Software architecture
Architecture and code audit
An independent audit that delivers facts, measurements and a priority order. You know what threatens your system, what it really costs and what to fix first.
What it covers
A useful audit does more than list defects: it ranks them by risk and effort. I combine code reading, static analysis, performance measurements and team interviews to separate real problems from theoretical worries.
The scope is agreed with you at kick-off: security, performance, maintainability, resilience or compliance. Every finding is tied to a concrete scenario — a traffic spike, a component failure, a change of business rule — so that the fix decision becomes straightforward.
A report you can use the following Monday
The final report is a ten-page summary plus detailed appendices. Fixes are grouped into immediate actions, planned work and watch items, each with an effort estimate.
- Static analysis and targeted review of risk areas.
- Performance measurements on representative scenarios.
- Verification of error handling, retries and idempotency.
- Review of authentication and authorisation mechanisms.
- Dependency and known-vulnerability review.
Problems addressed
Incidents repeat without an identified root cause. Technical debt is mentioned in every meeting but never quantified. A compliance requirement demands an independent technical review. You are taking over a system built by another supplier and lack landmarks. Response times degrade as data volume grows.
Expected benefits
An independent, argued and verifiable opinion. Prioritisation by risk rather than technical preference. Effort estimates to arbitrate your maintenance budget. Evidence you can use with your management or an external auditor. A method your teams can reuse on their own. No dependency on a vendor or proprietary tool.
Method and steps
- 1
Framing
Half a day to set the scope, evaluation criteria, required access and the restitution date.
- 2
Investigation
Analysis of code, configuration, logs and existing tests, completed by interviews with developers and operations.
- 3
Targeted checks
Load scenarios, application security tests and failure simulations on an isolated environment.
- 4
Restitution
Presentation of findings ranked by risk, discussion of trade-offs and delivery of the report with an estimated action plan.
Deliverables
Ten-page decision-oriented summary.
Register of findings with evidence, risk and estimated effort.
Recommendations grouped into immediate, planned and watched actions.
Baseline indicators to measure progress after remediation.
Verbal restitution and a question-and-answer session with your teams.
Technologies used
- Java
- Spring Boot
- PostgreSQL
- Kubernetes
- OpenTelemetry
- JUnit 5
- SonarQube
Frequently asked questions
Does the audit require full code access?
Read access to the repository is required for a serious audit. If the code cannot leave your infrastructure, I can work on site or in your remote development environment.
Does an audit always lead to a rewrite?
No, and that is rarely the outcome. Most audits end with a list of targeted fixes and a few architecture decisions, at a fraction of the cost of a rewrite.
Can you implement the fixes afterwards?
Yes, either directly or by supporting your teams. The audit remains valuable either way: it provides the prioritisation baseline and the tracking indicators.
Request an audit quote
Send me the context and the intended scope. I reply within two business days with a proportional audit proposal.