Code Audit and Remediation

Code that runs is not the same as code that is correct. We audit what you have, fix what is dangerous first, and set up the review process and test coverage that keep it from drifting again.

What we've learned so far

Every codebase accumulates debt. It used to happen slowly, through a hundred reasonable decisions made under deadline, and it now happens in weeks when a model does most of the typing. The speed is different. The underlying problem is not. In both cases the gap is between code that runs and code that is correct, and closing it takes someone who has reviewed enough complex systems to see what is missing rather than what is there.

What gets left out is consistent. Authentication that holds when someone actively tries to break it. Validation on every path rather than the obvious ones. Fallbacks for when a dependency is unavailable. Secrets kept out of the repository. Errors that fail safely instead of returning the database structure. Tests, so the next change does not quietly undo the last. Data handling that would survive a regulatory question. None of this is difficult to add. It is difficult to notice, because it is absent rather than wrong, and nothing in the product tells you it is not there.

The same applies in reverse. On a codebase that was written carefully, AI is a fast way to pay down debt, provided it works inside the existing conventions rather than importing its own. Point it at a well-structured system with clear rules and it will hold the line. Point it at an unclear one and it will confidently make things worse.

So the work has two halves. Fix what is there, in the order of what is actually dangerous. Then set up the rules, the review gates and the test coverage that stop it recurring, so the next hundred changes come out better than the last hundred did.

What this can involve

Reviewing security and compliance

Checking authentication, validation, secrets handling and data flows against how the application would actually be attacked or audited.

Code Refactoring and Technical Debt

Pay down the debt slowing delivery, without stopping delivery.

AI-assisted Code Review

Catch defects earlier while keeping human judgement on every merge.

Automated Testing Services

Test suites in Jest, Cypress and Playwright that run on every commit.

Technical Discovery

Assess the existing stack before committing to a direction.

How we work

Read the codebase

We go through what is actually there, not what the documentation claims, and find the parts the rest of the system depends on.

Identify gaps and vulnerabilities

Security gaps, missing validation, absent fallbacks and exposed secrets, ranked so you know what is dangerous and what is merely untidy.

Document and plan delivery

How the system works and the rules new code has to follow, including how AI-generated code gets reviewed before it merges.

Fix according to prioritisation

The dangerous parts first, in small changes that can be reviewed and reversed. The application stays running throughout.

Build tests around what matters

Coverage on the paths that carry real consequences, so the next change cannot quietly undo this one.

Est. engagement duration:
15 to 40 working days
Avg. team size:
1 to 2 people

Where this isn't the right fit

If the code is inconsistent but nothing is slow and nothing is unsafe, this work will cost you money and change very little. Untidy is not the same as broken. If the product is still changing shape every week, wait until the direction settles, because test coverage around features that get deleted next month is budget spent twice.

If you have already decided on a rewrite, you want a build team rather than an audit, and we would rather say so than bill you for one first. If releases are slow because of handovers or approvals rather than the code, fixing the codebase will not help. And if a customer has asked for a formal security certificate, you need an accredited assessor. We can tell you what to fix and fix it, but we do not issue that paperwork.

Projects we've delivered

2024

Shopify Store with 3D Outfit Configurator

Retail and eCommerce
2021

Telemedicine App with AI Health Assistant

Healthcare and Wellbeing

Frequently asked questions

Do you fix accessibility issues or just report them?

Should we break our monolith into microservices?

Related services

A code audit before you build on it. Let's see what you inherited.