Consultancy
Software consulting that gives you independent technical oversight
If a vendor is building your software and no one on your side can read the code, you are relying on trust alone. We review code, security and delivery practice, and represent your interests while work is underway.
Troubled projects show warning signs early
Demos that keep slipping. Defects that return after being fixed. Each feature taking longer than the last. A vendor unable to account for time spent. These usually trace to the same causes: weak testing, no coherent architecture, unclear scope, or an under-resourced team.
We identify which, quickly. Sometimes the remedy is better process with the same vendor. Sometimes part of the codebase must be rewritten. Occasionally the honest recommendation is to stop and restart with a narrower scope. In every case, you will know precisely where you stand.
What we build
What the engagement covers
Code review
Structure, readability, test coverage, dependency health and maintainability, with findings ranked by their likely future cost.
Security review
Authentication, access control, data handling and common web vulnerabilities, assessed against the OWASP Top 10.
Project recovery
An assessment of a late or stalled project and a concrete plan to deliver, re-scope or stop it.
Vendor oversight
We attend reviews, examine pull requests and releases, and report in plain language whether the work is on track.
Exit and handover readiness
Before a vendor exits, we ensure you hold the code, credentials, documentation and knowledge needed to continue.
How we work
How a review is conducted
Step 1: Access and context
Repository and environment access, project documentation and a conversation with the team that built the system.
Step 2: Technical review
Hands-on review of code, infrastructure and delivery process, typically over one to two weeks.
Step 3: Findings ranked by risk
Each issue explained in business terms, with its potential cost and urgency.
Step 4: Remediation plan
A recovery or improvement plan with effort estimates, executable by your current vendor, your team or us.
Deliverables and tools
Deliverables and technology
What you receive
- Review report ranked by risk
- Executive summary in plain language
- Recovery or improvement plan with estimates
- Optional monthly oversight reports
- Handover checklist for vendor transitions
Stacks we review
- JavaScript and TypeScript (React, Node.js)
- PHP and Laravel
- Python
- React Native, Flutter, Kotlin and Swift apps
- MySQL and PostgreSQL
- AWS and common hosting configurations
Engagement model
Reviews are fixed-fee and usually take one to three weeks depending on codebase size. Ongoing vendor oversight runs on a modest monthly retainer, typically a few hours a week.
Often paired with IT consultancy for a focused second opinion.
FAQ
Questions about software consulting
Our vendor may resist an external review. How do you manage that?
We frame it as a review of the project, not of individuals. Capable vendors generally welcome it. We share findings with them before the final report so they can respond.
Can you review a system without access to the source code?
Only partially. We can assess the running application and infrastructure externally, but recovering the source code is usually the first priority, and we can help you request it properly.
Will you take over the project afterwards?
Only if you ask us to. Many reviews conclude with the existing vendor continuing under a clearer plan.
Explore
Other consultancy services
Concerned about a project that is drifting?
Describe what you are observing. A short call is usually enough to judge whether a review is warranted.