Code audit and second opinion

An outside review of your Rails codebase, or of a proposal you have been given, written up in plain language so you can decide what to do next.

When a second opinion helps

You have a quote for a new system and no way to judge whether it is reasonable. Your vendor says the application needs a rewrite. Pages that used to load in a second now take five. You are about to buy a company whose product is a Rails application.

In each case the question is the same: what is actually in the code, and how much will it cost to live with? We answer that from the outside, without assuming we will do the follow-up work.

We wrote about this kind of review on our blog: a second opinion on development projects (in Japanese).

What we look at

  • Security: authentication, authorisation, mass assignment, injection, secrets in the repository, outdated gems with known vulnerabilities (Brakeman and bundler-audit, then a manual read)
  • Performance: N+1 queries, missing indexes, slow endpoints, background job design
  • Upgrade risk: how far behind Rails and Ruby are, and what blocks the next upgrade
  • Tests: what is covered, what is not, and whether the tests would catch a real regression
  • Code health: where changes are expensive and why

What you get

A written report in English or Japanese, ordered by risk, with an estimate for each fix, and a call to go through it. For a second opinion on a proposal, a shorter memo with the questions to put to the vendor.

Pricing

Prices in US dollars, before tax. A price marked "from" is the minimum; we agree a fixed price before we start, and invoices in yen are fine.

Second opinion

$500

fixed price, a few days

We review a quote, a technical proposal or an architecture plan from another vendor and tell you what looks right, what looks risky and what questions to ask.

Code audit

from $1,500

fixed price, about one week

A review of your Rails application: security, performance, dependencies, test coverage, upgrade risk and code health, with a prioritised list of fixes.

Frequently Asked Questions

Who is this for?
Companies that depend on a Rails application but do not have a senior Rails developer in-house: before buying a company or a codebase, before signing a large development contract, or when an application has become slow or hard to change.
What do we need to give you?
Read access to the repository, and for performance questions, access to logs or an APM tool. We sign an NDA before we look at anything.
Will you fix the problems you find?
If you want us to, yes, but the report is written so that any competent Rails team can act on it. You are not buying a sales pitch.
Can you review a non-Rails proposal?
For web applications in general, yes. If a vendor proposes a stack we do not know well, we will say so in the report.

Tell us about your project

Send a few lines about your application and what you need. We reply within two business days, in English or Japanese, with next steps and a rough estimate.