Service · IT consulting and audit

Systems and architecture review

Suppose a Valencia haulier runs routes and delivery notes on an application written seven years ago by a freelance developer who has not been heard from in a year. It works, but nobody dares change it, the server is on an unsupported PHP release, and invoices come out of the same program, which now ought to meet Verifactu rules. We go in with read-only access to a system we did not build and answer three things: will it cope with what is coming, could a different team look after it, and what would it cost to put right.

Impartial
the code is not ours
Read-only
access to code, logs, consoles
Technical debt
priced in euros + VAT
Report
clear to non-technical readers

What falls within the scope of this service

Judgement rests on criteria agreed in advance rather than on taste: capacity, ease of maintenance, security, and whether the system would survive its one expert leaving.

Pin down the details with one of our engineers

Design and load

Whether design choices hold up, where the bottlenecks are, and what happens when orders triple over Black Friday or the Christmas peak.

Code and tests

Readability, automated tests, copy-pasted logic, the route a fix takes to production, and whether any documentation would help a newcomer.

Third-party components

Abandoned libraries, packages with published vulnerabilities, runtimes and frameworks whose vendor support has ended.

Integrations

Links to a3ERP, Sage or Holded, Redsys card payments and Bizum, SEUR, MRW or Correos Express labels. We focus on behaviour when the remote service errors or stops answering.

Invoicing and Verifactu

Where the software issues invoices, we check whether it records, chains and retains entries as the invoicing systems regulation requires, or list what must change.

Servers and GDPR

Where servers and customer data sit, what the processor agreements say, and whether the set-up would stand up to an AEPD inspection.

Key-person risk

Could a newcomer pick it up, or is everything held in one developer's memory and a repository under their personal login?

How the engagement unfolds, one stage at a time

You get a duration before work begins; it depends on how large the application is and how many systems it talks to. Access is read-only throughout.

01

Why the review

An acquisition, a supplier change, Verifactu preparation or a plain risk check. That purpose decides where we dig deepest and how much detail you receive.

02

Access and material

Code, any documentation, the hosting dashboard, logs and the ticket backlog. Video calls with the people who run it fill the gaps that were only ever passed on by word of mouth.

03

Examination

Criteria are scored one by one, and each issue is paired with what it means for day-to-day operations.

04

Findings

Report ranked from most to least serious, a cost estimate per fix, and a walk-through together on Teams or Google Meet.

Messy code is rarely the scariest discovery. Clumsy software can keep a business running for ten years. The real danger is a single person who understands it and no documentation anywhere, which leaves you bargaining from weakness every time the contract comes up. We flag that dependency separately, whatever the technical quality elsewhere.

Common questions

Yes, within limits. We can test behaviour and speed, inspect public-facing configuration, study the database if you have access, read error logs and go through contracts and invoices. Anything we could not confirm is listed openly. Not having your own code is itself a risk worth recording, so check the intellectual property clause in your agreement.

Yes. Our focus is anything that moves the price: bundled open source licences, the size of the technical debt, key-person dependence and the cost of operating the product once the deal closes. Your lawyers handle the legal side and we work to their deadlines.

We test its technical behaviour against the regulation and give you a list of gaps. The formal statement of conformity comes from the software producer, not from us, and tax questions are best settled with your accountant.

For a medium-sized system, allow between one and three weeks, more if it connects to many other services. Our rate is €75 per hour + VAT; alternatively we quote a fixed fee after a first video meeting that settles the scope.

We will say so and show why, costing both paths: fixing it step by step versus building afresh. You decide, but with figures in hand instead of gut feeling.

Get a second opinion on your system

Give us a short outline of the application and what prompted the review. The report you receive puts the most serious risks at the top.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.