The tech audit that inspects your code and your production servers

A 360° diagnosis in decision language: where velocity stalls, what technical debt costs, and how exposed you are on security. Report in four days, one-hour readout.

Book a scoping callSchéma : le code décrit l'intention, les serveurs en production disent la vérité ; l'audit inspecte les deux et l'écart concentre le risque.

What production reveals

Six cases I run into regularly, invisible in the repository and very real on the servers:

Default configuration

Settings left at their defaults degrade performance or compromise data persistence. It looks minor, yet it often weighs heavy.

Open doors

A database or an admin console stays reachable from the outside, while nothing in the code hinted at it.

Secrets in plain text

Passwords and access keys sit in plain text in the configuration, copied from one deployment to the next. And former employees sometimes still have access to production or to critical components.

No alerting

No monitoring is in place: the outage is discovered when a customer calls, not before. I call this anti-pattern Customer-based alerting, and it's a disastrous customer experience.

Tests that cover nothing

In interviews, I'm told there's a solid testing strategy. In the code, I find tests that are missing or limited to the trivial, covering none of the critical scenarios. That feeds customer dissatisfaction, and sometimes churn.

Code / production drift

What runs in production no longer matches the repository. Hand-made changes linger, and no one can recreate the production environment from scratch anymore, for instance to trigger a disaster recovery plan after an attack.

The 8 review axes

01

System architecture

How the product's building blocks communicate, where the single points of failure sit, and what gives way when traffic is multiplied by ten.

02

Software architecture

Is the code still modular and changeable without breaking everything, or does coupling spread every change everywhere and slow the team down?

03

Infrastructure

Does the infrastructure scale with the company's growth, on the performance side? I add a FinOps analysis: I compare your infrastructure costs with those of similar-size companies I've already observed, then I identify the possible optimizations, in performance as well as cost.

04

Team organization

Do your teams go from source code to deployment without depending on anyone? Is their breakdown aligned with business stakes, with infrastructure, and with the codebase? The goal is autonomous teams: a short time-to-market, and a company that stays aggressive in its market.

05

Method & strategy

Does the way of delivering really serve the company's goals and align the teams on a shared trajectory, or does it burn budget off-target?

06

Product design

From the stated need to the shipped code, I measure the drift at each step: gathering, specification, implementation, quality.

07

Security

Real exposure surface: reachable data, over-broad rights, vulnerable dependencies. I measure it in the code and on the servers actually running.

08

Software quality

This is the health that determines future speed: tests, readability, technical debt. That hidden debt slows every change down.

Qualitative

Leadership interviews

I interview your CTO and your technical leads, then I hold their explanations against what the code, the servers, the team organization and the methodology used across the whole software lifecycle actually show. That's often where the gap between the story and the reality becomes visible.

Quantitative

Code and servers

An audit that stops at interviews, without a review of the source code or the servers, misses half the problems. The tickets and the business owners describe the intent, which rarely matches what was actually written in the source code. The reality of the customer experience plays out on the production servers. That's exactly what I check, on both sides. I read the source code, under NDA if needed, then I inspect the servers in execution and in configuration, where the flaws and configuration defects that weigh on performance and security hide.

You're a company leader

Your product holds up, your team ships, and the technical side, the methodology and the alignment of your teams' organization with your stakes all stay a black box you can't audit yourself. I give you a verified answer, in the language of decisions: where velocity stalls, where software quality stalls, what your real exposure is on security and GDPR, whether the team is sized for the roadmap ahead, and what technical debt is costing you. I come as an ally of your CTO. I leave them precise, actionable arguments and recommendations on their tech stack, their methodology and their team organization, to defend their work in front of you.

I've already run these audits for Ouest-France, Klaxoon, France's Ministry of the Interior, Ascor, Guest Suite, Wanteeed and COMAP.

They trusted me to audit their technical foundations.

  • Ouest-France
  • COMAP
  • Klaxoon
  • Guest Suite
  • Wanteeed
  • Netwo

You're a fund running due diligence

The scope narrows to what drives the decision: red flags, quantified technical debt, the team's ability to deliver the roadmap, security and compliance risks. The debrief decides: go, no-go, or go with conditions, with the impact on valuation.

I already work with Arkéa Capital, MAIF Avenir, SofiOuest, NCI and Caisse des Dépôts.

They trust me with the technical due diligence of their targets before they invest.

  • Caisse des Dépôts
  • Arkéa Capital
  • MAIF Avenir
  • NCI
  • SofiOuest

They trusted me with their tech

« François-Guillaume was extremely helpful in clarifying our SaaS strategy from both a technical and product standpoint. The audit gave us a clear and actionable assessment. François-Guillaume's expertise is inspiring, and his ability to simplify complex issues, understand the stakes, and his genuine care make his audits a truly enriching experience. »
Antoine LabordeAntoine Laborde, CTO Ogures Software
« With strong technical, organizational, and entrepreneurial skills, François-Guillaume quickly grasped our complex challenges and delivered a precise assessment along with invaluable recommendations. »
Ali KenanAli Kenan, CTO TokTokDoc
« François-Guillaume has both a very broad general IT knowledge and sharp expertise in new technologies. His theoretical knowledge is illustrated by his own field experience. »
Jin LeiJin Lei, CTO Hermes Technologies
« Following a half-day exchange about database performance issues, François-Guillaume's advice enabled us to quickly reduce response times across our services. »
Berger S.Berger S., CTO Qivivo
« He knows and recommends the right tools for every situation, and is able to structure things in a simple and effective way. A real pleasure to work with. »
Rémi CastelRémi Castel, Software Engineer Hublot

Why trust me with this audit

The audit applies the method from the book NoBullshit Tech-Lead. You know exactly what gets reviewed, before you sign.

I have built, shipped to production and sold SaaS products. I judge your stack the way an acquirer would judge mine: what holds in production, what gets expensive later.

Funds trust me to audit their targets before a fundraise.

My open source code runs close to 9.6 million times a month. I do not audit in theory.

How the audit unfolds

Déroulé de l'audit en quatre étapes : cadrage avec NDA signé, inspection du code et des serveurs, rapport sous quatre jours, restitution d'une heure.

For a fund: the due diligence verdict

Verdict de due diligence : go (l'actif tient), go sous conditions (feu vert une fois les red flags corrigés), ou no-go (risque rédhibitoire) ; chaque issue chiffrée sur la valorisation.

Formats and pricing, in the open

Comprehensive Technical Audit

14,750 EUR excl. VAT

The detailed assessment to decide with confidence.

  • 3 days, remote
  • Source code and infrastructure audited in depth
  • Scope defined together around your stakes
  • 360° control points: architecture, organization, product, team, security
  • In-depth interviews with team leads and the executive committee
  • Detailed debrief and ready-to-execute recommendations
Book a scoping call

Custom Audit

Starting at 18,800 EUR excl. VAT

For your most complex technical challenges.

  • About 2 weeks and up, on-site or remote
  • Source code and infrastructure audited in depth
  • Scope defined together around your stakes
  • Scaling, major refactoring, complex challenges
  • Optional support during implementation
Book a scoping call

Quick advisory

€250 · 30 min

A blocking issue. A decision to make. An external perspective on your architecture, organization, or go-to-market.

Unblock this point →

C-Level Sparring Session

€500 · 1 hour

For CEOs, CTOs, CPOs and COOs who want to be challenged, not reassured.

Book a sparring session →

Prices excl. VAT. The exact scope is set in a 30-minute call.

Confidentiality & posture

If needed, I sign your NDA before any access to the source code and the servers. I observe in read-only, without ever changing your production. The diagnosis is delivered to you behind closed doors. And I give your CTO the arguments to defend their work internally.

Frequently asked questions

How much does a technical audit cost for a startup or an SME?

A full audit usually runs from €3,000 to €15,000 depending on depth and on the auditor. I offer two formats: €4,800 excl. VAT for a flash due-diligence audit with a report within four days, and from €14,750 excl. VAT for a full 360° audit with a readout.

What is a technical due diligence before a fundraise?

It is an independent audit commissioned by an investor to assess how solid a digital asset is before investing. It covers architecture, technical debt, security, scalability, team organisation and continuity risks. The deliverable combines a report and a readout within a few days.

How do you objectively assess your CTO or your tech team?

The right move is to bring in a senior external peer, to avoid the hierarchical bias. I review architecture decisions, engineering quality (CI/CD, code review, debt), the ability to hire and retain, and the alignment between roadmap and resources. I arrive as an ally to the CTO and I leave him arguments to defend his work.

What is the difference between a technical audit and a due diligence?

It is the same method under a different angle. The audit is commissioned by internal management to improve and prioritise. The due diligence is commissioned by an investor before a transaction, to qualify the risk and decide on funding.

When should an SME have its tech audited?

Three signals come up often: deliveries slow down while the team grows, production incidents repeat, or an acquisition or fundraise is coming. An external view finds the root causes without the internal team's bias.

How do you guarantee confidentiality?

I sign your NDA before any access to the code and servers. I observe in read-only mode, without ever changing your production, and the readout happens behind closed doors.

Let us scope your stakes in 30 minutes

A short call is enough to check whether the audit makes sense, and which one. I sign your NDA before any access.

Book a scoping call