Flagship product · fixed scope

The Bay Inspection

Before you ship it, inspect it. A fixed-scope examination of the whole system — not just the code — ending in a written report and a production readiness rating you can act on.

Why start here

A verdict, not a proposal.

Most consultancy engagements start with a discovery phase that quietly becomes the project. This doesn’t.

An inspection is bounded in scope, time and cost. At the end you own a document that stands on its own — useful whether we do the remediation, your team does it, or you decide the risk is acceptable and ship anyway. That last outcome is a legitimate result and we’ll tell you when we think it applies.

Inspection — at a glance
IN

Repository access, read-only

Plus a walkthrough of how it’s deployed and what it depends on.

TIME

Typically 5–10 working days

Depends on system size. We’ll confirm before we start, not after.

OUT

Inspection Report + rating

Findings with severity, evidence, and a recommended fix for each.

NEXT

No obligation

The report is yours. Hiring us for the refit is a separate decision.

Scope

What we examine

Twenty-one areas across six domains. Not every area applies to every system — the report says which were assessed, which were not, and why.

Structure

  • Architecture
  • Application code
  • Maintainability
  • Documentation

Security

  • Authentication
  • Authorization
  • Secrets management
  • Dependencies

Data

  • Database design
  • Data integrity
  • Backups
  • Disaster recovery

Verification

  • Testing
  • Error handling
  • CI / CD

Operations

  • Logging
  • Monitoring
  • Observability
  • Infrastructure

Behaviour under load

  • Performance
  • Scalability
How it runs

Four steps, start to report

01

Intake

A short conversation. What it does, who uses it, how it’s deployed, what worries you.

02

Examination

Read-only access. We work through the scope and record evidence as we go.

03

Findings

Each issue gets severity, evidence, impact and a recommended fix. No vague advice.

04

Walkthrough

We take you through the report live and answer the “so what do we do first” question.

05

Your call

Fix it yourselves, have us refit it, or accept the risk knowingly.

The rating

Production Readiness Rating

A single score, backed by per-area results. It exists to make an abstract question concrete: could this survive real customers, and if not, what specifically is in the way?

The score is deliberately hard to game. An area with a critical finding caps the overall rating regardless of how strong everything else is — because in production, one unprotected admin endpoint outranks a tidy codebase.

Cleared for production Cleared with findings Not cleared
0% READINESS
Example · EB-00241
Not ClearedFor Production

Two critical security findings cap this system at 63% regardless of its architecture score. Both are fixable in days, not months — which is exactly the kind of thing an inspection is for.

After the inspection

Three honest outcomes

Cleared

Ship it

The engineering holds. You get the report as evidence — useful for customers, investors and your own peace of mind.

Cleared with findings

Ship, then fix

Nothing blocking, but real debt. You get a prioritised list and a sensible order to work through it.

Not cleared

Fix, then ship

Something would hurt you in production. We say what, why, and what it takes to clear it. Then it’s your call.