What is a code audit?
A code audit is an external review of an application's codebase. It covers architecture, code quality, test coverage, security and technical debt. It produces a report listing what is sound, what must be fixed, and what each fix represents in effort.
How much does a code audit cost?
At Reflekt Lab a code audit is fixed-price at €2,500, running two to five days depending on project size. The takeover that follows starts at €800 per day, and the number of days is estimated from the audit's findings rather than guessed beforehand.
Rebuild, refactor, or start over?
Almost never. A full rewrite discards work you already paid for and pushes your next release out by months. In the large majority of cases the right answer is to stabilise what exists, add tests on the critical paths, then replace the problematic components one at a time.
Can you take over an app built with Lovable, Cursor or Replit?
Yes, provided the source code can be exported. The usual concerns on these projects are security, missing tests, unoptimised queries and dependence on the original platform's subscription. The audit starts by confirming the export is complete and workable.
Who owns my application's source code?
It depends on your contract. A development engagement may assign the rights or merely license the software to you. Without the right to modify the sources, no other supplier can legally take the project on. It is the first thing to check, before any technical audit.
What if my current supplier has stopped replying?
We can work from whatever you have access to: the Git repository, a code archive, or in difficult cases the deployed application itself. We also help you recover missing access, particularly hosting and the domain name, which should be in your name.
How long does a project takeover take?
The audit takes two to five days. The technical handover generally runs two to six weeks depending on project size and test coverage. The two steps are separate precisely so that you decide on the second with a costed figure rather than a blind estimate.
What is in the audit report?
An architecture map, an inventory of dependencies and their support status, security flaws ranked by severity, a test coverage measurement, the failure points expected under load, and a per-issue estimate in days. The report is yours, including if you do not continue with us.
Which technologies do you work with?
Mainly Go, Python, TypeScript and React with PostgreSQL, on Kubernetes or managed platforms. We also audit PHP, Symfony and Node.js projects. If a technology falls outside what we can support, we say so before accepting the engagement.
What if the app has no tests at all?
That is the most common case and it does not block a takeover. The first task is writing tests for the critical business paths, the ones where an outage costs money. They act as the safety net for everything after. It is also the single biggest driver of the estimated day count.
How much does a code takeover cost?
A takeover runs in two stages. The audit is a fixed €2,500 and gives you the full report plus a costed estimate of the work, with no commitment to continue. If you go ahead, the technical takeover and the development that follows are billed from €800 per day. The number of days depends on the size of the codebase, whether any tests exist and the state of the infrastructure, and the audit gives you that number before you commit.
What is the difference between a source code audit and a technical audit?
A source code audit looks at the code itself: architecture, quality, test coverage, dependencies and security flaws. A technical audit is broader and also covers infrastructure, environments, the deployment pipeline, monitoring and hosting costs. We deliver both in the same €2,500 report, because in a takeover the two questions always arrive together.
How do you choose an agency to take over your code?
Three criteria settle it quickly. First, the agency should start with a separately billed audit and no commitment to continue: if you are offered a rewrite package up front, the proposal came before the diagnosis. Second, it should publish its prices, or at least give them before seeing the code. Third, it should be willing to tell you the takeover is not worth doing. We do, when that is the case.
Is offshore development still cheaper?
It depends what you are buying. The day rate gap is real and has not closed. What changed is that writing code, the part that gap applies to, is no longer the expensive half of a project. Review, architecture and maintainability are, and AI did not make those cheaper. A supplier who adopted these tools without tightening how architecture is reviewed delivers more code for your money at the same structural quality. The saving shows up on the invoice. The cost shows up when you need to change something.
How do you choose an application maintenance supplier?
Two things discriminate. Does the supplier read the code before committing to response times, and does the contract let you take the work elsewhere. Team size, certifications and location matter less than those two. A maintenance contract signed without an audit first commits the supplier to an application they do not know, and that always gets paid for on one side or the other.
What does a maintenance contract cover and what does it cost?
Corrective maintenance, evolutionary maintenance and keeping the application running. Ours starts after the €2,500 fixed-price audit, then from €800 per day, with the number of days set by what the audit found. On a takeover we set that volume after reading the application, because the price depends entirely on test coverage and the age of the dependencies.