Read-only access
Read-only repository and infrastructure access; NDA in place before any code is touched.
An outside read on your stack from senior engineers — architecture, security, performance, and operational risk — delivered as a written report plus a walkthrough.
Full-stack codebase and security review with a written report and a 60-min walkthrough.
Every deliverable below is included in the scoped engagement — no upsell at handoff.
The same four-step flow we use across every engagement, scoped to this gig.
Read-only repository and infrastructure access; NDA in place before any code is touched.
Senior engineers spend 3–4 days reading code, running tools, and probing for issues.
Findings drafted into a single report with severity and evidence for each.
60-min session with your team plus written answers to follow-up questions.
The stack we default to for codebase audit work. Always open to fitting yours.
Three reasons clients pick Hepha Works for codebase audit.
The person who scopes the work is the person who delivers it. No invisible subcontractors, no junior handoffs.
You see a written scope and a number before any work starts. No timesheet surprises, no scope-creep arguments.
We won't say it'll work if we don't think it will. If the gig isn't right for your situation, we'll tell you that on the call.
The questions we get most before kicking off codebase audit engagements.
No — this is a code and architecture audit. We can recommend pentesting partners if needed.
The audit doesn't include implementation. We can scope a remediation engagement separately.
Senior engineers only — 10+ years building and operating production systems.
Yes — tech DD for acquirers is a frequent use case. We'll structure the report for that audience.
No — the audit is explicitly an outside read, not a replacement. Reports are written to be useful to your team, not to flatter us.
Other gigs that pair well with Codebase Audit.
Send a brief and we'll come back with a written scope and a number within 1–2 business days.