Software Architecture & Technical Due Diligence
Independent review of codebases, vendors and architectures before you invest, buy or build.
Before a large technology decision, you need an opinion from someone with nothing to gain. We review codebases, architectures and vendor proposals and tell you plainly what is sound, what is risky and what it would cost to fix.
The same service supports investors and acquirers who need to understand the technology behind a company, and leadership teams who want an independent view of what they have built.
- We are willing to say don't build, don't buy or don't migrate when that is the right answer.
- Findings come with effort estimates, so the report supports a decision rather than delaying one.
- Reviewers are practising engineers who ship software, not auditors reading a checklist.
- An acquirer or investor who needs to understand the technology behind a target before signing.
- A group deciding whether to extend, replace or retire a core platform that several businesses depend on.
- A board facing a large vendor proposal with no independent view of it.
- A major build or buy decision is due and every opinion in the room has a stake.
- Key-person risk sits with one or two engineers nobody has spoken to.
- The vendor's proposal is the only architecture document that exists.
- A platform is described as legacy without anyone having measured what that costs.
What is included.
- 01
Codebase review
Quality, test coverage, security, dependencies and maintainability assessed with tooling and reading.
- 02
Architecture review
Scalability, resilience, cost and fit against the roadmap.
- 03
Team and process review
How software is built, released and supported, and where the key-person risk sits.
- 04
Vendor evaluation
Proposals compared on fit, total cost, lock-in and exit path.
- 05
Recommendations
A scorecard, risk register and prioritised actions with effort estimates.
Four steps, no surprises.
- 01
Brief
Agree the decision at stake and what evidence would change it.
- 02
Examine
Code, infrastructure, documentation and interviews with the team.
- 03
Score
Findings rated by severity and effort against your priorities.
- 04
Advise
Written report and a working session to talk through the options.
From first meeting to steady state.
- 01Week 1
Brief
The decision at stake agreed, along with the evidence that would change it and the access required.
- 02Weeks 2 to 3
Examine
Code, infrastructure, documentation and interviews with the team, under NDA and in a read-only environment.
- 03Week 4
Score and advise
Findings rated by severity and effort, a written report and a working session on the options.
- Decision reached within the agreed window with the evidence documented.
- Risks identified before signing rather than discovered after.
- Remediation effort estimated against effort later spent.
- Vendor terms improved on the points the review raised.
- Principal architect
- Senior engineers for the stacks in scope
- Security reviewer
- Engagement director
- Technical scorecard.
- Risk register with severity and effort.
- Architecture assessment.
- Vendor comparison where relevant.
- Recommendations and decision memo.
Reviews are fixed scope and take one to four weeks depending on codebase size and access. Larger due diligence for acquisitions is scoped after a short call. Follow-up advisory time is available as a light retainer.
IT Strategy & vCIO
Fractional CIO leadership that aligns technology spend and roadmap with what the business is trying to do.
Web, Webshop & App DevelopmentWeb Applications & SaaS Platforms
Custom portals, dashboards and multi-tenant SaaS with authentication, billing and admin built in.
CybersecurityPenetration Testing (Web, API, Mobile)
Manual, adversary-style testing of applications and their business logic, with a retest included.
Software Architecture & Technical Due Diligence, in plain terms.
For a codebase review, yes, under NDA and in a read-only environment you control. For vendor evaluation we work from proposals, demos and reference calls.
Our reviewers cover the mainstream stacks. For unusual technology we bring in a specialist and say so.
For investment decisions, for prioritising a remediation plan, for negotiating with a vendor or simply for knowing where you stand.
Yes. The most valuable reviews often end with a recommendation to stop something.