Skip to main content

Software architecture

Architecture and code audit

An independent audit that delivers facts, measurements and a priority order. You know what threatens your system, what it really costs and what to fix first.

What it covers

A useful audit does more than list defects: it ranks them by risk and effort. I combine code reading, static analysis, performance measurements and team interviews to separate real problems from theoretical worries.

The scope is agreed with you at kick-off: security, performance, maintainability, resilience or compliance. Every finding is tied to a concrete scenario — a traffic spike, a component failure, a change of business rule — so that the fix decision becomes straightforward.

A report you can use the following Monday

The final report is a ten-page summary plus detailed appendices. Fixes are grouped into immediate actions, planned work and watch items, each with an effort estimate.

  • Static analysis and targeted review of risk areas.
  • Performance measurements on representative scenarios.
  • Verification of error handling, retries and idempotency.
  • Review of authentication and authorisation mechanisms.
  • Dependency and known-vulnerability review.

Problems addressed

  • Incidents repeat without an identified root cause.
  • Technical debt is mentioned in every meeting but never quantified.
  • A compliance requirement demands an independent technical review.
  • You are taking over a system built by another supplier and lack landmarks.
  • Response times degrade as data volume grows.

Expected benefits

  • An independent, argued and verifiable opinion.
  • Prioritisation by risk rather than technical preference.
  • Effort estimates to arbitrate your maintenance budget.
  • Evidence you can use with your management or an external auditor.
  • A method your teams can reuse on their own.
  • No dependency on a vendor or proprietary tool.

Method and steps

  1. 1

    Framing

    Half a day to set the scope, evaluation criteria, required access and the restitution date.

  2. 2

    Investigation

    Analysis of code, configuration, logs and existing tests, completed by interviews with developers and operations.

  3. 3

    Targeted checks

    Load scenarios, application security tests and failure simulations on an isolated environment.

  4. 4

    Restitution

    Presentation of findings ranked by risk, discussion of trade-offs and delivery of the report with an estimated action plan.

Deliverables

  • Ten-page decision-oriented summary.

  • Register of findings with evidence, risk and estimated effort.

  • Recommendations grouped into immediate, planned and watched actions.

  • Baseline indicators to measure progress after remediation.

  • Verbal restitution and a question-and-answer session with your teams.

Technologies used

  • Java
  • Spring Boot
  • PostgreSQL
  • Kubernetes
  • OpenTelemetry
  • JUnit 5
  • SonarQube

Frequently asked questions

Does the audit require full code access?

Read access to the repository is required for a serious audit. If the code cannot leave your infrastructure, I can work on site or in your remote development environment.

Does an audit always lead to a rewrite?

No, and that is rarely the outcome. Most audits end with a list of targeted fixes and a few architecture decisions, at a fraction of the cost of a rewrite.

Can you implement the fixes afterwards?

Yes, either directly or by supporting your teams. The audit remains valuable either way: it provides the prioritisation baseline and the tracking indicators.

Request an audit quote

Send me the context and the intended scope. I reply within two business days with a proportional audit proposal.

Request an audit quote