Technical audit: the real state of your software
We independently review your system's code, infrastructure and dependencies, and deliver a report showing what to fix first.

Who it's for
For companies that need to know the state of a system before buying, inheriting or investing in it.
What it solves
- The supplier has left and nobody in the company knows how the system works inside.
- The team says everything must be rewritten, and the board has no way to judge it.
- The libraries are out of date and nobody knows which known flaws they carry.
- An investor or buyer has asked for a technical assessment before closing the deal.
What we do
- Code and architecture
- Structure, duplication, existing tests and the places where any change becomes a risk.
- Dependencies and licences
- Outdated libraries, publicly known security flaws and licences that could cause trouble.
- Infrastructure and releases
- How the system runs, how a new version reaches production and whether there is a way back.
- Data and backups
- Data model, slow queries, backups and whether anyone has ever tested a restore.
- Personal data
- Where personal data sits, who can access it and what ends up in logs.
- Brazilian specifics
- For example, CNPJ fields that only accept digits, now that a CNPJ can also contain letters.
What you get
- A findings report, each with severity, evidence and estimated effort
- A prioritised list of what to fix first and what can wait
- An inventory of the system's dependencies and licences
- An executive summary for decision-makers, without technical jargon
- A walkthrough of the findings for the technical team and the board
How we do it
Scope and access
We agree what the review covers and get read access to the code and environment.
Automated analysis
Static analysis and dependency tools run across the whole codebase.
Reading and interviews
Reading the critical parts and talking to the people who maintain the system.
Report
Findings with evidence, severity and a suggested order for fixing them.
Walkthrough
Discussing the findings with your team before any decision is made.
Technology examples
- SonarQube
- Semgrep
- Trivy
- OWASP Dependency-Check
- OpenTelemetry
- Git
Related services
FAQ
Does the audit include penetration testing?
No. A penetration test is separate work, done by independent specialists under formal authorisation. The audit points out security risks in the code and dependencies; ongoing work belongs to application security.
Will you fix what you find?
If you want, as separate work. The audit does not depend on it, and the report is written so that any team can carry out the fixes.
Do you need access to production?
Read access to the repository, the infrastructure configuration and the metrics is usually enough. Customer data does not need to leave your environment.
What decides the size of the audit?
The size of the codebase, how many systems and integrations are included and how deep you want us to go. We fix the scope before starting.
Write to Balkan
Talk to us about your project