Software audit

Software audit, code review and technical due diligence

A software audit shows you what state your software is in. I go through the code, the database, the hosting and the deployments. Then I write down what is solid, what is risky and what should be fixed first. That works for an app your own team built, one an agency delivered, and one built with AI tools.

I'm all in on AI, so I get through a large codebase fast. I stay careful with every finding, because you will make decisions based on the report. I work with companies that have no developer of their own and with teams that want a second, more experienced opinion.

I usually reply within one working day.

Vincent Schmalbach

What an audit covers

At the end you get a written report.

Code quality and structure

How the code is organized, where changes are hard, and which parts need tests before anyone touches them.

Security

Logins, permissions, separate data per customer, passwords and keys in the code, and outdated packages with known problems.

Database and performance

Slow queries, missing indexes, and the parts that will struggle as data and users grow.

Hosting, deployments and backups

How the app goes live, whether the backups can be restored, and what happens when a server fails.

AI-generated code review

Apps built with Cursor, Lovable, Bolt or Claude Code often work in a demo and break in daily use. I check what has to be fixed before customers and their data go in.

Technical due diligence

Before an investment or an acquisition. What the software is worth technically, who can maintain it, and what running and changing it will cost.

How I work

You don't need to have everything figured out before we talk. An idea, access to the repo, a screen recording or a list of problems is enough. I look at what is there, tell you what I would do and what it costs, and then I build it.

I use Claude Code, Codex and my own agent workflows for reading code, planning changes, writing tests, refactoring and debugging. It is not vibe coding. It is senior engineering with a much faster loop.

AI-first, checked by me

Claude Code and Codex help me map a large codebase quickly: what calls what, where the data goes, and where tests are missing. I check every finding in the code myself before it goes into the report.

I stay in control

AI writes a lot of my code. I still make every technical decision, read every change before it ships, and test it. Fast, but meticulous: the speed is only worth something if what goes live is right.

The way you want to work

Some clients want to look at every change before it goes live, others want me to deploy. Some want a weekly call, most prefer written updates. I work well asynchronously, and I still ask the important questions when they come up.

I think like an owner

I still run my own online products. So when I build or fix yours, I think about traffic, conversion, revenue and support as much as about the code, and I tell you when something is not worth building.

Examples of my work

Software I had to understand and judge before I changed it.

Industrial configurator

Taking over a messy legacy app

A product configurator with many variants, pricing rules and dependencies. I had to understand how the rules fit together before I could extend it without breaking existing configurations.

Healthcare SaaS

Access rules and integrations checked and cleaned up

In a live healthcare SaaS I replaced permission bypasses with explicit memberships and checked tenant separation, OAuth logins and webhooks. Appointments and billing kept running the whole time.

Real estate platform

An inherited Laravel 5 app

I took over a slow real estate website with outdated packages and an unreliable Salesforce sync. I found the bottlenecks and upgraded it step by step to Laravel 11.

What clients say

"We especially value how quickly he gets into mature projects and finds solutions that fit the existing state of the codebase."

Florian Brunner, designundzwanzig OG

"Vincent is one of those rare developers who can jump into a complex codebase, become useful immediately, and solve real problems without hand-holding."

Yash Chandra, Academy of Mine

"What stood out about working with Vincent was how methodical and efficient he was."

Philipp Toepelmann, Digital Investments GmbH

Questions

What do I get at the end?

A written report. It lists what works, what is risky, and what I would fix first. Your developers can work from it, and so can I.

Can you review an app built with AI tools?

Yes. Apps built with Cursor, Lovable, Bolt or Claude Code often look fine at first. The problems usually sit in security, data handling and the parts nobody tested.

Do you also fix what you find?

If you want. Some clients hand the report to their own team. Others ask me to do the work.

Is an audit useful before buying or investing in a company?

Yes. Technical due diligence tells you what the software is, who can maintain it, and what changes will cost. I write it so a buyer without a technical background can follow it.

Which technologies do you audit?

Laravel and PHP most of all, plus web apps in Vue, React, Node.js, Python and Go. If I can't judge something well, I tell you before we start.

How do you charge?

Fixed price for a job with a clear outcome, a flat monthly rate for ongoing work, or hourly. Describe what you need and I'll suggest one.

Get a quote

What the software does, who built it, and why you want an audit now. A few sentences are enough. I'll reply with what I would look at and what it would cost.

If you would rather talk first, book a 30-minute call or email contact@vincentschmalbach.com.

I usually reply within one working day.