The Bay Inspection
Before you ship it, inspect it. A fixed-scope examination of the whole system — not just the code — ending in a written report and a production readiness rating you can act on.
A verdict, not a proposal.
Most consultancy engagements start with a discovery phase that quietly becomes the project. This doesn’t.
An inspection is bounded in scope, time and cost. At the end you own a document that stands on its own — useful whether we do the remediation, your team does it, or you decide the risk is acceptable and ship anyway. That last outcome is a legitimate result and we’ll tell you when we think it applies.
Repository access, read-only
Plus a walkthrough of how it’s deployed and what it depends on.
Typically 5–10 working days
Depends on system size. We’ll confirm before we start, not after.
Inspection Report + rating
Findings with severity, evidence, and a recommended fix for each.
No obligation
The report is yours. Hiring us for the refit is a separate decision.
What we examine
Twenty-one areas across six domains. Not every area applies to every system — the report says which were assessed, which were not, and why.
Structure
- Architecture
- Application code
- Maintainability
- Documentation
Security
- Authentication
- Authorization
- Secrets management
- Dependencies
Data
- Database design
- Data integrity
- Backups
- Disaster recovery
Verification
- Testing
- Error handling
- CI / CD
Operations
- Logging
- Monitoring
- Observability
- Infrastructure
Behaviour under load
- Performance
- Scalability
Four steps, start to report
Intake
A short conversation. What it does, who uses it, how it’s deployed, what worries you.
Examination
Read-only access. We work through the scope and record evidence as we go.
Findings
Each issue gets severity, evidence, impact and a recommended fix. No vague advice.
Walkthrough
We take you through the report live and answer the “so what do we do first” question.
Your call
Fix it yourselves, have us refit it, or accept the risk knowingly.
Production Readiness Rating
A single score, backed by per-area results. It exists to make an abstract question concrete: could this survive real customers, and if not, what specifically is in the way?
The score is deliberately hard to game. An area with a critical finding caps the overall rating regardless of how strong everything else is — because in production, one unprotected admin endpoint outranks a tidy codebase.
Two critical security findings cap this system at 63% regardless of its architecture score. Both are fixable in days, not months — which is exactly the kind of thing an inspection is for.
Three honest outcomes
Ship it
The engineering holds. You get the report as evidence — useful for customers, investors and your own peace of mind.
Ship, then fix
Nothing blocking, but real debt. You get a prioritised list and a sensible order to work through it.
Fix, then ship
Something would hurt you in production. We say what, why, and what it takes to clear it. Then it’s your call.