Audit & rescue
For systems that are slow, unstable or failing security checks — and nobody's sure why.
What you get
- Performance and architecture review
- OWASP and SonarQube security fixes
- A written report with a priority list
The system is slow, crashes at the worst moment or failed a security check — and nobody is quite sure why. I find out, fix what is urgent and leave you a clear plan for the rest.
What I look at
- Performance: slow pages and queries, memory and CPU, caching and database indexes.
- Reliability: errors in the logs, failing background jobs, single points of failure, and backups you can actually restore.
- Security: the OWASP Top 10, dependencies with known vulnerabilities, secrets in the code and SonarQube findings.
- Code and architecture: what makes changes risky, and what to tidy first.
What you get
A written report in plain language, with every problem ranked by impact and effort — and the urgent fixes already done while the audit runs, not only at the end. If you want, I then work through the list with your team or on my own.
A good fit if…
- your app slows down as users grow, or goes down under load;
- a customer, an auditor or a penetration test flagged security issues you need to close;
- you inherited a codebase and need to know what you are dealing with before you plan the next year.
Questions
How long does an audit take?
One to two weeks for most systems. You get the urgent fixes during that time, not only at the end.
Do I need to give you access to production?
Read-only access to the code, logs and metrics is usually enough. Anything that touches production is agreed with you first.
Have a project in mind?
Tell me what you're building. You'll get an answer within a day, even if it's "not a fit".