Know What You Are Buying, Funding or Rebuilding Before You Commit
An independent code audit: a senior review of an existing codebase and how it is built, run and owned, written up so that engineers can act on it and decision makers can price it.
What does Code Audit involve?
A code audit is an independent review of an existing software system's source code, architecture, dependencies, security, infrastructure and delivery practices, producing a severity-rated findings report and remediation estimate; when it is commissioned by an acquirer, investor or board to inform a transaction or funding decision, it is usually called technical due diligence.
Software is often the largest asset in a deal that nobody on the deal team can read. An acquirer sees a product demo, a revenue line and a team slide. What they cannot see is whether the code is maintainable by anyone other than its original author, whether it depends on libraries with licences that conflict with how it is sold, whether customer data is protected, whether it will survive ten times the users, or whether a large part of it was written by contractors who never assigned their rights. The same blind spot applies to a board approving another year of spend on an internal platform, an investor weighing a follow-on round, or a business owner deciding whether to keep the system they have or pay for a rebuild. A code audit replaces assumptions with evidence, in the time frame a decision actually allows.
Our code audit services combine automated analysis with senior engineers reading the code, so every audit is a genuine source code review, not only an automated scan. Tooling covers what machines do well: dependency vulnerabilities, open source licence inventory, secrets committed to the repository history, static analysis, test coverage and code churn. People cover what tooling cannot: whether the architecture fits the business plan, whether the data model will hold up, how deployments and backups actually work, where knowledge is concentrated in one person, and what it would realistically cost to fix what we find. Every finding is rated by severity and business impact, linked to evidence, and paired with a remediation estimate, so an acquirer can adjust price or conditions, a board can fund the right fixes, and an owner can compare the cost of repair against the cost of replacement. We work under NDA, read-only where possible, and report to whoever commissioned the audit. If you are a founder planning a new product rather than assessing an existing one, our Discovery Audit covers the legal, compliance and IP questions before a build starts; this service is for software that already exists.
All Webbed Labs is a Sydney based enterprise AI and software development company. Sister company to All Webbed Up, the branding and marketing agency we deliver client work alongside.
Why choose All Webbed Labs for Code Audit?
Evidence, Not Impressions
Each finding links to the file, commit, configuration or scan result that supports it. You can hand the report to the target's engineers and they can verify every point, which makes negotiation about facts rather than opinions.
Findings With a Price Tag
Severity ratings alone do not help a deal team. We estimate the effort to remediate each material finding in engineer days and cost ranges, so issues can be reflected in price, escrow, conditions precedent or a post-completion plan.
Licence and Provenance Checks
We inventory open source components and their licences, flag copyleft obligations that may conflict with how the software is distributed, and map who committed the code. That gives your lawyers a factual basis for their review of IP assignment.
Security From the Inside
A code audit reviews authentication, authorisation, input handling, secrets management and data protection by reading the source, which finds issues an external scan cannot. Where a live penetration test is also warranted, we say so and scope it separately.
Key-Person Risk Made Visible
Commit history, documentation and interviews show how much of the system lives in one or two people's heads. For an acquirer or investor, that is often the largest risk in the asset, and it has a practical mitigation plan if identified early.
Repair or Rebuild, Answered
For owners weighing a rebuild, we compare the cost and risk of fixing the current system against replacing it, module by module where that helps. Sometimes the honest answer is that the existing code is better than it feels, and a rebuild would waste money.
How do Australian businesses use Code Audit?
What technologies does All Webbed Labs use for Code Audit?
What does the Code Audit process look like?
Scope, Questions and NDA
We agree the decision the audit supports, the questions that matter most, the systems in scope, the deadline and who receives the report. NDAs are signed with the commissioning party and, in a transaction, with the target. Scope is fixed before work starts.
Access and Automated Analysis
With read-only access to repositories and, where agreed, cloud consoles, we run dependency, licence, secrets and static analysis scans, generate a software bill of materials, and measure test coverage and code churn. Results are triaged by an engineer; raw scanner output is never passed off as findings.
Senior Engineering Review
Senior engineers read the critical paths: authentication, payments, data access, integrations and the areas with the most change or defects. We review architecture, data model, infrastructure, deployment, backups and observability against the business plan the software needs to support.
Team Interviews
Short structured interviews with the engineers and product owners fill gaps the code cannot: how releases happen, what breaks, what is planned, and who knows what. In a transaction, these are coordinated through the deal team and kept to agreed topics.
Findings, Ratings and Estimates
Each finding is written up with evidence, a severity and business impact rating, and a remediation estimate. We share draft findings with the commissioning party for factual correction before the report is finalised, so nothing in it is a surprise.
Report and Read-Out
You receive an executive summary, a detailed technical report, a risk register and a remediation roadmap, followed by a read-out session for decision makers and a separate technical session for engineers. We remain available to answer follow-up questions during the decision period.
Who is Code Audit for?
Is Code Audit the right solution for you?
When Code Audit is the right fit
- You are acquiring, investing in or lending against a company whose value depends substantially on its software
- A board or executive team needs an independent view of an internal platform before approving further investment
- You are deciding whether to repair, partially replace or rebuild an existing system and want the decision grounded in evidence
- You have inherited a codebase from a departed vendor or developer and need to know what you now own
- You are preparing for a sale or raise and want to find and fix issues before a buyer's diligence team does
When it is not the right fit
- You are planning a brand new product with no existing code, where our Discovery Audit is the right starting point
- You need formal assurance against a certification standard such as ISO 27001 or SOC 2, which requires an accredited auditor
- You only need to test whether a live system can be breached from outside, where a penetration test is the more direct tool
- The software is an off-the-shelf SaaS product you subscribe to, where vendor security documentation and contract terms matter more than code
- The decision is already made and the audit would only confirm it, in which case spend the budget on the remediation itself
How much does Code Audit cost?
Indicative ranges in AUD to help you budget. Every engagement is scoped individually, book a discovery call for a fixed quote tailored to your requirements.
Typical Australian market range, AUD ex GST, not a quote. A single application of modest size, about 6 to 12 senior days at a planning rate of roughly $1,400 a day: automated scans, targeted code review, short report, risk register and read-out.
Typical range, AUD ex GST. A product and its infrastructure for a transaction or funding decision, about 13 to 28 senior days: full scans and SBOM, architecture and security review, team interviews, remediation estimates, executive summary and data-room-ready report.
Typical range, AUD ex GST. Several products, legacy platforms or heavy regulatory exposure, with a red-flag summary early and a full report to a deal timetable. Scoped and fixed before work starts.
Code Audit: a quick glossary
- Technical due diligence
- An independent review of a company's software, infrastructure and engineering practices commissioned by a prospective acquirer or investor, to identify risks that affect value, deal terms or post-completion plans.
- Software bill of materials (SBOM)
- A machine-readable list of every third-party component in a piece of software, with versions and licences. It shows exactly what the software is made of and which published vulnerabilities apply to it.
- Copyleft licence
- An open source licence, such as the GPL or AGPL, that can require software incorporating the licensed code to be released under the same terms in certain circumstances. It matters when proprietary software is distributed or offered as a service.
- Static analysis
- Automated examination of source code without running it, to detect likely bugs, insecure patterns and code quality issues. Useful for coverage, but its output needs an engineer to separate real problems from noise.
- Key-person risk
- The risk that critical knowledge of a system is held by one or two individuals, so their departure would slow or stall development. Commit history and documentation gaps are the usual evidence.
- Code churn
- How often particular files or modules are changed over time. Areas with high churn and many defects are usually where maintenance cost and risk are concentrated.
- Red-flag report
- A short early summary of the most serious findings in a due diligence engagement, delivered ahead of the full report so a deal team can decide quickly whether to proceed, renegotiate or dig deeper.
Common questions about Code Audit
The technical work is largely the same. A code audit is the broader term and can be commissioned by anyone, including the software's owner. Technical due diligence is a code audit commissioned by a prospective acquirer or investor to inform a transaction, so it adds a focus on valuation-relevant risks such as IP provenance, key-person dependency, scalability against the business plan and the cost of remediation after completion.
An executive summary written for non-technical decision makers, a detailed technical report with evidence for each finding, a risk register rated by severity and business impact, remediation estimates in engineer days and cost ranges, a software bill of materials with licence inventory, and a read-out session. The format can be adapted to fit a data room or a board paper.
A focused audit of a single application usually takes one to two weeks from access to report. A multi-system platform or a target with several products typically takes three to four weeks. Deal timetables are often tight, so we can deliver a red-flag summary early in the engagement, followed by the full report.
No. A penetration test attacks the running system from outside to find exploitable weaknesses. A code audit reads the source and configuration from inside, and covers much more than security: architecture, maintainability, licences, delivery practices and team risk. They complement each other. If our review suggests a penetration test is warranted, we recommend it and can scope it through our cybersecurity service.
Not on its own. We provide the technical facts: an inventory of open source licences and their obligations, a list of who committed the code and when, and any third-party or generated code we can identify. Whether ownership has been validly assigned is a legal question for your lawyers, who can use our findings as evidence. This is general information, not legal advice.
Minimally. Most of the work is done from read-only repository access and documentation. We typically need a few hours of interviews with the lead engineers and a named contact for questions. We agree the time commitment with the deal team up front.
Probably not. A code audit assesses software that already exists. If you are a founder about to commission a new build, our Discovery Audit covers the legal, compliance, security and IP questions before development starts, and its fee is credited to the build if you proceed.
Yes, in most cases. Rebuilds are expensive and often recreate the same problems. An audit tells you which parts of the current system are sound, which are genuinely holding you back, and what fixing them would cost, so the choice between refactoring, partial replacement and a full rebuild is made on evidence.
Typical Australian market ranges are $8k to $18k for a focused audit of a single application, $18k to $40k for technical due diligence on a product and its infrastructure, and $40k or more for several products or a complex regulated target (AUD, ex GST). The size of the codebase, the number of systems and the deal timetable drive the figure, and the scope and fee are fixed before work starts.
It can tell you, with evidence, whether the code is secure, tested, documented and maintainable to a reasonable professional standard, and where it falls short. It cannot settle who was at fault in a dispute, because that depends on what was agreed. An audit is a sensible step if you are unsure about software an agency or freelancer delivered, before paying a final invoice or briefing a new team.
Yes, and they are audited the same way as any other code. Code produced quickly with AI assistants can carry the usual problems at higher volume: duplicated logic, thin tests, insecure defaults, committed secrets and outdated or unnecessary dependencies. The report shows where those issues sit and what it would cost to bring the codebase up to a maintainable standard.
Our manual review covers TypeScript and JavaScript (including React and Next.js), Python, PHP, Java and C# with .NET, on PostgreSQL or MySQL, hosted on AWS, Azure or Google Cloud. Automated scanning for vulnerabilities, secrets and licences covers most mainstream languages. If a target uses a stack outside that range, we say so at scoping rather than review it thinly.