IT audit

Know what to fix. And why it comes first.

An independent assessment of code, architecture and system operations. We combine systematic analysis with expert judgment and prioritise findings by their business impact.

When an audit helps

Before a decision, after an incident, during a handover.

An audit helps identify the causes of problems, assess modernisation risks or review software quality. We specialise in backend systems, distributed systems, telecommunications and cryptography. Before accepting an engagement, we check that we have the expertise needed to assess the system.

01

Code & documentation

We review code correctness, testability, dependencies and whether the documentation matches the system’s behaviour. We also audit code and documentation produced with AI assistance.

02

Architecture & project

Module boundaries, data flows, failure points, decisions and delivery risks. We assess whether the solution fits its purpose.

03

Security

Access control, authentication, password and key management, dependencies and infrastructure configuration. We agree on the testing scope before the review.

04

Performance

Application profiling, database queries, behaviour under load and infrastructure costs.

05

Delivery process

Code reviews, tests, deployment automation and incident handling. We look for process gaps that increase error risks.

06

Monitoring & operations

Metrics, logs, alerts and response procedures. We assess whether the team can detect and diagnose failures.

Engagement scope

A full audit or a focused review.

Format
A written report and results presentation, or a shorter advisory review with an agreed summary.
Timing
A full audit usually takes 3–6 weeks. Focused review timelines are agreed individually.
What we need
Access to the agreed code, documentation and diagnostic data, plus time with the team. We sign a non-disclosure agreement (NDA) before materials are shared.
Pricing
Depends on the number of systems, selected areas, available materials and level of detail required. We provide the scope, cost and schedule before work starts.
Deliverables

A report your team can act on.

The proposal defines the deliverables. A full audit includes the main report, prioritised findings, an architecture map, an executive summary and a results meeting.

For each finding, we provide evidence, explain the consequences and recommend next steps. We state which issues are confirmed and which need further investigation.

EXAMPLE AUDIT FINDING
RISK: HIGH TR / 01

Retrying a payment may create a duplicate order.

Observation
In this example, retrying a request after a lost response creates a new operation.
Impact
Risk of duplicate charges and manual complaint handling.
Recommendation
Introduce an idempotency key and a retry test.
Verification
A retried request returns the same operation result, including under concurrent requests.

This example was prepared for this page and is not from a client audit. A report also includes evidence, context and an estimate of the work needed to resolve the issue.

Process

We validate findings with your team.

  1. Scoping

    We agree on the goal, access to materials, schedule and confidentiality.

  2. Analysis

    We review code and documentation, using measurements and team interviews.

  3. Review of findings

    We discuss preliminary findings with the team to check that we understand how the system works.

  4. Report & discussion

    We deliver priorities, recommendations and a plan for further action.

Do we have to hire you for remediation?

No. Your team or another provider can implement the recommendations. If you ask us to make the fixes, we will agree on a separate scope and price.

Does the audit cover the whole system?

Only within the agreed scope. We can focus on a module, process, documentation or risk. The report states the review boundaries and access limitations.

What decision should the audit support?

In a free conversation, we discuss the goal and possible scope. You do not need to share code at this stage.

Let’s discuss an audit