Design and load
Whether design choices hold up, where the bottlenecks are, and what happens when orders triple over Black Friday or the Christmas peak.
Suppose a Valencia haulier runs routes and delivery notes on an application written seven years ago by a freelance developer who has not been heard from in a year. It works, but nobody dares change it, the server is on an unsupported PHP release, and invoices come out of the same program, which now ought to meet Verifactu rules. We go in with read-only access to a system we did not build and answer three things: will it cope with what is coming, could a different team look after it, and what would it cost to put right.
Judgement rests on criteria agreed in advance rather than on taste: capacity, ease of maintenance, security, and whether the system would survive its one expert leaving.
Whether design choices hold up, where the bottlenecks are, and what happens when orders triple over Black Friday or the Christmas peak.
Readability, automated tests, copy-pasted logic, the route a fix takes to production, and whether any documentation would help a newcomer.
Abandoned libraries, packages with published vulnerabilities, runtimes and frameworks whose vendor support has ended.
Links to a3ERP, Sage or Holded, Redsys card payments and Bizum, SEUR, MRW or Correos Express labels. We focus on behaviour when the remote service errors or stops answering.
Where the software issues invoices, we check whether it records, chains and retains entries as the invoicing systems regulation requires, or list what must change.
Where servers and customer data sit, what the processor agreements say, and whether the set-up would stand up to an AEPD inspection.
Could a newcomer pick it up, or is everything held in one developer's memory and a repository under their personal login?
You get a duration before work begins; it depends on how large the application is and how many systems it talks to. Access is read-only throughout.
An acquisition, a supplier change, Verifactu preparation or a plain risk check. That purpose decides where we dig deepest and how much detail you receive.
Code, any documentation, the hosting dashboard, logs and the ticket backlog. Video calls with the people who run it fill the gaps that were only ever passed on by word of mouth.
Criteria are scored one by one, and each issue is paired with what it means for day-to-day operations.
Report ranked from most to least serious, a cost estimate per fix, and a walk-through together on Teams or Google Meet.
Messy code is rarely the scariest discovery. Clumsy software can keep a business running for ten years. The real danger is a single person who understands it and no documentation anywhere, which leaves you bargaining from weakness every time the contract comes up. We flag that dependency separately, whatever the technical quality elsewhere.
Yes, within limits. We can test behaviour and speed, inspect public-facing configuration, study the database if you have access, read error logs and go through contracts and invoices. Anything we could not confirm is listed openly. Not having your own code is itself a risk worth recording, so check the intellectual property clause in your agreement.
Yes. Our focus is anything that moves the price: bundled open source licences, the size of the technical debt, key-person dependence and the cost of operating the product once the deal closes. Your lawyers handle the legal side and we work to their deadlines.
We test its technical behaviour against the regulation and give you a list of gaps. The formal statement of conformity comes from the software producer, not from us, and tax questions are best settled with your accountant.
For a medium-sized system, allow between one and three weeks, more if it connects to many other services. Our rate is €75 per hour + VAT; alternatively we quote a fixed fee after a first video meeting that settles the scope.
We will say so and show why, costing both paths: fixing it step by step versus building afresh. You decide, but with figures in hand instead of gut feeling.
Give us a short outline of the application and what prompted the review. The report you receive puts the most serious risks at the top.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.