Software audit, code review and technical due diligence
A software audit shows you what state your software is in. I go through the code, the database, the hosting and the deployments. Then I write down what is solid, what is risky and what should be fixed first. That works for an app your own team built, one an agency delivered, and one built with AI tools.
I'm all in on AI, so I get through a large codebase fast. I stay careful with every finding, because you will make decisions based on the report. I work with companies that have no developer of their own and with teams that want a second, more experienced opinion.
I usually reply within one working day.
What an audit covers
At the end you get a written report.
Code quality and structure
How the code is organized, where changes are hard, and which parts need tests before anyone touches them.
Security
Logins, permissions, separate data per customer, passwords and keys in the code, and outdated packages with known problems.
Database and performance
Slow queries, missing indexes, and the parts that will struggle as data and users grow.
Hosting, deployments and backups
How the app goes live, whether the backups can be restored, and what happens when a server fails.
AI-generated code review
Apps built with Cursor, Lovable, Bolt or Claude Code often work in a demo and break in daily use. I check what has to be fixed before customers and their data go in.
Technical due diligence
Before an investment or an acquisition. What the software is worth technically, who can maintain it, and what running and changing it will cost.
How I work
You don't need to have everything figured out before we talk. An idea, access to the repo, a screen recording or a list of problems is enough. I look at what is there, tell you what I would do and what it costs, and then I build it.
I use Claude Code, Codex and my own agent workflows for reading code, planning changes, writing tests, refactoring and debugging. It is not vibe coding. It is senior engineering with a much faster loop.
AI-first, checked by me
Claude Code and Codex help me map a large codebase quickly: what calls what, where the data goes, and where tests are missing. I check every finding in the code myself before it goes into the report.
I stay in control
AI writes a lot of my code. I still make every technical decision, read every change before it ships, and test it. Fast, but meticulous: the speed is only worth something if what goes live is right.
The way you want to work
Some clients want to look at every change before it goes live, others want me to deploy. Some want a weekly call, most prefer written updates. I work well asynchronously, and I still ask the important questions when they come up.
I think like an owner
I still run my own online products. So when I build or fix yours, I think about traffic, conversion, revenue and support as much as about the code, and I tell you when something is not worth building.
Ways to work with me
Fixed price, a flat monthly rate, or hourly. It's always me doing the work, not an agency. If you're not sure, describe what you need and I'll suggest one.
Examples of my work
Software I had to understand and judge before I changed it.
Taking over a messy legacy app
A product configurator with many variants, pricing rules and dependencies. I had to understand how the rules fit together before I could extend it without breaking existing configurations.
Access rules and integrations checked and cleaned up
In a live healthcare SaaS I replaced permission bypasses with explicit memberships and checked tenant separation, OAuth logins and webhooks. Appointments and billing kept running the whole time.
An inherited Laravel 5 app
I took over a slow real estate website with outdated packages and an unreliable Salesforce sync. I found the bottlenecks and upgraded it step by step to Laravel 11.
What clients say
"We especially value how quickly he gets into mature projects and finds solutions that fit the existing state of the codebase."
"Vincent is one of those rare developers who can jump into a complex codebase, become useful immediately, and solve real problems without hand-holding."
"What stood out about working with Vincent was how methodical and efficient he was."
Questions
What do I get at the end?
A written report. It lists what works, what is risky, and what I would fix first. Your developers can work from it, and so can I.
Can you review an app built with AI tools?
Yes. Apps built with Cursor, Lovable, Bolt or Claude Code often look fine at first. The problems usually sit in security, data handling and the parts nobody tested.
Do you also fix what you find?
If you want. Some clients hand the report to their own team. Others ask me to do the work.
Is an audit useful before buying or investing in a company?
Yes. Technical due diligence tells you what the software is, who can maintain it, and what changes will cost. I write it so a buyer without a technical background can follow it.
Which technologies do you audit?
Laravel and PHP most of all, plus web apps in Vue, React, Node.js, Python and Go. If I can't judge something well, I tell you before we start.
How do you charge?
Fixed price for a job with a clear outcome, a flat monthly rate for ongoing work, or hourly. Describe what you need and I'll suggest one.
Get a quote
What the software does, who built it, and why you want an audit now. A few sentences are enough. I'll reply with what I would look at and what it would cost.
If you would rather talk first, book a 30-minute call or email contact@vincentschmalbach.com.