Service · IT advisory and audit

Systems and architecture review

Consider a construction company in Klagenfurt whose site diary and time-recording app was built eight years ago by a small agency that has since closed. Site managers log hours and photos on tablets, and the data flows into payroll every night. The system works, yet nobody dares to change it any more. The server runs a PHP release that no longer receives security fixes, and management wants to extend the app with defect reports and per-site drawings. Before anyone spends money on that, an independent assessment is worthwhile. We obtain read access to a system we did not write and answer three questions. Can it carry what is planned? Could another team take it over? And what would it cost to put it in order?

Independent
we did not write this code
Read-only
repository, logs, consoles
Technical debt
priced in euros plus VAT
Report
readable without a computer science degree

Everything this covers

Assessment follows criteria agreed in advance, not personal taste: capacity, maintainability, security, operations and whether the system could survive without the people who built it.

Settle the details with an engineer

Architecture and data flow

How data travels from the tablet on site to payroll, where it is buffered along the way and what happens when the connection drops halfway.

Code quality and tests

Readability, structure, automated tests, duplicated code and whether a new developer could be productive within a week.

Dependencies and life cycle

Unmaintained libraries, packages with published vulnerabilities, PHP, Node.js or framework versions past end of support, each with the date from which it becomes critical.

Integrations under pressure

Links to BMD or Business Central, to payment providers such as Stripe or eps and to parcel carriers. Above all, we look at what happens when the other side returns an error or stops responding altogether.

Operations and delivery

How a change gets from a laptop into production, whether backups, monitoring and logs exist, and who would be alerted in the middle of the night.

Data protection and hosting

Where servers and personal data reside, whether data processing agreements are in place and whether GDPR erasure and access requests can technically be fulfilled at all.

Receipts and cash registers

If the software issues invoices or receipts for cash sales, we examine technically how it handles numbering, retention and, where relevant, the link to a certified cash register. The tax assessment itself stays with your tax adviser.

Our working method

How long it runs is estimated up front, based on codebase size and how many external systems are attached. At no point do we hold write permissions.

01

Clarifying the trigger

Acquiring a company, changing supplier, a planned extension or simply an uneasy feeling. The reason determines where we look closely and how deep the report goes.

02

Material and conversations

Repository, documentation, hosting console, logs and open tickets, plus video calls with the people who use or maintain the system daily. A great deal was never written down.

03

Criteria-based review

Each criterion is scored separately, and every finding is explained in terms of what it means for the business.

04

Report and options

Findings ranked by severity, with an estimated cost for each fix and, where it makes sense, two routes: gradual repair or a rebuild. Discussed with you on Teams or Google Meet.

Who actually owns the code? Surprisingly often the repository sits in the former developer's personal account, the server is paid for on his credit card and the contract is silent on usage rights. As long as that remains the case, you negotiate every change from a weak position. We therefore clarify access and ownership at the very start and, where anything is unclear, recommend speaking to your lawyer before more money goes into the system.

Frequently asked questions

Very little. We need read access, one or two hours of architecture walkthrough and a way to ask follow-up questions by chat or video. Day-to-day development carries on undisturbed.

No, and it should not come across that way. Independent review is standard practice in other fields, such as the formal handover of a building. We assess objectively, name strengths as well as weaknesses and suggest going through the report together with the supplier.

Yes, as the technical strand of a due diligence exercise. We focus on what affects the purchase price: open source licences inside the product, accumulated legacy issues, knowledge concentrated in a few heads and running costs after the deal. The legal review sits with your law firm, and we fit in with its timetable.

For a typical line-of-business application, plan on roughly one to three weeks; the number of interfaces is what stretches it. After an initial video call and once the scope is defined, you receive a quote based on €110 per hour plus VAT.

Then the report says so, with its reasoning and with separate estimates for gradual refurbishment and for a rebuild. Often a middle path is wisest: replace the critical parts, stabilise and document the rest.

Get a second opinion on your system

Outline what the software does and what prompted the question. The report you get back ranks every risk, starting with whatever could hurt you most.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.