// free audit · 4 min

Codebase Risk Review

You don't need to upload your code. Answer 12 questions about how your codebase behaves, get a risk score, and a senior engineer will review the hot spots with you.

Progress0 / 12 answered
Security & secrets
1.Where are API keys and credentials stored?
2.When were dependencies last scanned for known vulnerabilities?
3.Has the app had an external security review or pen test?
Testing & CI
4.What happens when a test fails in CI?
5.How confident is the team changing core business logic?
6.How long does the full test suite take?
Dependencies & upgrades
7.Is your main framework / runtime on a supported version?
8.How hard is upgrading a major dependency?
9.How many people understand the most critical module?
Deployability & observability
10.How is code deployed to production?
11.How do you find out about production errors?
12.How fast can you roll back a bad release?

Where should we send your report?

Press submit to see your score, your fixes in priority order, and book a free 30-minute walkthrough with a senior engineer.

Answer all 12 questions to submit (12 left).