your CFO, board, or investor. With fix-cost estimates against each item.

Typical timeline · 1–2 weeks
Inside the build

What's actually included.

Architecture review

Is the system structured to handle next year's load and feature set, or will the next feature require a rewrite? Concrete examples, not abstract concerns.

Security review

Auth, authorization, session handling, secrets management, input validation, OWASP Top 10. Findings ranked by severity (critical / high / medium / low / informational).

Data handling

How is sensitive data stored, transmitted, logged? Are backups working? Is GDPR / DPDP exposure manageable?

Deploy + ops

How are releases shipped, rolled back, monitored? What breaks at 2am and who gets paged? Is the runbook real or aspirational?

Dependencies

Outdated packages, abandoned libraries, license risks, transitive vulnerabilities. With a 'remediation budget' estimate.

Bus factor

Could one engineer leaving cause a six-month freeze? What's documented vs. tribal? What needs to be captured before the next handover.

Who this is for

Founders evaluating a rebuild pitch, CFOs evaluating an acquisition target's tech, IT leaders inheriting a codebase from a previous vendor, and engineering leaders preparing for a security audit, fundraising round, or compliance certification.

How we work

Three stages, no surprises.

01

Discovery

A 30-minute call to map the workflow that's actually broken. We walk you through what we'd build, what we wouldn't, and a written scope with timeline and milestones.

02

Weekly sprints

Working prototype by week 2, MVP in staging by week 4–6. Friday demo every week: you see it before it's done, not after. Slack channel + Linear / Jira board you have access to.

03

Handover + retainer

Go-live with a written playbook, training material per role, and a 30-day office-hours window. Most clients move onto a maintenance retainer for the work that comes after.

Ready to start

Walk us through what's broken.
We'll come back with a plan.

A 30-minute discovery call, free, no deck. We map your workflow, flag what's worth fixing first, and outline a scope with timeline and effort.